2026 CVE Vulnerabilities

64,772 CVEs published in 2026.

Filter:LOWClear
CVE IDSeverityCVSSDescription
CVE-2026-10684LOW3In subsys/debug/coredump/coredump_shell.c, print_coredump_hdr() used the 16-bit tgt_code field of a stored Zephyr coredu...
CVE-2026-52791LOW2fuse-overlayfs is an implementation of overlayfs in FUSE for rootless containers. Prior to 1.17, the release-1.x C branc...
CVE-2026-63241LOW3.1An insecure direct object reference vulnerability in Koollab LMS allowed an authenticated user to query the course compl...
CVE-2026-63236LOW3.7An improper access control vulnerability in Koollab LMS allowed an unauthenticated attacker to read another user's name,...
CVE-2026-63235LOW3.7An improper access control vulnerability in Koollab LMS allowed an unauthenticated attacker to forcibly terminate the se...
CVE-2026-63228LOW2.6An unrestricted image upload vulnerability in Koollab LMS allowed an authenticated attacker to upload malicious content ...
CVE-2026-55403LOW3.7datamodel-code-generator generates Python data models from schema definitions. Prior to 0.63.0, src/datamodel_code_gener...
CVE-2026-54620LOW2sqlite3 provides Ruby bindings for the SQLite3 embedded database. From 2.1.0 to 2.9.4, the callbacks used for SQLite agg...
CVE-2026-54619LOW2sqlite3 provides Ruby bindings for the SQLite3 embedded database. In version 2.9.4 and earlier, redefining a SQLite func...
CVE-2026-6879LOW2`Element.findall()` and fully-consumed `Element.iterfind()` exhibit `O(n^2)` time complexity when using XPath index pred...
CVE-2026-18028LOW2.3The "quick setup" view presented to users after they first create an event allows to set up the most critical parts of ...
CVE-2026-17072LOW3.3A flaw was found in GStreamer's gst-plugins-good. A heap-based out-of-bounds read of 4 bytes can occur when parsing FLAC...
CVE-2026-55977LOW3.3Successful exploitation of this vulnerability could allow an attacker with local network access to bypass the applicatio...
CVE-2026-14821LOW2.7The Quiz and Survey Master (QSM) WordPress plugin before 11.1.5 does not perform a capability check before deleting out...
CVE-2026-14819LOW3.5The Event Tickets and Registration WordPress plugin before 5.28.4 does not properly escape event titles before outputtin...
CVE-2026-64745LOW2.4This issue was addressed with additional restrictions on the lock screen. This issue is fixed in macOS Sequoia 15.7.8, m...
CVE-2026-59730LOW2.1Astro is a web framework for content-driven websites. In versions 8.1.0 through 11.0.1, when trailingSlash: 'always' is ...
CVE-2026-59727LOW2.1Astro is a web framework for content-driven websites. In versions 3.10.0 through 7.0.3, when a transition:persist, trans...
CVE-2026-48051LOW3.5Papra is a minimalistic document management and archiving platform. Prior to version 26.5.0, Papra's webhook delivery sy...
CVE-2026-17513LOW3.3A vulnerability was found in ggml-org whisper.cpp 95ea8f9b. Affected is the function ggml_ftype_to_ggml_type of the file...
CVE-2026-56538LOW3.5An endpoint in HCL Connections is vulnerable to information disclosure. In certain scenarios this might lead to disclosi...
CVE-2026-56537LOW3.5HCL Connections is vulnerable to information disclosure which could allow a user to obtain sensitive information they ar...
CVE-2026-17512LOW3.3A vulnerability has been found in ggml-org whisper.cpp 1.8.4-58. This impacts the function log_mel_spectrogram of the fi...
CVE-2026-40000LOW1.8The Activity zte.com.cn.filer/zte.com.cn.filer.FilePreViewActivity within ZTE File Manager is designed to preview compre...
CVE-2026-14189LOW3.8The WPBot WordPress plugin before 8.5.2 does not validate administrator-configured field identifiers before using them ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now