2026 CVE Vulnerabilities

43,273 CVEs published in 2026.

Filter:LOWClear
CVE IDSeverityCVSSDescription
CVE-2026-22629LOW3.7An improper restriction of excessive authentication attempts vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.4...
CVE-2026-21791LOW3.3HCL Sametime for Android is impacted by a sensitive information disclosure. Hostnames information is written in applica...
CVE-2026-3706LOW3.7A vulnerability was determined in mkj Dropbear up to 2025.89. Impacted is the function unpackneg of the file src/curve25...
CVE-2026-3671LOW3.3A flaw has been found in Freedom Factory dGEN1 up to 20260221. Affected by this vulnerability is the function TokenBalan...
CVE-2026-2671LOW3.1A vulnerability was detected in Mendi Neurofeedback Headset V4. Affected by this vulnerability is an unknown functionali...
CVE-2026-30848LOW3.7Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to version...
CVE-2026-3668LOW3.1A weakness has been identified in Freedom Factory dGEN1 up to 20260221. This affects the function AndroidEthereum of the...
CVE-2026-29185LOW2.7Backstage is an open framework for building developer portals. Prior to version 1.20.1, a vulnerability in the SCM URL p...
CVE-2026-27139LOW2.5On Unix platforms, when listing the contents of a directory using File.ReadDir or File.Readdir the returned FileInfo cou...
CVE-2026-28475LOW3.7OpenClaw versions prior to 2026.2.13 use non-constant-time string comparison for hook token validation, allowing attacke...
CVE-2026-28540LOW3.3Out-of-bounds character read vulnerability in Bluetooth. Impact: Successful exploitation of this vulnerability may affec...
CVE-2026-21786LOW3.3HCL Sametime for iOS is impacted by a sensitive information disclosure. Hostnames information is written in application...
CVE-2026-23811LOW3.1A vulnerability in the client isolation mechanism may allow an attacker to bypass Layer 2 (L2) communication restriction...
CVE-2026-23810LOW3.1A vulnerability in the packet processing logic may allow an authenticated attacker to craft and transmit a malicious Wi-...
CVE-2026-26891LOW2.7Sourcecodester Logistic Hub Parcel's Management System v1.0 is vulnerable to SQL Injection in /manage_parcel_type.php.
CVE-2026-26889LOW2.7Sourcecodester Pharmacy Point of Sale System v1.0 is vulnerable to SQL Injection in /pharmacy/manage_category.php.
CVE-2026-26888LOW2.7Sourcecodester Pharmacy Point of Sale System v1.0 is vulnerable to SQL Injection in /pharmacy/manage_stock.php.
CVE-2026-26887LOW2.7Sourcecodester Pharmacy Point of Sale System v1.0 is vulnerable to SQL Injection in /pharmacy/manage_supplier.php.
CVE-2026-26890LOW2.7Sourcecodester Pharmacy Point of Sale System v1.0 is vulnerable to SQL Injection in /pharmacy/manage_product.php.
CVE-2026-26886LOW2.7Sourcecodester Online Men's Salon Management System v1.0 is vulnerable to SQL Injection in /admin/services/manage_servic...
CVE-2026-26885LOW2.7Sourcecodester Online Men's Salon Management System v1.0 is vulnerable to SQL Injection in /classes/Master.php?f=delete_...
CVE-2026-26884LOW2.7Sourcecodester Online Men's Salon Management System v1.0 is vulnerable to SQL Injection in /msms/admin/appointments/view...
CVE-2026-26883LOW2.7Sourcecodester Online Men's Salon Management System v1.0 is vulnerable to SQL Injection in /msms/classes/Master.php?f=de...
CVE-2026-3465LOW3.1A vulnerability was determined in Tuya App and SDK 24.07.11 on Android. Affected by this vulnerability is an unknown fun...
CVE-2026-25674LOW3.7An issue was discovered in 6.0 before 6.0.3, 5.2 before 5.2.12, and 4.2 before 4.2.29. Race condition in file-system sto...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now