2026 CVE Vulnerabilities

64,763 CVEs published in 2026.

Filter:LOWClear
CVE IDSeverityCVSSDescription
CVE-2026-76371LOW2.7In FireAMP versions below 2.1.15, a user who holds a role that can edit, create, or run playbooks in Splunk SOAR could r...
CVE-2026-76369LOW2.7In Splunk SOAR versions below 8.6.0, a user who holds the OnPrem Broker role could write files outside the intended Auto...
CVE-2026-76368LOW2.7In Splunk SOAR versions below 8.6.0, a user who holds a role that contains the playbooks:view permission could view meta...
CVE-2026-76361LOW2.7In Splunk SOAR versions below 8.6.0, a user with the "Administrator" role could use the /rest/support/connectivity/.../c...
CVE-2026-76348LOW3.8In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who holds a Splunk role that contains the...
CVE-2026-75476LOW3.1Tanium addressed a compression bomb vulnerability in Threat Response.
CVE-2026-68554LOW2.3Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.15.0, an on-path attacker can append att...
CVE-2026-11617LOW3.1Tanium addressed a compression bomb vulnerability in Findings.
CVE-2026-61712LOW2.3BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. P...
CVE-2026-16891LOW3.3IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to obtain sensitive information due to an out...
CVE-2026-16890LOW3.6IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to obtain sensitive information or cause a de...
CVE-2026-16888LOW3.7IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to obtain sensitive information due to a pat...
CVE-2026-73829LOW3.7Time-of-check Time-of-use (TOCTOU) Race Condition in ZenHive mpp allows an unauthenticated remote client to redeem one c...
CVE-2026-75583LOW3.5keeper.sh's calendar module version prior to 2.18.14 contains a server-side request forgery (SSRF) guard bypass vulnerab...
CVE-2026-65610LOW2.4nnn stores homelen variable as uchar_t, which can only represent values in the range 0-255. An attacker who can influenc...
CVE-2026-65609LOW2.4nnn is vulnerable to Out-of-Bound write vulnerability. Due to lack of validation of attacker-controlled length fields de...
CVE-2026-49423LOW3.3When building the iovec array for a received TLS 1.2 CBC record, ktls_ocf_tls_cbc_decrypt() incremented the iovec index ...
CVE-2026-49431LOW3.3The ZFS_IOC_SET_PROP ioctl, used by zfs-set(8), incorrectly validated the calling user such that an unprivileged user is...
CVE-2026-49426LOW3.3When auditing a system call executed via ptrace(PT_SC_REMOTE), the kernel passed the return value of an internal setup f...
CVE-2026-19406LOW2.7The Easy Appointments WordPress plugin before 4.0.1 does not restrict one of its appointment-listing REST endpoints to t...
CVE-2026-14826LOW2.7The Quiz and Survey Master (QSM) WordPress plugin before 11.2.4 does not perform a per-object ownership check on the RE...
CVE-2026-14825LOW2.7The Quiz and Survey Master (QSM) WordPress plugin before 11.2.4 does not perform a per-object ownership check before sa...
CVE-2026-13173LOW2.7The Eventin WordPress plugin before 4.1.21 does not verify the current user's permission to edit other users before ass...
CVE-2026-76014LOW3.3A vulnerability has been found in BusyBox up to 1.30.1. This vulnerability affects unknown code of the file networking/w...
CVE-2026-76042LOW3.1Use of uninitialized resource in GPU in Google Chrome prior to 151.0.7922.169 allowed a remote attacker who had compromi...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now