2026 CVE Vulnerabilities

43,273 CVEs published in 2026.

Filter:LOWClear
CVE IDSeverityCVSSDescription
CVE-2026-2974LOW2.5A vulnerability was identified in AliasVault App up to 0.25.3 on Android/iOS. This vulnerability affects unknown code of...
CVE-2026-2968LOW3.7A vulnerability was detected in Cesanta Mongoose up to 7.20. This impacts the function mg_chacha20_poly1305_decrypt of t...
CVE-2026-2967LOW3.7A security vulnerability has been detected in Cesanta Mongoose up to 7.20. This affects the function getpeer of the file...
CVE-2026-2966LOW3.7A weakness has been identified in Cesanta Mongoose up to 7.20. The impacted element is the function mg_sendnsreq of the ...
CVE-2026-2965LOW2.4A security flaw has been discovered in 07FLYCMS, 07FLY-CMS and 07FlyCRM up to 1.2.9. The affected element is an unknown ...
CVE-2026-2903LOW3.3A flaw has been found in skvadrik re2c up to 4.4. Impacted is the function check_and_merge_special_rules of the file src...
CVE-2026-2889LOW3.3A vulnerability was detected in CCExtractor up to 0.96.5. Affected is the function processmp4 in the library src/lib_ccx...
CVE-2026-27467LOW2.4BigBlueButton is an open-source virtual classroom. In versions 3.0.19 and below, when first joining a session with the m...
CVE-2026-22885LOW3.7A vulnerability exists in EnOcean SmartServer IoT version 4.60.009 and prior, which would allow remote attackers, in th...
CVE-2026-21620LOW2.3Relative Path Traversal, Improper Isolation or Compartmentalization vulnerability in erlang otp erlang/otp (tftp_file mo...
CVE-2026-2825LOW3.5A vulnerability has been found in rachelos WeRSS we-mp-rss up to 1.4.8. This impacts the function fix_html of the file t...
CVE-2026-27007LOW3.3OpenClaw is a personal AI assistant. Prior to version 2026.2.15, `normalizeForHash` in `src/agents/sandbox/config-hash.t...
CVE-2026-26964LOW2.7Windmill is an open-source developer platform for internal code: APIs, background jobs, workflows and UIs. Versions 1.63...
CVE-2026-26958LOW1.7filippo.io/edwards25519 is a Go library implementing the edwards25519 elliptic curve with APIs for building cryptographi...
CVE-2026-24122LOW3.7Cosign provides code signing and transparency for containers and binaries. In versions 3.0.4 and below, an issuing certi...
CVE-2026-25423LOW3.8Missing Authorization vulnerability in creativeinteractivemedia Real 3D FlipBook real3d-flipbook-lite allows Exploiting ...
CVE-2026-2733LOW3.8A flaw was identified in the Docker v2 authentication endpoint of Keycloak, where tokens continue to be issued even afte...
CVE-2026-2709LOW3.5A flaw has been found in busy up to 2.5.5. The affected element is an unknown function of the file source-code/busy-mast...
CVE-2026-2702LOW3.1A security flaw has been discovered in Beetel 777VR1 up to 01.00.09. This issue affects some unknown processing of the c...
CVE-2026-25120LOW2.7Gogs is an open source self-hosted Git service. In versions 0.13.4 and below, the DeleteComment API does not verify that...
CVE-2026-24764LOW3.7OpenClaw (formerly Clawdbot) is a personal AI assistant users run on their own devices. In versions 2026.2.2 and below, ...
CVE-2026-2656LOW2.5A flaw has been found in ChaiScript up to 6.1.0. This affects the function chaiscript::Type_Info::bare_equal of the file...
CVE-2026-2655LOW2.5A vulnerability was detected in ChaiScript up to 6.1.0. The impacted element is the function chaiscript::str_less::opera...
CVE-2026-1582LOW3.7The WP All Export plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and includ...
CVE-2026-2419LOW2.7The WP-DownloadManager plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.69 v...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now