2026 CVE Vulnerabilities

43,273 CVEs published in 2026.

Filter:LOWClear
CVE IDSeverityCVSSDescription
CVE-2026-5199LOW2.3A writer role user in an attacker-controlled namespace could signal, delete, and reset workflows or activities in a vict...
CVE-2026-5310LOW2.5A vulnerability was identified in Enter Software Iperius Backup up to 8.7.2. This impacts an unknown function of the fil...
CVE-2026-5254LOW3.5A security vulnerability has been detected in welovemedia FFmate up to 2.0.15. Affected by this issue is some unknown fu...
CVE-2026-5253LOW3.5A weakness has been identified in bufanyun HotGo 1.0/2.0. Affected by this vulnerability is an unknown functionality of ...
CVE-2026-5252LOW3.5A security flaw has been discovered in z-9527 admin 1.0/2.0. Affected is an unknown function of the file /server/routes/...
CVE-2026-5249LOW3.5A vulnerability was found in gougucms 4.08.18. This impacts an unknown function of the file \gougucms-master\app\admin\v...
CVE-2026-3470LOW3.8A vulnerability exists in the SonicWall Email Security appliance due to improper input sanitization that may lead to dat...
CVE-2026-3469LOW2.7A denial-of-service (DoS) vulnerability exists due to improper input validation in the SonicWall Email Security applianc...
CVE-2026-34383LOW3.5Admidio is an open-source user management solution. Prior to version 5.0.8, the inventory module's item_save endpoint ac...
CVE-2026-34372LOW2.7Sulu is an open-source PHP content management system based on the Symfony framework. From versions 1.0.0 to before 2.6.2...
CVE-2026-5209LOW2.4A security vulnerability has been detected in SourceCodester Leave Application System 1.0. Affected by this issue is som...
CVE-2026-33415LOW2.7Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.3, 2026.2.0-latest to be...
CVE-2026-33762LOW2.8go-git is an extensible git implementation library written in pure Go. Prior to version 5.17.1, go-git’s index decoder f...
CVE-2026-32970LOW3.3OpenClaw before 2026.3.11 contains a credential fallback vulnerability where unavailable local gateway.auth.token and ga...
CVE-2026-21716LOW3.3An incomplete fix for CVE-2024-36137 leaves `FileHandle.chmod()` and `FileHandle.chown()` in the promises API without th...
CVE-2026-21715LOW3.3A flaw in Node.js Permission Model filesystem enforcement leaves `fs.realpathSync.native()` without the required read pe...
CVE-2026-5037LOW3.3A vulnerability was determined in mxml up to 4.0.4. This issue affects the function index_sort of the file mxml-index.c ...
CVE-2026-4995LOW3.5A vulnerability was determined in wandb OpenUI up to 1.0. Affected by this vulnerability is an unknown functionality of ...
CVE-2026-4994LOW3.5A vulnerability was found in wandb OpenUI up to 1.0/3.5-turb. Affected is the function generic_exception_handler of the ...
CVE-2026-4993LOW3.3A vulnerability has been found in wandb OpenUI up to 0.0.0.0/1.0. This impacts an unknown function of the file backend/o...
CVE-2026-4973LOW3.5A vulnerability was detected in SourceCodester Online Quiz System up to 1.0. Affected by this vulnerability is an unknow...
CVE-2026-4972LOW2.4A security vulnerability has been detected in code-projects Online Reviewer System up to 1.0. Affected is an unknown fun...
CVE-2026-4969LOW3.5A vulnerability was identified in code-projects Social Networking Site 1.0. The impacted element is an unknown function ...
CVE-2026-4957LOW2.7A flaw has been found in OpenBMB XAgent 1.0.0. The impacted element is the function FunctionHandler.handle_tool_call of ...
CVE-2026-4909LOW2.4A weakness has been identified in code-projects Exam Form Submission 1.0. This impacts an unknown function of the file /...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now