2026 CVE Vulnerabilities

64,775 CVEs published in 2026.

Filter:LOWClear
CVE IDSeverityCVSSDescription
CVE-2026-13235LOW3.3Missing Authorization vulnerability in Drupal AI (Artificial Intelligence) allows Forceful Browsing. This issue affects ...
CVE-2026-13233LOW3.3Server-Side Request Forgery (SSRF) vulnerability in Drupal OpenAI Provider allows Server Side Request Forgery. This issu...
CVE-2026-13232LOW3.1Incorrect Authorization vulnerability in Drupal Advanced Content Feedback (aka admin_feedback) allows Forceful Browsing....
CVE-2026-11909LOW3.3Missing Authorization vulnerability in Drupal Examples for Developers allows Forceful Browsing. This issue affects Examp...
CVE-2026-55671LOW2.3ZITADEL is an open source identity management platform. From 4.0.0-rc.1 through 4.15.1, ZITADEL's HTTP notification chan...
CVE-2026-55670LOW2.3ZITADEL is an open source identity management platform. Prior to 4.15.1, ZITADEL's event store validation can retain the...
CVE-2026-59180LOW3.1Apprise is an open source library which allows you to send a notification to almost all of the most popular notification...
CVE-2026-55783LOW2.4NanaZip is the 7-Zip derivative intended for the modern Windows experience. Prior to 6.5.1749.0, NanaZip's seven in-hous...
CVE-2026-55782LOW2.4NanaZip is the 7-Zip derivative intended for the modern Windows experience. Prior to 6.5.1749.0, NanaZip's WebAssembly a...
CVE-2026-55781LOW2.4NanaZip is the 7-Zip derivative intended for the modern Windows experience. Prior to 6.5.1749.0, NanaZip's UFS and FFS i...
CVE-2026-55780LOW2.4NanaZip is the 7-Zip derivative intended for the modern Windows experience. Prior to 6.5.1749.0, NanaZip's .NET single-f...
CVE-2026-59791LOW3.5In JetBrains YouTrack before 2026.2.17012 cSS injection via Mermaid diagram rendering was possible
CVE-2026-56813LOW2.1Improper Neutralization of Parameter/Argument Delimiters vulnerability in elixir-plug plug allows an attacker to inject ...
CVE-2026-58225LOW2.1SQL Injection vulnerability in elixir-ecto postgrex allows an attacker who can influence a LISTEN channel name to inject...
CVE-2026-15028LOW3.9A flaw was found in libarchive. This vulnerability allows a remote attacker to trigger a heap overflow by providing a sp...
CVE-2026-15326LOW3.8A vulnerability was identified in halo-dev halo up to 2.24.2. This affects the function ThemeUtils.unzipThemeTo of the f...
CVE-2026-15321LOW2.4A vulnerability was found in MyEMS up to 6.4.0. The affected element is the function on_post of the file myems-api/core/...
CVE-2026-15311LOW3.5A vulnerability was identified in NousResearch hermes-agent up to 2026.5.29.2. Affected by this issue is the function Ma...
CVE-2026-15276LOW3.3A flaw has been found in pdeljanov Symphonia up to 0.6.0. This vulnerability affects unknown code of the component Metad...
CVE-2026-15274LOW3.3A vulnerability was detected in lo48576 fbxcel up to 0.9.0. This affects an unknown part of the file src/pull_parser/v74...
CVE-2026-59215LOW3.1Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. Prior to 0.10.0, channel thread pa...
CVE-2026-15194LOW3.3A security flaw has been discovered in Open5GS 2.7.7. This affects the function amf_context_final of the file src/amf/co...
CVE-2026-15185LOW3.3A vulnerability was determined in GPAC 26.03-DEV. This affects the function vobsub_read_idx of the file /src/media_tools...
CVE-2026-15184LOW3.3A vulnerability was found in GNU LibreDWG up to 0.13.4. The impacted element is the function dwg_next_entity of the file...
CVE-2026-59269LOW3.8A user authenticating to Kubernetes clusters via the Pinniped Supervisor could potentially gain elevated permissions in ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now