2026 CVE Vulnerabilities

64,763 CVEs published in 2026.

Filter:LOWClear
CVE IDSeverityCVSSDescription
CVE-2026-79777LOW2.7rclone before v1.75.0 includes full Go stack traces in RC API error responses when panics occur. Attackers can trigger p...
CVE-2026-70548LOW3.5Under specific circumstances, low-level user can run request to remote CocoaPods repos via JFrog Artifactory External De...
CVE-2026-15310LOW2.1When decompressing crafted zip files using the bzip/LZMA/Zstandard compressions, Python could use an attacker-controll...
CVE-2026-78887LOW3.7A weakness has been identified in liketrek TREK up to 3.0.22. This impacts the function validateShareTokenForAsset of th...
CVE-2026-78886LOW3.7A security flaw has been discovered in liketrek TREK up to 3.0.22. This affects an unknown function of the file server/s...
CVE-2026-21758LOW3.7HCL Hive is affected by an information disclosure vulnerability, which could lead to an attacker gathering sensitive inf...
CVE-2026-66882LOW2.1Improper Neutralization of Input During Web Page Generation (XSS) vulnerability in team-alembic AshAuthentication allows...
CVE-2026-78638LOW3.3A flaw has been found in peerigon unzip-crx and unzip-crx-3 up to 0.2.0. This affects the function unzip of the file dis...
CVE-2026-72701LOW3.7Grav CMS before 2.0.16 contains a timing vulnerability in Utils::verifyNonce() that uses non-constant-time string compar...
CVE-2026-16434LOW2.3Adminer 4.6.0 through 5.5.0 (fixed in 5.5.1) contains an incomplete fix for a prior X-Forwarded-Prefix vulnerability (GH...
CVE-2026-78435LOW3.8A vulnerability has been found in Faveo Helpdesk up to 2.0.3. Affected is the function unlink of the file app/Http/Contr...
CVE-2026-75554LOW2.3Insufficient Session Expiration vulnerability in the OAuth token refresh grant in hexpm hexpm allows a user removed from...
CVE-2026-76816LOW3.5Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.137.Final and 4.2.17.Final, ...
CVE-2026-78187LOW3.1A vulnerability has been found in Piwigo 16.3.0. This impacts an unknown function of the component Public Authentication...
CVE-2026-19565LOW3.7Apache::AppSamurai::Util versions through 1.01 for Perl generate predictable session authentication keys from the clock ...
CVE-2026-77003LOW2.7The Content Mask WordPress plugin before 1.8.5.5 does not check the capability required to publish the post type being c...
CVE-2026-78049LOW3.7A vulnerability has been found in Systerel S2OPC up to 1.7.3. Impacted is the function SOPC_NodeMgtHelperInternal_AddVar...
CVE-2026-71514LOW3.3NLTK 3.9.4 through 3.10.2 contains a path traversal vulnerability in CrubadanCorpusReader. _load_lang_ngrams joins the c...
CVE-2026-14187LOW2.7The Tutor LMS WordPress plugin before 4.0.6 does not enforce per-object ownership checks on its course content type, al...
CVE-2026-33333LOW3.5Combodo iTop is a web based IT service management tool. Prior to 3.2.3, there is sensitive information disclosure in the...
CVE-2026-48756LOW2.1Incus is a system container and virtual machine manager. Prior to version 7.1.0, `(*backend).CreateCustomVolumeFromBacku...
CVE-2026-48754LOW2.1Incus is a system container and virtual machine manager. Prior to version 7.1.0, `(*backend).createDependentVolumesFromB...
CVE-2026-18356LOW3.7The Limit Login Attempts Reloaded WordPress plugin before 3.3.5 does not compare logins against its username denylist ca...
CVE-2026-13176LOW2.7The Eventin WordPress plugin before 4.1.21 does not validate a user-supplied webhook URL stored on events nor verify eve...
CVE-2026-48590LOW2.1XML Injection vulnerability in joshnuss xml_builder (XmlBuilder module) allows Content Spoofing, XML Injection. This vu...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now