2026 CVE Vulnerabilities

64,760 CVEs published in 2026.

Filter:LOWClear
CVE IDSeverityCVSSDescription
CVE-2026-81316LOW2.1Incorrect Authorization vulnerability in ash-project ash_sql allows a caller to receive an aggregate value computed over...
CVE-2026-80227LOW2.1Incorrect Comparison vulnerability in ash-project ash_sql allows a user to pad a string field with tab, newline, carriag...
CVE-2026-78691LOW2.1Improper Neutralization of Special Elements in Data Query Logic vulnerability in ash-project ash_sql allows a user who s...
CVE-2026-82488LOW3.5A vulnerability was identified in Beetel 450TC3 01.00.00_01. This vulnerability affects unknown code of the component Us...
CVE-2026-82483LOW3.5A vulnerability was detected in coppermine-gallery Coppermine Photo Gallery up to 1.6.28. This impacts an unknown functi...
CVE-2026-82482LOW3.5A security vulnerability has been detected in coppermine-gallery Coppermine Photo Gallery up to 1.6.28. This affects an ...
CVE-2026-78364LOW3.5The MW WP Form WordPress plugin before 5.1.6 does not sanitise and escape some of its form settings before outputting th...
CVE-2026-77846LOW2.1Improper Neutralization of Special Elements in Data Query Logic vulnerability in ash-project ash_sqlite allows an attack...
CVE-2026-82562LOW3.7### Summary When `qs.parse` is called with `comma: true` and `throwOnLimitExceeded: true`, a comma-separated value un...
CVE-2026-77831LOW2.1Inefficient Algorithmic Complexity vulnerability in ash-project ash_paper_trail allows a user who can submit a large arr...
CVE-2026-81200LOW2.7The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.42 does not correctly restrict access to order informa...
CVE-2026-77704LOW2.7The Booking for Appointments and Events Calendar WordPress plugin before 2.4.9 does not check that a user holds the req...
CVE-2026-55785LOW3.7free5GC is an open-source implementation of the 5G core network. Prior to 1.4.5, the AUSF component performs cryptograph...
CVE-2026-77063LOW3.7multer is a middleware for handling multipart/form-data in Node.js. When an application uses an asynchronous fileFilter ...
CVE-2026-22056LOW2.3StorageGRID (formerly StorageGRID Webscale) versions 11.5 and higher in a non-standard configuration and scenario are su...
CVE-2026-13735LOW3.7Zephyr's WireGuard implementation in subsys/net/lib/wireguard/wg_crypto.c mishandled keepalive packets. In wg_process_da...
CVE-2026-58616LOW3Concurrent execution using shared resource with improper synchronization ('race condition') in Copilot Chat (Microsoft E...
CVE-2026-82112LOW3.5A flaw has been found in houtini-ai houtini-lm up to 2.13.2. The impacted element is an unknown function of the file src...
CVE-2026-58106LOW2CVE-2025-40843 https://github.com/advisories/GHSA-5xf2-f6ch-6p8r  was fixed by replacing unchecked strcpy() with a bound...
CVE-2026-38093LOW3.3file_picker (aka flutter_file_picker) for Flutter, all versions through 10.3.10, is vulnerable to path traversal (CWE-22...
CVE-2026-82249LOW3.1gitoxide before 0.38.2 fails to validate carriage return characters in URL values passed to credential helpers. Attacker...
CVE-2026-82238LOW3.1filebrowser from version 2.24.0 contains a race condition in the TUS upload handler that allows authenticated users to w...
CVE-2026-82237LOW3.1filebrowser through 2.63.23 does not remove share records when a shared file is renamed (only deletion triggers share cl...
CVE-2026-82236LOW3.1File Browser versions from 2.63.6 through 2.63.23 fail to clean up public share links when a privileged user deletes ano...
CVE-2026-52681LOW3.1Sieve CPU resource usage is tracked in the compiled script, so an attacker that has valid credentials can reset the acco...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now