2026 CVE Vulnerabilities

64,766 CVEs published in 2026.

Filter:LOWClear
CVE IDSeverityCVSSDescription
CVE-2026-73492LOW2.3Loofah is a general library for manipulating and transforming HTML/XML documents and fragments, built on top of Nokogiri...
CVE-2026-73491LOW2.3Loofah is a general library for manipulating and transforming HTML/XML documents and fragments, built on top of Nokogiri...
CVE-2026-73427LOW2.1Trix is a what-you-see-is-what-you-get rich text editor for everyday writing. Prior to 2.1.18, Trix is vulnerable to cro...
CVE-2026-73425LOW3.7Astro is a web framework for content-driven websites. Prior to 8.1.2, the Astro Netlify adapter converts each image.remo...
CVE-2026-18096LOW3.3IBM Db2 12.1.5 for Linux, UNIX and Windows (includes DB2 Connect Server) could allow a local attacker to cause a denial ...
CVE-2026-11937LOW3.1IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 and IBM Verify Ident...
CVE-2026-65926LOW3.1An anonymous caller when anonymous access is enabled, or a low-privilege authenticated user, may learn private Release B...
CVE-2026-49262LOW3In the Aimeos Pagible content management system prior to version 0.10.4, the administrative proxy route (`cmsproxy`) is ...
CVE-2026-70467LOW3.8A server-side request forgery (ssrf) vulnerability in Fortinet FortiSIEM 7.5.0, FortiSIEM 7.4.0 through 7.4.2, FortiSIEM...
CVE-2026-18044LOW3.7The Estatik Real Estate Plugin WordPress plugin before 4.3.4 does not validate the same recipient list that it later use...
CVE-2026-64951LOW3.5A rogue Velociraptor client can upload a malformed sparse file such that if the GUI attempts to expand the file, a panic...
CVE-2026-73283LOW2.5In sshd in OpenSSH before 10.5, the restrict keyword (in authorized_keys) was supposed to be applicable to tunnel forwar...
CVE-2026-73281LOW3.5In ssh-agent in OpenSSH before 10.5, some operations can occur remotely but were intended to occur only locally, includi...
CVE-2026-65655LOW2.3When OAuth authentication is enabled and browser-facing TLS terminates at a reverse proxy that forwards the callback to ...
CVE-2026-73087LOW2.3Dozzle is a realtime log viewer for docker containers. From 10.5.2 until 10.6.15, the isBlockedIP SSRF guard in internal...
CVE-2026-28729LOW2.4Integer overflow in the UEFI firmware for the Intel(R) Slim Bootloader may allow an information disclosure. System softw...
CVE-2026-25194LOW1.8Out-of-bounds write in the firmware for the Intel(R) Slim Bootloader may allow a denial of service. System software adve...
CVE-2026-73071LOW3.3Vim is an open source, command line text editor. From 9.2.0511 until 9.2.0844, json_decode_item() in src/json.c can reta...
CVE-2026-11734LOW2.7A buffer overflow vulnerability in the listed NETGEAR models allows an authenticated admin user to cause the affected de...
CVE-2026-73157LOW2.3Affected versions of cti-transmute render data obtained from a remote MISP instance into the event-browser interface usi...
CVE-2026-11985LOW3.6On the Zephyr ARM port, enabling the hardware FPU (CONFIG_FPU) forces the "Floating point ABI" choice, which defaults to...
CVE-2026-66774LOW3.7SAP Approuter does not consistently handle certain error conditions. An attacker with low privileges could exploit this ...
CVE-2026-58245LOW3.8SAP Advanced Planning and Optimization (Model Mix Planning) contains a hardcoded credential within the source code of th...
CVE-2026-58239LOW3.7SAP Approuter does not sufficiently validate tenant context in inbound requests. An unauthenticated attacker could send ...
CVE-2026-44762LOW3.7SAP Data Services Management Console allows an overly permissive Content Security Policy (CSP) configuration and lacks c...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now