2026 CVE Vulnerabilities

43,253 CVEs published in 2026.

Filter:LOWClear
CVE IDSeverityCVSSDescription
CVE-2026-48011LOW3.7Shopware is an open commerce platform. Prior to versions 6.6.10.18 and 6.7.10.1, an attacker is able to enumerate the us...
CVE-2026-46668LOW2.3SpiceDB is an open source database system for creating and managing security-critical application permissions. From vers...
CVE-2026-45380LOW3.6bit7z is a cross-platform C++ static library that allows the compression/extraction of archive files. Prior to version 4...
CVE-2026-50568LOW3.6Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applic...
CVE-2026-46497LOW2.3Crawlee is a web scraping and browser automation library. From version 1.0.0 to before version 1.7.0, Crawlee is vulnera...
CVE-2026-11859LOW2An HTML injection vulnerability in the "fetch links" email sent by Thinkst Applied Research Canarytokens, enabling Inter...
CVE-2026-9060LOW3.5The Store Locator WordPress plugin before 1.6.6 does not sanitize and escape one of its settings before storing it and o...
CVE-2026-29114LOW2.3A vulnerability has been found in some Dahua products. An attacker may obtain the device’s CA root certificate. If that ...
CVE-2026-48289LOW3.5Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by an Improper Input Validation vuln...
CVE-2026-48288LOW3.5Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by an Improper Input Validation vuln...
CVE-2026-45642LOW3.9Improper input validation in Microsoft Azure Attestation service and Device Health Attestation Service allows an authori...
CVE-2026-45485LOW3.3Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
CVE-2026-45466LOW3.3Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
CVE-2026-45459LOW3.3Protection mechanism failure in Microsoft Office Excel allows an unauthorized attacker to bypass a security feature loca...
CVE-2026-42770LOW3.7Issue summary: When EVP_PKEY_derive_set_peer() is called with a DHX (X9.42) peer key, the peer key is not properly check...
CVE-2026-42768LOW3.7Issue summary: The CMS_decrypt and PKCS7_decrypt functions are vulnerable to Bleichenbacher-style attack when an attacke...
CVE-2026-11792LOW3.3A heap buffer overflow flaw was found in 389 Directory Server. When audit logging is enabled, the create_masked_entry_st...
CVE-2026-11764LOW3.6When creating an export of all reusable media, the secrets of connected gift cards were included in the export even if ...
CVE-2026-49738LOW2.1The path allowance check in GeneralUtility::isAllowedAbsPath() performed a plain string prefix comparison without requir...
CVE-2026-41986LOW2.4Logic bypass vulnerability in the file system. Impact: Successful exploitation of this vulnerability may affect availabi...
CVE-2026-41974LOW3.6Permission control vulnerability in service notifications. Impact: Successful exploitation of this vulnerability may aff...
CVE-2026-8981LOW3.5The Custom Block Builder WordPress plugin before 4.3.0 does not consistently check the unfiltered_html capability acros...
CVE-2026-44743LOW3.7Under certain conditions, when an unauthorized attacker accesses a specific endpoint, SAP Business Objects application l...
CVE-2026-11691LOW3.1Insufficient validation of untrusted input in New Tab Page in Google Chrome prior to 149.0.7827.103 allowed a remote att...
CVE-2026-11686LOW3.1Insufficient validation of untrusted input in Dawn in Google Chrome on macOS prior to 149.0.7827.103 allowed a remote at...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now