2026 CVE Vulnerabilities

43,261 CVEs published in 2026.

Filter:LOWClear
CVE IDSeverityCVSSDescription
CVE-2026-28751LOW3.3in OpenHarmony v6.0 and prior versions allow a local attacker cause DOS.
CVE-2026-27781LOW3.3in OpenHarmony v6.0 and prior versions allow a local attacker cause DOS.
CVE-2026-25110LOW3.3in OpenHarmony v6.0 and prior versions allow a local attacker cause DOS.
CVE-2026-27964LOW3.9FacturaScripts is an open source accounting and invoicing software. Versions 2025.7 and prior contain a Reflected Cross-...
CVE-2026-4643LOW3.5Mattermost Desktop App versions <=6.1 6.0.1 5.4.13.0 fail to prevent server-rendered content from closing an underlying ...
CVE-2026-6334LOW3.8Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13 fail to enforce client identity binding during the OAuth autho...
CVE-2026-8770LOW3.3A vulnerability was identified in continuedev continue up to 1.2.22. This affects the function lsTool of the file core/t...
CVE-2026-8741LOW3.1A vulnerability has been found in EMQX up to 6.2.0. This affects an unknown function of the file apps/emqx/src/emqx_pers...
CVE-2026-45316LOW3.5Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.3, the P...
CVE-2026-45803LOW3.5`gh` is GitHub’s official command line tool. From 1.6.0 to before 2.92.0, a security vulnerability has been identified i...
CVE-2026-41963LOW2.8Stack overflow vulnerability in the media platform. Impact: Successful exploitation of this vulnerability may affect ava...
CVE-2026-41962LOW3.6Permission control vulnerability in the app management and control module. Impact: Successful exploitation of this vulne...
CVE-2026-0428LOW1.8Insufficient parameter sanitization in TEE SOC Driver could allow an attacker to issue a malformed DRV_SOC_CMD_ID_SRIOV_...
CVE-2026-45781LOW3.5The MCP Registry provides MCP clients with a list of MCP servers, like an app store for MCP servers. Prior to 1.7.9, OCI...
CVE-2026-8579LOW3.1Insufficient validation of untrusted input in Skia in Google Chrome prior to 148.0.7778.168 allowed a remote attacker wh...
CVE-2026-8578LOW3.1Out of bounds read in GPU in Google Chrome on Linux prior to 148.0.7778.168 allowed a remote attacker who had compromise...
CVE-2026-8572LOW3.1Insufficient policy enforcement in Network in Google Chrome on Android prior to 148.0.7778.168 allowed a remote attacker...
CVE-2026-8556LOW3.1Inappropriate implementation in ANGLE in Google Chrome on Windows prior to 148.0.7778.168 allowed a remote attacker who ...
CVE-2026-8554LOW3.1Type Confusion in ANGLE in Google Chrome on Windows prior to 148.0.7778.168 allowed a remote attacker who had compromise...
CVE-2026-8553LOW3.1Use after free in GPU in Google Chrome prior to 148.0.7778.168 allowed a remote attacker who had compromised the rendere...
CVE-2026-8545LOW3.1Object corruption in Compositing in Google Chrome prior to 148.0.7778.168 allowed a remote attacker who had compromised ...
CVE-2026-8536LOW3.1Insufficient validation of untrusted input in ReadingMode in Google Chrome on Mac prior to 148.0.7778.168 allowed a remo...
CVE-2026-44638LOW2.5libsixel is a SIXEL encoder/decoder implementation derived from kmiya's sixel. From to 1.8.7-r1, a wrong NULL check aft...
CVE-2026-44589LOW3.7Nuxt OG Image generates OG Images with Vue templates in Nuxt. The isBlockedUrl() denylist introduced in nuxt-og-image@6....
CVE-2026-6923LOW3.8A side-channel attack, which requires a physical presence to the TPM, can lead to extraction of an Elliptic Curve Diffie...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now