2026 CVE Vulnerabilities

64,763 CVEs published in 2026.

Filter:LOWClear
CVE IDSeverityCVSSDescription
CVE-2026-47080LOW2.1XML Injection vulnerability in joshnuss xml_builder (XmlBuilder module) allows Content Spoofing, XML Injection. This vu...
CVE-2026-47079LOW2.1Inappropriate Encoding for Output Context vulnerability in joshnuss xml_builder (XmlBuilder module) allows Content Spoof...
CVE-2026-66721LOW2.7Missing authorization issue for domain admins in CloudStack's host tags listing functionality. Domain Admins, by def...
CVE-2026-19435LOW2.7The Duplicate Post WordPress plugin before 1.5.6 does not check the user's capabilities before returning post data, allo...
CVE-2026-19085LOW2.7The Duplicate Post WordPress plugin before 1.5.6 does not check that a user may read the content of a post before duplic...
CVE-2026-16577LOW2.7The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution WordPress plugin before 5.0.14 does not validate a c...
CVE-2026-14325LOW3.5The Drag and Drop Multiple File Upload for Contact Form 7 WordPress plugin before 1.3.9.9 does not escape one of its set...
CVE-2026-76137LOW3.3Missing authentication for critical function vulnerability exists in VOCALOID6. Any process running under the same local...
CVE-2026-43679LOW2.4This issue was addressed with improved permissions checking. This issue is fixed in watchOS 26.4. An attacker with physi...
CVE-2026-77648LOW2.2In OpenStack Glance through 32.0.0, the /v2/tasks API accepts type=import tasks that bypass import_filtering_opts, allow...
CVE-2026-54505LOW2TREK is a collaborative travel planner. Prior to 3.1.0, when the Journey add-on is enabled, TREK interpolates the unesca...
CVE-2026-49245LOW3.7SFTPGo is an open source, event-driven file transfer solution. From 2.2.0 until 2.7.3, the inline query parameter on bro...
CVE-2026-70652LOW2libvips is a fast image processing library with low memory needs. Prior to version 8.18.3, libvips built with libultrahd...
CVE-2026-77151LOW3.7A security flaw has been discovered in lin-snow Ech0 up to 5.4.1. Affected by this issue is the function MD5Encrypt of t...
CVE-2026-66788LOW3.7A flaw was found in Lighthouse. A remote attacker, by compromising a spoke cluster, can exploit a vulnerability where th...
CVE-2026-66785LOW2.5A flaw was found in Submariner. This vulnerability allows a malicious cluster (spoke) to redirect network traffic from o...
CVE-2026-49996LOW3.7SecureDrop Client is a desktop app for journalists to securely communicate with sources and handle submissions on the Se...
CVE-2026-64846LOW2.8Nix is a package manager for Linux and other Unix systems. Prior to 2.35.0, a malicious derivation executed with the rec...
CVE-2026-18283LOW2.4Sony XAV-9500ES udev USB Rules Authorization Bypass Vulnerability. This vulnerability allows physically present attacker...
CVE-2026-18280LOW3.9Sony XAV-9500ES gpsd Buffer Overflow Arbitrary Code Execution Vulnerability. This vulnerability allows physically presen...
CVE-2026-18278LOW3.5Sony XAV-9500ES prh_l2_decode_packet Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows ...
CVE-2026-64963LOW2.3A path traversal vulnerability in ATutor allows an authenticated user to access files from other course directories when...
CVE-2026-7485LOW2.3Incorrect authorization in frozen BI aggregations in Checkmk <2.5.0p2, <2.4.0p29, <2.3.0p47, and all 2.2.0 versions allo...
CVE-2026-73542LOW3.7Multiple SEIKO EPSON printers and scanners contain revoked root certificates. A man-in-the-middle attack may allow an at...
CVE-2026-19699LOW2.7The GutenKit WordPress plugin before 2.5.0 does not have a sufficient capability check on some of its REST API endpoint...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now