2026 CVE Vulnerabilities

64,779 CVEs published in 2026.

Filter:LOWClear
CVE IDSeverityCVSSDescription
CVE-2026-48935LOW3.3A flaw in Node.js Permission API can cause a file metadata to be modified even on a path that was set as read-only with ...
CVE-2026-13322LOW3.8A flaw was found in KubeVirt's downward metrics virtio-serial server. The server reads guest requests using textproto.Re...
CVE-2026-13350LOW2.3Permissions where checked incorrectly during room creation, allowing attackers to create rooms of types they shouldn't b...
CVE-2026-48940LOW3.4A Joomla user with K2 "create item" rights (Author tier by default) can submit an article whose `embedVideo` POST field ...
CVE-2026-57588LOW3.3A SQL injection vulnerability in Nessus allows an attacker to craft a malicious scan result file that, when imported by ...
CVE-2026-57535LOW2.1Content injected to PDF rendering contexts could, in many places, include HTML content including <img> tags. If the src ...
CVE-2026-57534LOW2.1Malicious HTML content could be injected into the content of a page in the pretix-pages plugin.
CVE-2026-57533LOW2.1Malicious HTML content could be injected into the page pretix shows when redirection to an untrusted page occurs. Since...
CVE-2026-57234LOW2.6Nokogiri is an open source XML and HTML library for the Ruby programming language. Prior to 1.19.4, the NONET parse opti...
CVE-2026-13314LOW2Malicious HTML content could be injected into the content rendered by the pretix-digital plugin.
CVE-2026-12755LOW2.7Improper input validation in the PAM AD discovery endpoints in Devolutions Server 2026.2.4.0 through 2026.2.7.0 allows ...
CVE-2026-42004LOW3.7An attacker can send a crafted EDNS OPT record that will be ignored by DNSdist’s filtering rules, but will be rewritten ...
CVE-2026-40208LOW3.7An attacker might be able to delay the processing of DoH3 queries by sending DoH3 GET queries with an invalid DATA frame...
CVE-2026-40011LOW3.7An attacker sending a large number of crafted DNS queries might be able to trigger a dynamic block being inserted with a...
CVE-2026-56130LOW2"Remember me" cookie age is not verified on the server. This potentially allows an attacker to intercept a valid cookie ...
CVE-2026-45188LOW2.4Relative Path Traversal vulnerability in Apache Kvrocks. This issue affects Apache Kvrocks: from 1.0.0 through 2.15.0. ...
CVE-2026-3176LOW3.1GitLab has remediated an issue in GitLab EE affecting all versions from 18.6 before 18.11.6, 19.0 before 19.0.3, and 19....
CVE-2026-12635LOW3.1GitLab has remediated an issue in GitLab CE/EE affecting all versions from 8.3 before 18.11.6, 19.0 before 19.0.3, and 1...
CVE-2026-0934LOW3.8GitLab has remediated an issue in GitLab EE affecting all versions from 17.9 before 18.11.6, 19.0 before 19.0.3, and 19....
CVE-2026-49979LOW2.7Appsmith is a platform to build admin panels, internal tools, and dashboards. Prior to 1.99, the POST /api/v1/admin/send...
CVE-2026-39894LOW2.5Cacti is an open source performance and fault management framework. In versions 1.2.30 and below, the locale-dependent d...
CVE-2026-52796LOW3.5Gogs is an open source self-hosted Git service. Prior to 0.14.3, specially crafted issue index pattern can cause a panic...
CVE-2026-49277LOW2.3Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 8.5.0, 8.4.2, 8.3.4, 8.2.4, ...
CVE-2026-45757LOW2.3Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 8.5.0, 8.4.2, 8.3.4, 8.2.4, ...
CVE-2026-49246LOW1.7Jellyfin is an open source self hosted media server. Prior to 10.11.10, a specifically crafted MKV file containing forge...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now