2026 CVE Vulnerabilities

43,261 CVEs published in 2026.

Filter:LOWClear
CVE IDSeverityCVSSDescription
CVE-2026-44515LOW2.3Nextcloud News is an RSS/Atom feed reader. Prior to 28.3.0-beta.1, Nextcloud News allows authenticated users to add feed...
CVE-2026-44348LOW2.5PoDoFo is a C++17 PDF manipulation library. From 1.0.0 to before 1.0.4, a double-free vulnerability exists in compute_ha...
CVE-2026-7471LOW3.5GitLab has remediated an issue in GitLab EE affecting all versions from 18.8 before 18.9.7, 18.10 before 18.10.6, and 18...
CVE-2026-2900LOW2.7GitLab has remediated an issue in GitLab EE affecting all versions from 16.10 before 18.9.7, 18.10 before 18.10.6, and 1...
CVE-2026-33585LOW3.8Improper management of the idle timeout parameter in the Keycloak interface of the Arqit SKA-Platform enables an attacke...
CVE-2026-0238LOW3.2A vulnerability in Palo Alto Networks Broker VM allows an authenticated administrator to inject arbitrary content into c...
CVE-2026-44582LOW3.7Next.js is a React framework for building full-stack web applications. From 13.4.6 to before 15.5.16 and 16.2.5, React S...
CVE-2026-44459LOW3.8Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.18, improper validat...
CVE-2026-42158LOW2.3Flowsint is an open-source OSINT graph exploration tool designed for cybersecurity investigation, transparency, and veri...
CVE-2026-44242LOW3.7Micronaut Framework is a JVM-based full stack Java framework designed for building modular, easily testable JVM applicat...
CVE-2026-44220LOW3.2ciguard is a static security auditor for CI/CD pipelines. From 0.8.0 to 0.8.1 , the discover_pipeline_files() function i...
CVE-2026-44219LOW3.7ciguard is a static security auditor for CI/CD pipelines. From 0.6.0 to 0.8.1, both SCA HTTP clients (src/ciguard/analyz...
CVE-2026-44218LOW3ciguard is a static security auditor for CI/CD pipelines. From 0.1.0 to 0.8.1, the published ghcr.io/jo-jo98/ciguard con...
CVE-2026-34685LOW3.4Adobe Commerce versions 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 and earlier are affected by an ...
CVE-2026-41611LOW3.3Improper neutralization of script-related html tags in a web page (basic xss) in Visual Studio Code allows an unauthoriz...
CVE-2026-20793LOW3.3Unchecked return value for some Intel(R) QAT software drivers for Windows before version 1.13 within Ring 3: User Applic...
CVE-2026-43514LOW3.7Observable Timing Discrepancy vulnerability when comparing AJP secret in Apache Tomcat. This issue affects Apache Tomca...
CVE-2026-32684LOW2.9The application does not impose strict enough restrictions on directory access permissions, posing a risk that other mal...
CVE-2026-40131LOW3.4SQL injection vulnerability exists in @sap/hdi-deploy package, where SQL queries are dynamically constructed using user ...
CVE-2026-45362LOW3.2Sangoma Switchvox before 8.4 places cleartext SIP authentication credentials in a backup file.
CVE-2026-42188LOW2.4Geyser is a bridge between Minecraft: Bedrock Edition and Minecraft: Java Edition. Prior to 2.9.3, a server-side request...
CVE-2026-28957LOW3.3An issue with app access to camera metadata was addressed with improved logic. This issue is fixed in iOS 18.7.9 and iPa...
CVE-2026-28910LOW3.3This issue was addressed with improved permissions checking. This issue is fixed in macOS Tahoe 26.4. A malicious app ma...
CVE-2026-42874LOW3.7Microdot is a minimalistic Python web framework. Prior to 2.6.1, the Response.set_cookie() method does not sanitize its ...
CVE-2026-43969LOW3.2Improper Neutralization of CRLF Sequences ('CRLF Injection') vulnerability in ninenines cowlib allows HTTP request split...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now