2026 CVE Vulnerabilities

64,766 CVEs published in 2026.

Filter:LOWClear
CVE IDSeverityCVSSDescription
CVE-2026-63650LOW2OpenVPN 2.7_alpha1 through 2.7.5 using mbedTLS allows remote authenticated users to be misidentified by ignoring the con...
CVE-2026-27871LOW2.9Cwe-327 Use of a Broken or Risky Cryptographic Algorithm vulnerability in Johnson Controls TL280 allows Cryptanalytic At...
CVE-2026-49263LOW2Capstone is a disassembly framework. Prior to version 6.0.0-Alpha9, Capstone's WebAssembly backend accepts attacker-cont...
CVE-2026-73844LOW3.7CKAN MCP Server is a tool for querying CKAN open data portals. Prior to 0.4.112, error paths reflect raw upstream respon...
CVE-2026-47192LOW2.1kas is a setup tool for bitbake based projects. Starting in version 4.8 and prior to version 5.3, kas checks out and pro...
CVE-2026-47191LOW2.1kas is a setup tool for bitbake based projects. Prior to version 5.3, when relying solely on a git commit ID (SHA-1 or S...
CVE-2026-19841LOW3.1A flaw has been found in TRENDNET TEW-813DRU 1.01b01. Impacted is an unknown function of the file /etc/vsftpd.conf of th...
CVE-2026-19837LOW2.7A weakness has been identified in Webkul Bagisto up to 2.4.4. This affects an unknown part of the file /admin/customers/...
CVE-2026-19835LOW3.8A vulnerability was identified in Webkul Bagisto up to 2.4.4. Affected by this vulnerability is an unknown functionality...
CVE-2026-19763LOW3.8A vulnerability was determined in DTStack Taier 1.4.0. Affected by this issue is the function FileUtils.deleteDirectory ...
CVE-2026-19749LOW3.7A vulnerability was detected in Tenda CH7, CH7G, CH10, CP3, CP3 Pro, CP7, TC3B14C, TC3B15C, TC3T14C and TC3T15C up to 20...
CVE-2026-19748LOW3.7A security vulnerability has been detected in Tenda CH7, CH7G, CH10, CP3, CP3 Pro, CP7, TC3B14C, TC3B15C, TC3T14C and TC...
CVE-2026-17071LOW2.7IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to perform file manipulation due to path traver...
CVE-2026-49096LOW3.5Uncaught Exception (CWE-248) in Kibana Cases can lead to denial of service via Input Data Manipulation (CAPEC-153). Malf...
CVE-2026-17043LOW3.8IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to delete arbitrary files due to path traversal...
CVE-2026-58511LOW2.7Webhook Authorization Header Returned in Plaintext via API
CVE-2026-58445LOW2.7Cross-repository label-ID enumeration oracle via unscoped DeleteIssueLabel API
CVE-2026-55984LOW2.7Null Pointer Dereference in AddTime API Causes Authenticated Denial of Service
CVE-2026-23603LOW3.1Blind SSRF in OAuth2 avatar synchronization via unvalidated OIDC picture claim
CVE-2026-73575LOW3.5In Zimbra Collaboration (ZCS) before 10.1.17, a Cross-Site Request Forgery (CSRF) vulnerability exists in the Exchange W...
CVE-2026-6469LOW3.8Incorrect ownership assignment in PostgreSQL ALTER TABLE ALTER TYPE command reassigns ownership of dependent statistics ...
CVE-2026-16241LOW3.8Integer underflow in PostgreSQL ECPG allows a database server administrator to achieve temporary denial of service again...
CVE-2026-14673LOW3.8Untrusted search path in PostgreSQL amcheck allows a grantee of amcheck function EXECUTE privilege to execute arbitrary ...
CVE-2026-14213LOW3.7The Booking for Appointments and Events Calendar WordPress plugin before 2.4.6 does not verify that an authenticated em...
CVE-2026-48791LOW2sigstore-java is a sigstore java client for interacting with sigstore infrastructure. Version 2.0.0 erroneously removed ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now