2026 CVE Vulnerabilities

64,766 CVEs published in 2026.

Filter:LOWClear
CVE IDSeverityCVSSDescription
CVE-2026-11812LOW2.5The UpdateHub management subsystem (subsys/mgmt/updatehub/updatehub.c) drives every update operation through a single fi...
CVE-2026-11811LOW3.7The UpdateHub over-the-air update client's start_coap_client() in subsys/mgmt/updatehub/updatehub.c leaks the CoAP/DTLS ...
CVE-2026-19411LOW3.9A NULL pointer vulnerability has been found in the the shim application of dp.c library. A missing NULL pointer could al...
CVE-2026-11809LOW3.7The UpdateHub OTA client in subsys/mgmt/updatehub/updatehub.c contains an out-of-bounds / uninitialized-memory read in z...
CVE-2026-6368LOW2.1Calling wordexp with WRDE_APPEND in the GNU C Library version 2.0 to version 2.43 can cause the interface to return inva...
CVE-2026-72729LOW2Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, the discourse-loca...
CVE-2026-18503LOW2.4Attacker-controlled CSV samples can trigger super-linear regular-expression work during dialect sniffing and consume si...
CVE-2026-64941LOW2.1URL Redirection to Untrusted Site ('Open Redirect') vulnerability in phoenixframework phoenix_live_view allows an attack...
CVE-2026-21062LOW3.3Authorization bypass in SemClipboardService prior to SMR Aug-2026 Release 1 allows local attackers to access clipboard d...
CVE-2026-17016LOW3.7The Accept PayPal & Stripe with Subscriptions for WooCommerce WordPress plugin through 3.1.0 does not validate the amoun...
CVE-2026-14211LOW3.8The Booking for Appointments and Events Calendar WordPress plugin before 9.7 does not verify that an authenticated empl...
CVE-2026-12971LOW2.2The LearnPress WordPress plugin before 4.4.4 does not validate a user-supplied URL before the server fetches it, allowi...
CVE-2026-19382LOW2.3A weakness has been identified in Almico Speedfan 4.52. This affects the function KiSystemCall64 in the library speedfan...
CVE-2026-19380LOW2.3A vulnerability was identified in Mullvad wireguard.sys 0.10.1. The affected element is the function AdapterState of the...
CVE-2026-12372LOW3.7A Server-Side Request Forgery (SSRF) vulnerability exists in nltk/nltk versions 3.9.4 and the current develop branch. Th...
CVE-2026-70395LOW2.1Improper Neutralization of Special Elements in Data Query Logic vulnerability in ash-project ash allows an attacker to f...
CVE-2026-19361LOW3.7A flaw has been found in macrozheng mall 0504e86. This vulnerability affects unknown code of the file /sso/getAuthCode o...
CVE-2026-19352LOW3.1A vulnerability was determined in mifi lossless-cut up to 3.69.0. Affected by this issue is some unknown functionality o...
CVE-2026-17011LOW3.8The Nexter Blocks WordPress plugin before 5.0.2 does not restrict who can save global CSS through one of its REST endpo...
CVE-2026-16957LOW2.7The Slim SEO WordPress plugin before 4.9.11 does not restrict a post-meta preview feature to posts the user is allowed ...
CVE-2026-19324LOW3.3A weakness has been identified in HelloGGX shadcn-vue-mcp up to e170e277b94235cde627803277fc8c41103a4d38. Affected by th...
CVE-2026-11742LOW3.6The kernel queue helper z_queue_node_peek() in kernel/queue.c dereferences a node taken from a queue's data_q list, read...
CVE-2026-19245LOW3.3A flaw has been found in HKUDS nanobot up to 0.2.1. The impacted element is the function ExecTool._prepare_command of th...
CVE-2026-71849LOW3.7Hono is a Web application framework that provides support for any JavaScript runtime. From 4.7.0 to 4.12.33, the Proxy H...
CVE-2026-66000LOW2.3Frappe is a full-stack web application framework. Prior to 16.23.0 and 15.112.0, Document Follow notification generation...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now