2026 CVE Vulnerabilities

64,760 CVEs published in 2026.

Filter:LOWClear
CVE IDSeverityCVSSDescription
CVE-2026-77351LOW3.5Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 5.0.0, Wallos lets any authentic...
CVE-2026-82906LOW3.7A flaw has been found in sdcb chats up to 1.12.0. This impacts the function DownloadPublic of the file src/BE/web/Contro...
CVE-2026-14367LOW3.1The I3C IBI subsystem in drivers/i3c/i3c_ibi_workq.c hands out statically-allocated work nodes through a free-list i3c_i...
CVE-2026-82810LOW3.3A weakness has been identified in extension.vn 2FA Authenticator Extension 1.0.0.2 on Chrome. The impacted element is th...
CVE-2026-21827LOW3.1HCL Connections is vulnerable to an information disclosure vulnerability which could allow a user to obtain sensitive in...
CVE-2026-82699LOW2.7A flaw has been found in sambitraj Student Management System up to 56ba287f2e9031523ccb4244cb6e3fe530e4e5d5. This impact...
CVE-2026-82697LOW3.7A security vulnerability has been detected in sambitraj Student-Management-System up to 56ba287f2e9031523ccb4244cb6e3fe5...
CVE-2026-82677LOW2.4A vulnerability was determined in valkey-io valkey 9.1.0. Impacted is the function moduleTimerHandler of the file src/mo...
CVE-2026-82671LOW3.4A vulnerability has been found in IObit Unlocker 1.3.0.12. This vulnerability affects the function ZwTerminateProcess in...
CVE-2026-82863LOW3.3@hulumi/baseline versions before 1.3.2 fail to fully detect CloudTrail selector tampering events, reducing audit logging...
CVE-2026-82665LOW3.8A vulnerability was detected in yaojingang GEOFlow up to 2.1.0. This vulnerability affects the function unlink of the fi...
CVE-2026-82631LOW2.2A security flaw has been discovered in valkey-io valkey 9.1.0. The affected element is the function handleClientsBlocked...
CVE-2026-82622LOW3.5A security vulnerability has been detected in code-projects Employee Leave Managing System 1.0. Affected is an unknown f...
CVE-2026-82727LOW2.3Generation of Error Message Containing Sensitive Information vulnerability in ash-project ash_phoenix writes the entire ...
CVE-2026-82725LOW2.3Authorization Bypass Through User-Controlled Key vulnerability in ash-project ash_phoenix lets an attacker who controls ...
CVE-2026-82681LOW2Improper Encoding or Escaping of Output vulnerability in ash-project ash_admin lets an attacker who controls a record's ...
CVE-2026-81853LOW2.3Authorization Bypass Through User-Controlled Key vulnerability in ash-project ash_admin turns a record-lookup URL into a...
CVE-2026-81852LOW2.1Use of Insufficiently Random Values vulnerability in ash-project ash_admin ships a hardcoded, publicly known CSP nonce, ...
CVE-2026-82596LOW3.3A vulnerability was determined in LatencyUtils up to 2.0.3. Affected by this issue is the function LatencyStats.recordDe...
CVE-2026-82367LOW2.3Exposure of Data Element to Wrong Session vulnerability in ash-project ash_graphql can deliver one subscription's resolv...
CVE-2026-81643LOW2.3Incorrect Authorization vulnerability in ash-project ash_graphql delivers GraphQL subscription payloads for records a su...
CVE-2026-82555LOW3.7A vulnerability has been found in TOTOLINK N600R 4.3.0cu.7866_B20220506. This vulnerability affects the function loginAu...
CVE-2026-81322LOW2.1Exposure of Sensitive Information to an Unauthorized Actor vulnerability in ash-project ash_cloak allows anyone with acc...
CVE-2026-82656LOW2.6Admidio before 5.0.12 fails to sanitize album names in the photo ZIP download functionality, allowing authenticated user...
CVE-2026-81318LOW2.1Incorrect Authorization vulnerability in ash-project ash_sql allows a caller in a schema-based multitenant application t...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now