2026 CVE Vulnerabilities

43,261 CVEs published in 2026.

Filter:LOWClear
CVE IDSeverityCVSSDescription
CVE-2026-35249LOW3.2Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version th...
CVE-2026-34312LOW2.4Vulnerability in the RDBMS component of Oracle Database Server. Supported versions that are affected are 19.3-19.30. Ea...
CVE-2026-34268LOW2.9Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE...
CVE-2026-22018LOW3.7Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE...
CVE-2026-22014LOW3.8Vulnerability in the Oracle User Management product of Oracle E-Business Suite (component: Workflow and Business Events)...
CVE-2026-22008LOW3.7Vulnerability in Oracle Java SE (component: Libraries). The supported version that is affected is Oracle Java SE: 25.0...
CVE-2026-22007LOW2.9Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE...
CVE-2026-22001LOW2.7Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Information Schema). Supported versions t...
CVE-2026-40878LOW2.1mailcow: dockerized is an open source groupware/email suite based on docker. In versions prior to 2026-03b, the mailcow ...
CVE-2026-6745LOW3.5A vulnerability was determined in Bagisto up to 2.3.15. Affected by this vulnerability is an unknown functionality of th...
CVE-2026-6743LOW3.5A vulnerability has been found in WebSystems WebTOTUM 2026. This impacts an unknown function of the component Calendar. ...
CVE-2026-40279LOW3.7BACnet Stack is a BACnet open source protocol stack C library for embedded systems. Prior to 1.4.3, decode_signed32() in...
CVE-2026-29179LOW3.3October is a Content Management System (CMS) and web platform. Prior to 3.7.16 and 4.1.16, fine-grained sub-permission c...
CVE-2026-27937LOW3.1October is a Content Management System (CMS) and web platform. Prior to 3.7.16 and 4.1.16, a reflected Cross-Site Script...
CVE-2026-31369LOW3.2PcManager is affected by type privilege bypass, successful exploitation of this vulnerability may affect service availab...
CVE-2026-40264LOW2.7OpenBao is an open source identity-based secrets management system. OpenBao's namespaces provide multi-tenant separation...
CVE-2026-39388LOW3.1OpenBao is an open source identity-based secrets management system. Prior to version 2.5.3, OpenBao's Certificate authen...
CVE-2026-6651LOW2.4A security flaw has been discovered in erponline.xyz ERP Online up to 4.0.0. This vulnerability affects unknown code of ...
CVE-2026-6648LOW3.5A vulnerability was found in Qibo CMS 1.0. Affected by this vulnerability is an unknown functionality of the component I...
CVE-2026-6633LOW3.5A security flaw has been discovered in Yifang CMS up to 2.0.5. The impacted element is the function store of the file pl...
CVE-2026-5958LOW2.1When sed is invoked with both -i (in-place edit) and --follow-symlinks, the function open_next_file() performs two separ...
CVE-2026-6624LOW2.4A weakness has been identified in BichitroGan ISP Billing Software 2025.3.20. Affected is an unknown function of the fil...
CVE-2026-6622LOW2.4A vulnerability was identified in BichitroGan ISP Billing Software 2025.3.20. This affects an unknown function of the fi...
CVE-2026-6619LOW3.5A vulnerability has been found in langgenius dify up to 1.13.3. Impacted is the function openInNewTab of the file web/ap...
CVE-2026-6611LOW3.1A vulnerability was found in liangliangyy DjangoBlog up to 2.1.0.0. This affects an unknown function of the file djangob...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now