2026 CVE Vulnerabilities

64,760 CVEs published in 2026.

Filter:LOWClear
CVE IDSeverityCVSSDescription
CVE-2026-42393LOW3.1The comparison used for the doveadm password and API key is not fully timing safe and can reveal the length of the confi...
CVE-2026-40204LOW3.1None None None No publicly available exploits are known.
CVE-2026-40203LOW3.7When IMAP compression is enabled, the same compression state is reused across responses in a session, so response sizes ...
CVE-2026-79615LOW2.7The Quiz and Survey Master (QSM) WordPress plugin before 11.2.4 does not check authorisation when returning question ba...
CVE-2026-81848LOW3.5A vulnerability was determined in cyberchitta scrapling-fetch-mcp up to 0.2.2. The impacted element is the function s_fe...
CVE-2026-81836LOW3.7A vulnerability was detected in RooCodeInc Roo-Code up to 3.51.1. This vulnerability affects unknown code of the file sr...
CVE-2026-59314LOW3.7Applications that build a Content-Disposition header value from untrusted input may be vulnerable to HTTP response split...
CVE-2026-59306LOW3.8Potential for deserialization of untrusted types in Spring Cloud Stream. Spring Cloud Stream 5.0.0 - 5.0.2 Spring Cloud ...
CVE-2026-59305LOW3.8Partition interceptor may be improperly added while sending message. Spring Cloud Stream 5.0.0 - 5.0.2 Spring Cloud Stre...
CVE-2026-59304LOW3.8Improper caching of the original content type in Spring Cloud Stream Avro. Spring Cloud Stream 5.0.0 - 5.0.2 Spring Clou...
CVE-2026-59303LOW3.8Dynamic destination cache size is not properly bound in Spring Cloud Stream. Spring Cloud Stream 5.0.0 - 5.0.2 Spring Cl...
CVE-2026-59300LOW3.5Potential for logging sensitive data in Spring Cloud Function AWS. Spring Cloud Function 5.0.0 - 5.0.3 Spring Cloud Func...
CVE-2026-59299LOW3.5Composition lookup can potentially poison base function in Spring Cloud Function. Spring Cloud Function 5.0.0 - 5.0.3 Sp...
CVE-2026-59298LOW3.5Potential for improper filtering of HTTP headers in Spring Cloud Function. Spring Cloud Function 5.0.0 - 5.0.3 Spring Cl...
CVE-2026-59297LOW3.5Implementation of isSecure() call of ServerlessHttpServletRequest does not verify the actual scheme. Spring Cloud Functi...
CVE-2026-59292LOW3.2PropertiesPersistingMetadataStore, the default file-based ConcurrentMetadataStore, persists its state to ${java.io.tmpdi...
CVE-2026-54713LOW3.7CakePHP Queue is a queue-interop compatible queueing library. From 0.1.11 until 2.3.1, QueueManager::getUniqueId() gener...
CVE-2026-81725LOW3.7NLTK before 3.10.3 contains a regular expression denial of service vulnerability in Pl196xCorpusReader that allows attac...
CVE-2026-81723LOW3.7NLTK versions before 3.10.3 contain a quadratic CPU exhaustion vulnerability in XMLCorpusView._read_xml_fragment() that ...
CVE-2026-81717LOW3.5openssl_encrypt (pip package openssl-encrypt) before 1.4.9 contains two weaknesses in the portable USB drive feature, wh...
CVE-2026-81715LOW3.3openssl_encrypt (pip package openssl-encrypt) versions <= 1.4.8 do not redact the keyserver bearer token passed as the p...
CVE-2026-81696LOW3.3openssl_encrypt versions before 1.4.9 fail to sanitize terminal control characters in file metadata printed by the info ...
CVE-2026-81695LOW3.3openssl_encrypt versions before 1.4.9 fail to escape attacker-controlled key_id values printed to stderr during decrypt ...
CVE-2026-81694LOW3.3openssl-encrypt (pip package, versions <= 1.4.8) fails to sanitize filenames read from untrusted drive data (outside the...
CVE-2026-81685LOW3.3openssl_encrypt versions before 1.4.9 fail to sanitize recovery-slot metadata in the desktop GUI, allowing attackers to ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now