2026 CVE Vulnerabilities

43,274 CVEs published in 2026.

Filter:LOWClear
CVE IDSeverityCVSSDescription
CVE-2026-2069LOW3.3A flaw has been found in ggml-org llama.cpp up to 55abc39. Impacted is the function llama_grammar_advance_stack of the f...
CVE-2026-25764LOW3.5OpenProject is an open-source, web-based project management software. Prior to versions 16.6.7 and 17.0.3, an HTML injec...
CVE-2026-22254LOW3.5Winter is a free, open-source content management system (CMS) based on the Laravel PHP framework. Versions of Winter CMS...
CVE-2026-1990LOW3.3A security vulnerability has been detected in oatpp up to 1.3.1. This impacts the function oatpp::data::type::ObjectWrap...
CVE-2026-25815LOW3.2Fortinet FortiOS through 7.6.6 allows attackers to decrypt LDAP credentials stored in device configuration files, as exp...
CVE-2026-1966LOW2.4YugabyteDB Anywhere displays LDAP bind passwords configured via gflags in cleartext within the web UI. An authenticated ...
CVE-2026-25517LOW2.7Wagtail is an open source content management system built on Django. Prior to versions 6.3.6, 7.0.4, 7.1.3, 7.2.2, and 7...
CVE-2026-20730LOW3.3A vulnerability exists in BIG-IP Edge Client and browser VPN clients on Windows that may allow attackers to gain access ...
CVE-2026-1791LOW2.7Unrestricted Upload of File with Dangerous Type vulnerability in Hillstone Networks Operation and Maintenance Security G...
CVE-2026-24513LOW3.1A security issue was discovered in ingress-nginx where the protection afforded by the `auth-url` Ingress annotation may ...
CVE-2026-25224LOW3.7Fastify is a fast and low overhead web framework, for Node.js. Prior to version 5.7.3, a denial-of-service vulnerability...
CVE-2026-24934LOW3.7The DDNS function uses an insecure HTTP connection or fails to validate the SSL/TLS certificate when querying an externa...
CVE-2026-1703LOW2When pip is installing and extracting a maliciously crafted wheel archive, files may be extracted outside the installati...
CVE-2026-1751LOW3.1A vulnerability has been discovered in GitLab CE/EE affecting all versions starting with 16.8 before 18.5.0 that could h...
CVE-2026-1743LOW3.1A vulnerability has been found in DJI Mavic Mini, Air, Spark and Mini SE up to 01.00.0500. Affected by this vulnerabilit...
CVE-2026-1705LOW2.4A vulnerability was detected in D-Link DSL-6641K N8.TR069.20131126. Affected by this issue is the function ad_virtual_se...
CVE-2026-25211LOW3.2Llama Stack (aka llama-stack) before 0.4.0rc3 does not censor the pgvector password in the initialization log.
CVE-2026-25046LOW2.9Kimi Agent SDK is a set of libraries that expose the Kimi Code (Kimi CLI) agent runtime in applications. The vsix-publis...
CVE-2026-1588LOW2.7A vulnerability was found in jishenghua jshERP up to 3.6. The impacted element is the function install of the file /jshE...
CVE-2026-23553LOW2.9In the context switch logic Xen attempts to skip an IBPB in the case of a vCPU returning to a CPU on which it was the pr...
CVE-2026-1520LOW2.4A vulnerability was identified in rethinkdb up to 2.4.3. Affected by this issue is some unknown functionality of the com...
CVE-2026-1237LOW2.1Vulnerable cross-model authorization in juju. If a charm's cross-model permissions are revoked or expire, a malicious us...
CVE-2026-1485LOW2.8A flaw was found in Glib's content type parsing logic. This buffer underflow vulnerability occurs because the length of ...
CVE-2026-1444LOW2.4A vulnerability has been found in iJason-Liu Books_Manager up to 298ba736387ca37810466349af13a0fdf828e99c. This affects ...
CVE-2026-1190LOW3.1A flaw was found in Keycloak's SAML brokering functionality. When Keycloak is configured as a client in a Security Asser...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now