2026 CVE Vulnerabilities

64,704 CVEs published in 2026.

Filter:LOWClear
CVE IDSeverityCVSSDescription
CVE-2026-67224LOW2.1RabbitMQ is a messaging and streaming broker. Prior to versions 3.13.15, 4.0.20, 4.1.11, 4.2.6, and 4.3.1, The trace con...
CVE-2026-67218LOW2.1RabbitMQ is a messaging and streaming broker. Prior to versions 4.0.22, 4.1.11, 4.2.6, and 4.3.0, accept_content/2 at li...
CVE-2026-66075LOW2.3RabbitMQ is a messaging and streaming broker. Prior to versions 3.13.15, 4.0.20, 4.1.11, 4.2.6, and 4.3.1, is_authorized...
CVE-2026-66069LOW2.3RabbitMQ is a messaging and streaming broker. Prior to versions 4.1.13, 4.2.7, and 4.3.0, is_authorized/2 uses is_author...
CVE-2026-96552LOW3.1A vulnerability was identified in sfturing hosp_order up to 627f426331da8086ce8fff2017d65b1ddef384f8. The affected eleme...
CVE-2026-96550LOW3.7A vulnerability was found in sfturing hosp_order up to 627f426331da8086ce8fff2017d65b1ddef384f8. This issue affects the ...
CVE-2026-66076LOW2.3RabbitMQ is a messaging and streaming broker. Prior to versions 3.13.15, 4.0.20, 4.1.11, 4.2.6, and 4.3.0, is_authorized...
CVE-2026-96872LOW2.9Improper handling of insufficient permissions or privileges vulnerability in The Wikimedia Foundation Mediawiki - WikiLa...
CVE-2026-96549LOW3.3A vulnerability has been found in sfturing hosp_order up to 627f426331da8086ce8fff2017d65b1ddef384f8. This vulnerability...
CVE-2026-96546LOW2.5A one-byte out-of-bounds heap read flaw was found in GIMP's uncompressed DDS image loader. When a user opens an uncompre...
CVE-2026-77285LOW2.4OpenBao is an open source identity-based secrets management system. Prior to 2.6.0, OpenBao Agent's exec rendering mode ...
CVE-2026-71465LOW3.1RunAdHocCommand.build_args() appends limit as bare positional (args.append(limit)) instead of using ...
CVE-2026-71464LOW3.1LaunchConfigurationBaseSerializer.scm_branch has no validate_scm_branch() leading-dash check, unlike ...
CVE-2026-71463LOW2.7Notification template Jinja AST whitelist only inspects static Getattr nodes. Dynamic subscripts (job['job...
CVE-2026-96675LOW3.3alsa-lib through 1.2.16.1 contains a denial of service vulnerability in the multi PCM plugin that fails to validate spar...
CVE-2026-4921LOW2.7IBM Guardium Data Protection 12.2 could allow an administrative user to obtain sensitive information when a detailed tec...
CVE-2026-71178LOW3.7Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Use of Non-Canonical URL Pat...
CVE-2026-78253LOW2.3Uncontrolled recursion in QXmlStreamReader::readElementText() in Qt Group Qt allows attackers to cause a denial of servi...
CVE-2026-77756LOW3.7Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in Apache Tomcat caused b...
CVE-2026-87848LOW3.7The MPCX Lightbox WordPress plugin 1.2.2 through 1.2.5 does not have any authorisation or authentication on one of its A...
CVE-2026-79616LOW0.6Out-of-bounds read while parsing untrusted SVG path strings in Qt Quick's Context2D.path / PathSvg.path.
CVE-2026-93528LOW3.7The NP Quote Request for WooCommerce WordPress plugin before 2.4.16 does not verify order ownership before rendering an ...
CVE-2026-93507LOW3.3The WC Fields Factory WordPress plugin before 4.1.11 does not properly restrict access to, or verify a nonce for, a post...
CVE-2026-91077LOW2.7The Event Booking Manager for WooCommerce WordPress plugin before 5.7.3 does not restrict its event listing query to ev...
CVE-2026-90951LOW3.7The Paid Membership Subscriptions WordPress plugin before 3.1.0 does not bind one of its unauthenticated payment action...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now