2026 CVE Vulnerabilities

43,246 CVEs published in 2026.

Filter:LOWClear
CVE IDSeverityCVSSDescription
CVE-2026-12823LOW3.3A security flaw has been discovered in Browserbase Skills up to 20260526. This impacts an unknown function of the compon...
CVE-2026-12812LOW3.5A security vulnerability has been detected in Radware Cyber Controller up to 10.11.0. This affects an unknown part of th...
CVE-2026-56355LOW3.7GNU Savannah Administration Savane through 3.17 uses untrusted data as part of authorization.
CVE-2026-56325LOW3.1Capgo before 12.128.2 uses ILIKE pattern matching instead of exact matching for app_id lookup in the preview subdomain r...
CVE-2026-48794LOW1.3Authelia is an open-source authentication and authorization server providing two-factor authentication and single sign-o...
CVE-2026-47203LOW2.9Authelia is an open-source authentication and authorization server providing two-factor authentication and single sign-o...
CVE-2026-49358LOW3PhpWeasyPrint is a PHP library allowing PDF generation from a URL or an HTML page. Prior to version 2.6.0, `AbstractGene...
CVE-2026-8668LOW2.3A static credential embedded in Chef 360 prior to v1.7.0 permitted unauthenticated access to internal message queues.  Q...
CVE-2026-48617LOW1.8A flaw in Node.js Permission Model enforcement allows Bypass via `process.report.writeReport()` Path Misvalidation. This...
CVE-2026-40457LOW2.1A Reflected Cross-Site Scripting (XSS) vulnerability exists in LMS (LAN Management System) before commit 9c5651b in the ...
CVE-2026-12102LOW2.7The UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP plugin for WordPre...
CVE-2026-50268LOW1.9Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applicati...
CVE-2026-12567LOW2.2The github_workflows module constructs local directory paths from user-controlled repository names without validating fo...
CVE-2026-12566LOW3.1The docker_pull module uses the realm parameter from a Docker registry's WWW-Authenticate response header as the authent...
CVE-2026-6733LOW3.7Impact: Undici's HTTP/1.1 client is vulnerable to response queue poisoning on reused keep-alive sockets. An attacker-con...
CVE-2026-39199LOW2.9snes9x 1.63 allows an out-of-bounds write and denial of service via a crafted .ups file.
CVE-2026-11525LOW3.7Impact: When undici parses a Set-Cookie header, it accepts any SameSite attribute value that contains Strict, Lax, or No...
CVE-2026-12458LOW3.1Inappropriate implementation in Passwords in Google Chrome prior to 149.0.7827.155 allowed a remote attacker who convinc...
CVE-2026-0057LOW3.3In Contacts Provider, there is a possible way to access an incoming call's phone number and associated metadata due to a...
CVE-2026-46977LOW3.2Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: VMSVGA device). The supported v...
CVE-2026-46874LOW3.2Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version th...
CVE-2026-46816LOW3.2Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: VMSVGA device). The supported v...
CVE-2026-46815LOW3.2Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: VMSVGA device). The supported v...
CVE-2026-0158LOW3.3In Camera, there is a possible unauthorized way to access photos due to a missing permission check. This could lead to l...
CVE-2026-0145LOW3.3In keymint, there is a possible Permission Bypass due to a logic error in the code. This could lead to local information...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now