2026 CVE Vulnerabilities

43,274 CVEs published in 2026.

Filter:LOWClear
CVE IDSeverityCVSSDescription
CVE-2026-1831LOW2.7The YayMail - WooCommerce Email Customizer plugin for WordPress is vulnerable to unauthorized plugin installation and ac...
CVE-2026-2642LOW3.3A security vulnerability has been detected in ggreer the_silver_searcher up to 2.2.0. The impacted element is the functi...
CVE-2026-2641LOW3.3A weakness has been identified in universal-ctags ctags up to 6.2.1. The affected element is the function parseExpressio...
CVE-2026-0102LOW3.1Under specific conditions, a malicious webpage may trigger autofill population after two consecutive taps, potentially w...
CVE-2026-24733LOW3.7Improper Input Validation vulnerability in Apache Tomcat. Tomcat did not limit HTTP/0.9 requests to the GET method. If...
CVE-2026-20796LOW3.1Mattermost versions 10.11.x <= 10.11.9 fail to properly validate channel membership at the time of data retrieval which ...
CVE-2026-0872LOW2.5Improper Certificate Validation vulnerability in Thales SafeNet Agent for Windows Logon on Windows allows Signature Spoo...
CVE-2026-20681LOW3.3A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Tahoe 2...
CVE-2026-20671LOW3.1A logic issue was addressed with improved checks. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPad...
CVE-2026-20663LOW3.3The issue was resolved by sanitizing logging. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOS 2...
CVE-2026-20656LOW3.3A logic issue was addressed with improved validation. This issue is fixed in Safari 26.3, iOS 18.7.5 and iPadOS 18.7.5, ...
CVE-2026-20646LOW3.3A logging issue was addressed with improved data redaction. This issue is fixed in macOS Tahoe 26.3. A malicious app may...
CVE-2026-20642LOW2.4An input validation issue was addressed. This issue is fixed in iOS 26.3 and iPadOS 26.3. A person with physical access ...
CVE-2026-20601LOW3.3A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Tahoe 26.3. An app may be a...
CVE-2026-0228LOW1.3An improper certificate validation vulnerability in PAN-OS allows users to connect Terminal Server Agents on Windows to ...
CVE-2026-2345LOW3.6Proctorio Chrome Extension is a browser extension used for online proctoring. The extension contains multiple window.add...
CVE-2026-26013LOW3.7LangChain is a framework for building agents and LLM-powered applications. Prior to 1.2.11, the ChatOpenAI.get_num_token...
CVE-2026-1762LOW2.9A vulnerability in GE Vernova Enervista UR Setup on Windows allows File Manipulation.This issue affects Enervista: 8.6 a...
CVE-2026-21249LOW3.3External control of file name or path in Windows NTLM allows an unauthorized attacker to perform spoofing locally.
CVE-2026-23901LOW2.5Observable Timing Discrepancy vulnerability in Apache Shiro. This issue affects Apache Shiro: from 1.*, 2.* before 2.0....
CVE-2026-24320LOW3.1Due to improper memory management in SAP NetWeaver and ABAP Platform (Application Server ABAP), an authenticated attacke...
CVE-2026-23686LOW3.4Due to a CRLF Injection vulnerability in SAP NetWeaver Application Server Java, an authenticated attacker with administr...
CVE-2026-2246LOW3.3A security vulnerability has been detected in AprilRobotics apriltag up to 3.4.5. Affected by this vulnerability is the ...
CVE-2026-2245LOW3.3A vulnerability was identified in CCExtractor up to 183. This affects the function parse_PAT/parse_PMT in the library sr...
CVE-2026-2215LOW3.7A vulnerability was detected in rachelos WeRSS we-mp-rss up to 1.4.8. This issue affects some unknown processing of the ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now