2026 CVE Vulnerabilities

43,261 CVEs published in 2026.

Filter:LOWClear
CVE IDSeverityCVSSDescription
CVE-2026-6610LOW3.7A vulnerability has been found in liangliangyy DjangoBlog up to 2.1.0.0. The impacted element is an unknown function of ...
CVE-2026-6600LOW3.5A flaw has been found in langflow-ai langflow up to 1.8.3. This affects an unknown function of the file src/frontend/src...
CVE-2026-6597LOW2.7A weakness has been identified in langflow-ai langflow up to 1.8.3. Impacted is the function remove_api_keys/has_api_ter...
CVE-2026-6593LOW3.5A vulnerability was found in ComfyUI up to 0.13.0. Affected by this issue is some unknown functionality of the file serv...
CVE-2026-6592LOW3.5A vulnerability has been found in ComfyUI up to 0.13.0. Affected by this vulnerability is the function getuserdata of th...
CVE-2026-6570LOW2.7A security flaw has been discovered in kodcloud KodExplorer up to 4.52. Affected is the function initInstall of the file...
CVE-2026-32690LOW3.7Secrets in Variables saved as JSON dictionaries were not properly redacted - in case thee variables were retrieved by th...
CVE-2026-40341LOW3.5libgphoto2 is a camera access and control library. In versions up to and including 2.5.33, an out of bound read in ptp_u...
CVE-2026-40336LOW2.4libgphoto2 is a camera access and control library. Versions up to and including 2.5.33 have a memory leak in `ptp_unpack...
CVE-2026-40334LOW3.5libgphoto2 is a camera access and control library. In versions up to and including 2.5.33, a missing null terminator exi...
CVE-2026-35402LOW2.3mcp-neo4j-cypher is an MCP server for executing Cypher queries against Neo4j databases. In versions prior to 0.6.0, the ...
CVE-2026-6493LOW3.5A flaw has been found in lukevella rallly up to 4.7.4. This affects an unknown function of the file apps/web/src/app/[lo...
CVE-2026-6486LOW3.5A vulnerability was detected in classroombookings up to 2.17.0. This impacts the function read of the file crbs-core/app...
CVE-2026-40263LOW3.7Note Mark is an open-source note-taking application. In versions 0.19.1 and prior, the login endpoint performs bcrypt pa...
CVE-2026-41080LOW2.9libexpat before 2.8.0 uses insufficient entropy, and thus hash flooding can occur via a crafted XML document.
CVE-2026-3155LOW3.1The OneSignal – Web Push Notifications plugin for WordPress is vulnerable to authorization bypass in versions up to, and...
CVE-2026-40947LOW2.9Yubico libfido2 before 1.17.0, python-fido2 before 2.2.0, and yubikey-manager before 5.9.1 have an unintended DLL search...
CVE-2026-6313LOW3.1Insufficient policy enforcement in CORS in Google Chrome prior to 147.0.7727.101 allowed a remote attacker who had compr...
CVE-2026-6312LOW3.1Insufficient policy enforcement in Passwords in Google Chrome prior to 147.0.7727.101 allowed a remote attacker who had ...
CVE-2026-33877LOW3.7ApostropheCMS is an open-source Node.js content management system. Versions 4.28.0 and prior contain a timing side-chann...
CVE-2026-21727LOW3.3--- title: Cross-Tenant Legacy Correlation Disclosure and Deletion draft: false hero: image: /static/img/heros/hero-le...
CVE-2026-33212LOW3.1Weblate is a web based localization tool. In versions prior to 5.17, the tasks API didn't verify user access for pending...
CVE-2026-27769LOW2.7Mattermost versions 10.11.x <= 10.11.12 fail to validate whether users were correctly owned by the correct Connected Wor...
CVE-2026-34454LOW3.5OAuth2 Proxy is a reverse proxy that provides authentication using OAuth2 providers. A regression introduced in 7.11.0 p...
CVE-2026-27308LOW2.4ColdFusion versions 2023.18, 2025.6 and earlier are affected by an Uncontrolled Resource Consumption vulnerability that ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now