2026 CVE Vulnerabilities

43,261 CVEs published in 2026.

Filter:LOWClear
CVE IDSeverityCVSSDescription
CVE-2026-10078LOW2.7A flaw was found in the Quay config-tool's GitLab OAuth validator. This vulnerability causes sensitive credentials, spec...
CVE-2026-9991LOW3.1Inappropriate implementation in Media in Google Chrome on Windows prior to 148.0.7778.216 allowed a remote attacker who ...
CVE-2026-9959LOW3.1Race in WebRTC in Google Chrome on Windows prior to 148.0.7778.216 allowed a remote attacker to leak cross-origin data v...
CVE-2026-9950LOW3.1Insufficient validation of untrusted input in iOS in Google Chrome on iOS prior to 148.0.7778.216 allowed a remote attac...
CVE-2026-9944LOW3.1Uninitialized Use in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the re...
CVE-2026-9920LOW3.1Uninitialized Use in GPU in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attacker who had compromis...
CVE-2026-6816LOW3.8An access bypass vulnerability in Drupal TFA Basic Plugins allows users with the administer users permission to view or ...
CVE-2026-10011LOW3.1Inappropriate implementation in Skia in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromi...
CVE-2026-45403LOW2.5AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatti...
CVE-2026-47337LOW3.3Ubuntu Linux 6.8, 6.17 and 7.0 contain SAUCE patches with a possible NULL pointer dereference in the handling of AF_INET...
CVE-2026-47336LOW3.3Ubuntu Linux 6.8 contains SAUCE patches with a possible use of an uninitialized variable in AppArmor AF_INET/AF_INET6 so...
CVE-2026-47330LOW3.3Ubuntu Linux 6.8, 7.17 and 7.0 contain AppArmor SAUCE patches which can, under certain circumstances, use an uninitializ...
CVE-2026-47329LOW3.3Ubuntu Linux 6.8, 6.17 and 7.0 contain SAUCE patches which fail to validate invalid sizes of the name field in AppAmor n...
CVE-2026-47327LOW3.3Ubuntu Linux 6.8, 6.17 and 7.0 contain SAUCE patches with a possible NULL pointer dereference in the handling of AppArmo...
CVE-2026-45076LOW2.7Synapse is an open source Matrix homeserver implementation. Prior to 1.152.1, in federated rooms, malicious homeservers ...
CVE-2026-48524LOW3.7PyJWT is a JSON Web Token implementation in Python. Prior to 2.13.0, PyJWKClient.get_signing_key() forces a fresh HTTP r...
CVE-2026-48156LOW3.3pypdf is a free and open-source pure-python PDF library. Prior to 6.12.0, an attacker who uses this vulnerability can cr...
CVE-2026-9828LOW2.9Deserialization of untrusted data vulnerability in QOS.CH Sarl logback logback-core (HardenedObjectInputStream (logback-...
CVE-2026-49009LOW3.1Northern.tech Mender Server v4.1.0, v4.0.1 and below, and fixed in v4.1.1 and v4.0.2 allows Directory Traversal.
CVE-2026-33552LOW3.7Northern.tech Mender Enterprise Server before 4.1.1 has Incorrect Access Control.
CVE-2026-44474LOW3.7Ella Core is a 5G core designed for private networks. Prior to 1.10.0, Ella Core didn't enforce security rules on concur...
CVE-2026-9712LOW3.8When creating an export through the pretix API, API clients are returned an UUID value for their export job (a long, ra...
CVE-2026-46057LOW3.3In the Linux kernel, the following vulnerability has been resolved: landlock: Fix LOG_SUBDOMAINS_OFF inheritance across...
CVE-2026-42791LOW3.7Improper Certificate Validation vulnerability in Erlang OTP public_key (pubkey_ocsp module) allows forged OCSP responses...
CVE-2026-9608LOW2.4A vulnerability was determined in QianFox FoxCMS up to 1.2.6. The impacted element is an unknown function of the file /T...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now