2026 CVE Vulnerabilities

43,031 CVEs published in 2026.

Filter:LOWClear
CVE IDSeverityCVSSDescription
CVE-2026-66401LOW2.4FreeRDP before 3.29.0 contains an out-of-bounds heap read vulnerability in the UVC H.264 extension-unit parser that fail...
CVE-2026-14823LOW2.2The Event Tickets and Registration WordPress plugin before 5.29.0.1 does not properly verify authorization on some of it...
CVE-2026-14214LOW2.7The Booking for Appointments and Events Calendar WordPress plugin before 2.4.4 does not restrict which fields can be wr...
CVE-2026-14197LOW3.8The Fluent Support WordPress plugin before 2.3.1 does not perform a per-ticket access check before reassigning a ticket...
CVE-2026-14195LOW2.7The Brizy WordPress plugin before 2.8.18 does not properly verify authorization on a request handler before returning p...
CVE-2026-11882LOW3.7The Builderall for WordPress plugin before 3.0.2 does not bind the state value of its public OAuth authentication routes...
CVE-2026-10827LOW3.5The Spectra Legacy WordPress plugin before 2.20.0 does not validate or escape several block style attributes before usi...
CVE-2026-54787LOW3.1sigstore-go is a Go library for Sigstore signing and verification. Prior to 1.2.1, sigstore-go does not check a bundle s...
CVE-2026-55825LOW3.1Contao is an Open Source CMS. In versions 5.7.0 through 5.7.6, an authenticated backend user who can access one job can ...
CVE-2026-57232LOW3.1Contao is an Open Source CMS. From 5.3.35 through 5.3.47 and from 5.7.0-RC1 through 5.7.8, the Feed Reader front-end mod...
CVE-2026-55824LOW2.6Contao is an Open Source CMS. In versions 4.13.40 through 5.3.46 and 5.7.0-RC1 through 5.7.6, the crawler leaks auth cre...
CVE-2026-25552LOW3.7Ghost CLI before 1.30.1 contains an IP spoofing vulnerability that allows unauthenticated remote attackers to bypass rat...
CVE-2026-56569LOW3.3HCL iControl was affected by Sensitive Data Exposure vulnerabilities. It involves the public exposure of internal config...
CVE-2026-56567LOW3.3HCL iControl v4.3.0 was affected by Security Misconfiguration vulnerabilities. It involves the public exposure of intern...
CVE-2026-65636LOW2.1Improper Neutralization of CRLF Sequences vulnerability in ufirstgroup ymlr (Elixir.Ymlr module) allows attackers to inj...
CVE-2026-18206LOW3.7A flaw was found in the keycloak-services component of Keycloak, which provides identity and access management services....
CVE-2026-15381LOW3.7The WP Go Maps WordPress plugin before 10.1.04 does not properly sanitise and escape a parameter before using it in a S...
CVE-2026-14927LOW3.7The FluentCart A New Era of eCommerce WordPress plugin before 1.5.3 does not perform any authorization or ownership che...
CVE-2026-14862LOW3.7The Support Genix WordPress plugin before 1.4.48 does not properly authorize access to support-ticket attachment downlo...
CVE-2026-14849LOW3.7The Paid Membership Subscriptions WordPress plugin before 3.0.7 does not protect the member and payment export files it...
CVE-2026-13393LOW3.5The ElementsKit Elementor Addons WordPress plugin before 3.10.01 does not sanitize or escape certain megamenu menu-item...
CVE-2026-58039LOW3.3A flaw in Node.js Permission Model enforcement allows process.report writes (and overwrites) files outside --allow-fs-wr...
CVE-2026-41709LOW2.7VMware ESX contains an insufficient logging vulnerability. A malicious administrator could exploit this issue to perform...
CVE-2026-59326LOW3.3The Spring Boot language server logs the raw value of the https_proxy/HTTPS_PROXY/http_proxy/HTTP_PROXY environment vari...
CVE-2026-56847LOW3.3A flaw in Node.js Permission Model enforcement allows `trace_events.createTracing().enable()` Writes Trace Logs Outside ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now