2026 CVE Vulnerabilities

64,705 CVEs published in 2026.

Filter:LOWClear
CVE IDSeverityCVSSDescription
CVE-2026-87074LOW3.7The Forminator Forms WordPress plugin before 1.57.2.1 does not bind its saved-draft notification to the visitor who cre...
CVE-2026-87069LOW3.1The Forminator Forms WordPress plugin before 1.57.2.1 does not perform a nonce, capability or ownership check before ru...
CVE-2026-84743LOW3.8The Events Calendar WordPress plugin before 6.17.5 does not perform a per-object capability check on one family of its R...
CVE-2026-84742LOW2.7The Events Calendar WordPress plugin before 6.17.5 does not check the capability required to publish content before crea...
CVE-2026-95958LOW3.3A security flaw has been discovered in JusticeRage Manalyze 1.0.0. Impacted is the function PE::_parse_relocations of th...
CVE-2026-18173LOW3.7IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to obtain sensitive informati...
CVE-2026-76909LOW2.1Unleash is an open-source feature management platform. Prior to 8.0.3, the change-request approval email template at src...
CVE-2026-62364LOW2.3wlc is a Weblate command-line client using Weblate's REST API. Prior to 2.0.1, automatically discovered configuration fr...
CVE-2026-95657LOW3.5A vulnerability was determined in dgtlmoon Changedetection.io up to 0.55.8. This issue affects the function setCurrentSe...
CVE-2026-95818LOW3.6A stack-based buffer overflow in the dynamic loader (ld.so) of the GNU C Library (glibc) versions 2.14 through 2.44 allo...
CVE-2026-92706LOW3.4Dark Reader is an accessibility browser extension that makes web pages colors dark. Prior to 4.9.126, a website can caus...
CVE-2026-86698LOW2.3Insufficient Session Expiration vulnerability in OAuth token issuance in hexpm hexpm allows a user whose organization me...
CVE-2026-81884LOW2.5radare2 is a UNIX-like reverse engineering framework and command-line toolset. Prior to 6.2.0, radare2's Mach-O LC_DATA_...
CVE-2026-81883LOW3.3radare2 is a UNIX-like reverse engineering framework and command-line toolset. Prior to 6.2.0, radare2's Lua 5.3 bytecod...
CVE-2026-77637LOW3.8Cloudreve is a self-hosted file management and sharing system. Prior to 4.18.0, tool.GET("wopi") and tool.POST("mail") i...
CVE-2026-95272LOW3.7A vulnerability was found in dgtlmoon changedetection.io up to 0.60.7. This affects the function static_content of the f...
CVE-2026-95270LOW3.7A flaw has been found in dgtlmoon changedetection.io up to 0.60.7. The affected element is the function check_password o...
CVE-2026-94426LOW3.5A vulnerability was determined in xuxueli xxl-job up to 3.5.0. The impacted element is an unknown function of the file /...
CVE-2026-49449LOW2.5Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. From 1.4.0 unt...
CVE-2026-85219LOW3.7Denial-of-Service in Redis module in Thinkst Canary's OpenCanary 0.9.9 allows an unauthenticated remote attacker cause u...
CVE-2026-91165LOW2.4Warpgate is an open source SSH, HTTPS and MySQL bastion host for Linux. Prior to 0.27.6, the response_mode=form_post SSO...
CVE-2026-63416LOW3.7draw.io is a configurable diagramming and whiteboarding application. Prior to version 30.2.7, src/main/java/com/mxgraph/...
CVE-2026-84298LOW3.1Hatchet is a platform for orchestrating background tasks, AI agents, and durable workflows at scale. Prior to 0.95.3, th...
CVE-2026-77166LOW2.4The emoji field in the page emoji update endpoint does not properly validate user input. By injecting long text and line...
CVE-2026-55870LOW2.3GoCD is a continuous deliver server. Prior to 26.1.0, GoCD can return unmasked credentials that administrators stored in...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now