2026 CVE Vulnerabilities

64,760 CVEs published in 2026.

Filter:LOWClear
CVE IDSeverityCVSSDescription
CVE-2026-81102LOW3.1The Dash MCP server bound its listener to the loopback address but never checked the host a request named. src/mcp_serve...
CVE-2026-56651LOW2Dool in versions up to 1.3.8 is vulnerable to symlink following when the "--devel" flag is used, as the application open...
CVE-2026-13416LOW3.5The CMP WordPress plugin before 4.1.18 does not sanitise and escape a settings value before outputting it on the coming...
CVE-2026-21807LOW3.9HCL BigFix Quantum Risk Analyzer binary lacks several critical, industry-standard hardening protections that could allow...
CVE-2026-21809LOW3.9HCL BigFix Quantum Risk Analyzer has a certain validation process that provides overly descriptive error messages when i...
CVE-2026-77573LOW3.5Weblate is a web-based continuous localization platform used to manage software translations. In versions prior to 2026....
CVE-2026-77508LOW3.5Weblate is a web based localization tool. Prior to 2026.8, an authenticated user can change the account's primary email ...
CVE-2026-56547LOW3.5The Apple profile generated for the Apple built-in Mail, Calendar and Contacts account to synchronize with HCL Traveler ...
CVE-2026-47844LOW3.7In specific scenarios, the Reactor Netty HTTP Server may leak exception details across unrelated requests. In order for ...
CVE-2026-47843LOW3.7In specific scenarios involving multiple clients with different DNS resolver configurations, Reactor Netty may incorrect...
CVE-2026-54548LOW3.3kas is a setup tool for bitbake based projects. Prior to 5.4, internal SSH key setup triggered by SSH_PRIVATE_KEY or SSH...
CVE-2026-13480LOW3.1The LoRaWAN TS004 Fragmented Data Block Transport handler frag_transport_package_callback() in subsys/lorawan/services/f...
CVE-2026-7487LOW3.5GitLab has remediated an issue in GitLab EE affecting all versions from 13.1 before 19.1.7, 19.2 before 19.2.5, and 19.3...
CVE-2026-58108LOW1.2The personal access token removal query selects from PersonalAccessTokenDB but filters on columns of Session, with no jo...
CVE-2026-15366LOW2.4A control logic defect in a specific built-in webpage of Kids Mode allows users to view local gallery photos directly wi...
CVE-2026-15365LOW2.4A pop-up logic flaw in a certain feature of Kids Mode allows users to bypass password verification and use Quick Apps ou...
CVE-2026-19220LOW3.7The Forminator Forms WordPress plugin before 1.57.1 does not verify that site registration is enabled on the network be...
CVE-2026-9805LOW2.7SMM IHISI command handler, FMTSWriteUseIntelLib, for FMTS command 0x32, read and write data without checking buffer size...
CVE-2026-80201LOW2Kimai before 2.53.0 fails to block sensitive User methods in the Twig invoice template sandbox, allowing admins to call ...
CVE-2026-80199LOW3.7Kimai before 2.54.0 contains a timing oracle vulnerability in TokenAuthenticator that allows unauthenticated attackers t...
CVE-2026-79289LOW3.1Improper control of a resource through its lifetime in Workers in Google Chrome prior to 152.0.7977.65 allowed a remote ...
CVE-2026-79272LOW3.1Improper input validation in FindInPage in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compro...
CVE-2026-79255LOW3.1Improper input validation in WebRTC in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromise...
CVE-2026-79228LOW3.1Incorrect authorization in SiteIsolation in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compr...
CVE-2026-79203LOW3.1Improper input validation in DevTools in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromi...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now