2026 CVE Vulnerabilities

43,031 CVEs published in 2026.

Filter:LOWClear
CVE IDSeverityCVSSDescription
CVE-2026-16993LOW3.7The DHL Shipping Germany for WooCommerce WordPress plugin before 4.0.1 does not protect its shipping-label storage direc...
CVE-2026-16746LOW2.7The MultiVendorX WordPress plugin before 5.0.11 does not verify that the requested store belongs to the current user in...
CVE-2026-18852LOW3.3A vulnerability has been found in epsilla-cloud vectordb up to 0.3.18/df5a5f5afb85a2376a0f2f316c79dea9b2c6ac7a. This imp...
CVE-2026-18817LOW2.2A security flaw has been discovered in Baserow up to 2.3.2. Affected by this issue is the function BaserowImpersonateAut...
CVE-2026-70483LOW3.1Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.6 until 0.11.0, DELETE /a...
CVE-2026-16791LOW3.9A temporary file creation vulnerability in the Linux version of Lenovo XClarity Essentials OneCLI 5.5.0 and below could ...
CVE-2026-18790LOW3.3A weakness has been identified in Systerel S2OPC up to 1.7.3. This affects the function LockedStaMac_ProcessMsg_DeleteMo...
CVE-2026-66884LOW2.1Cross-Site Request Forgery vulnerability in Erlang Ecosystem Foundation oidcc_plug (Oidcc.Plug.AuthorizationCallback mod...
CVE-2026-16070LOW2.7The Brizy WordPress plugin before 2.8.19 does not properly verify authorization on the object being modified before upd...
CVE-2026-16068LOW3.5The Brizy WordPress plugin before 2.8.19 does not properly restrict who can modify its site-global design data and does...
CVE-2026-11366LOW3.7The MonsterInsights WordPress plugin before 11.1.0 does not correctly validate the signature on one of its unauthentica...
CVE-2026-68744LOW3.3A flaw was found in SSSD. The sss_nss_protocol_fill_initgr() function in the NSS responder pre-allocates reply space for...
CVE-2026-18739LOW2.5A flaw was found in popt, a command-line option parsing library. An off-by-one error in the poptStuffArgs function, when...
CVE-2026-18569LOW3.7A flaw was found in the backchannel logout endpoint of the keycloak-services component, which is part of the Red Hat Bui...
CVE-2026-58044LOW3.7A flaw in Node.js HTTP client can cause a request desynchronization for Node.js-based forwarding proxies that rebuild ou...
CVE-2026-11836LOW1.8Insufficient verification of data authenticity in Caliptra Core ROM and Core Firmware (validate_debug_unlock_token()) in...
CVE-2026-46712LOW2.3Misskey is an open source, federated social media platform. Versions 2025.3.2 and later, but prior to 2026.5.4, contain ...
CVE-2026-18682LOW3.1A security flaw has been discovered in OpenAkita up to 1.27.12. This vulnerability affects unknown code of the file /api...
CVE-2026-63545LOW2.4Sharp and Toshiba Tec MFPs (multifunction printers) caches data internally when printing, and leave them uncleared. They...
CVE-2026-18591LOW2.1A vulnerability was identified in Meesho Online Shopping App up to 20260607 on Android. Affected by this vulnerability i...
CVE-2026-16276LOW2.7The Classified Listing WordPress plugin before 5.4.4 does not perform a capability check on an AJAX action that returns...
CVE-2026-16274LOW2.7The Classified Listing WordPress plugin before 5.4.4 does not perform a capability or ownership check on an AJAX action...
CVE-2026-15231LOW2.7The Tag, Category, and Taxonomy Manager WordPress plugin before 3.51.0 does not verify that a user is authorized to acc...
CVE-2026-18581LOW3.3A vulnerability was determined in ggml-org llama.cpp e15efe0. Affected by this issue is some unknown functionality of th...
CVE-2026-15939LOW2.7The Simple Restrict WordPress plugin before 1.2.9 does not enforce its content-restriction permission check on the REST ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now