2026 CVE Vulnerabilities

64,775 CVEs published in 2026.

Filter:LOWClear
CVE IDSeverityCVSSDescription
CVE-2026-10755LOW2.7The All in One SEO WordPress plugin before 4.9.9 does not correctly restrict access to some of its AI integration REST ...
CVE-2026-16218LOW2.6A vulnerability was detected in hunvreus devpush up to 0.4.6. Affected by this issue is the function reset_storage of th...
CVE-2026-16211LOW2.6A vulnerability was determined in allegro up to bcf65b994ef29fb3fc2e10b660e6288723d5209e. This impacts the function Asse...
CVE-2026-16205LOW2.4A weakness has been identified in Pluck CMS up to 4.7.21. This vulnerability affects the function htmlspecialchars_decod...
CVE-2026-16203LOW3.5A vulnerability was identified in SourceCodester Class and Exam Timetabling System 1.0. Affected by this issue is some u...
CVE-2026-16202LOW3.5A vulnerability was determined in SourceCodester Class and Exam Timetabling System 1.0. Affected by this vulnerability i...
CVE-2026-16156LOW3.5A security flaw has been discovered in SourceCodester Class and Exam Timetabling System 1.0. This affects an unknown par...
CVE-2026-16155LOW3.5A vulnerability was identified in SourceCodester Class and Exam Timetabling System 1.0. Affected by this issue is some u...
CVE-2026-54335LOW3.7Feathersjs is a framework for creating web APIs and real-time applications with TypeScript or JavaScript. In 5.0.44 and ...
CVE-2026-54244LOW3.5Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.74.0 and 6.20.3, the Live Preview endp...
CVE-2026-48978LOW2.1oras-go is a Go library for managing OCI artifacts. Prior to 2.6.1, auth.Client follows the realm URL from a registry's ...
CVE-2026-50185LOW3.3RustCrypto CMOV provides conditional move CPU intrinsics which are guaranteed on major platforms to execute in constant-...
CVE-2026-16073LOW3.5A security vulnerability has been detected in AstrBotDevs AstrBot up to 4.25.2. Affected by this issue is the function S...
CVE-2026-15997LOW1.7Out-of-bounds write vulnerability in Legion of the Bouncy Castle Inc. BC-LTS bcprov-lts8on on ARM allows Overflow Buffer...
CVE-2026-62994LOW3.7CoreDNS is a DNS server written in Go. From 1.9.4 until 1.14.5, a network DNS client allowed to request AXFR for a CoreD...
CVE-2026-47088LOW3.1An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. There is heap exposure in nested MIME comment parsi...
CVE-2026-47087LOW3.5An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. URLAUTH does not honor revoked authorizer access. A...
CVE-2026-47086LOW3.5An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. GENURLAUTH-issued tokens can bypass ACLs. Any authe...
CVE-2026-47081LOW3.1An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. There is an XAPPLEPUSHSERVICE folder existence orac...
CVE-2026-44969LOW3.3dbt-mcp is a Model Context Protocol server for interacting with dbt. Prior to 1.17.1, DbtMCP.call_tool() in src/dbt_mcp/...
CVE-2026-15945LOW2.7A flaw was found in the group search functionality of the Keycloak server's administrative API. When Fine-Grained Admin ...
CVE-2026-35145LOW3.1HCL DFXAnalytics is affected by a Missing HTTP Strict-Transport-Security Header vulnerability. The application fails to ...
CVE-2026-12907LOW2.7The RTMKit WordPress plugin before 2.0.9 does not perform a proper capability check on one of its -builder AJAX actions,...
CVE-2026-12906LOW2.7The RTMKit WordPress plugin before 2.0.9 does not perform a capability check in one of its AJAX actions and resolves a r...
CVE-2026-38755LOW2.9A heap overflow in the evalcommand() function (shell/ash.c) of Busybox v1.38.0 allows attackers to cause a Denial of Ser...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now