2026 CVE Vulnerabilities

64,779 CVEs published in 2026.

Filter:LOWClear
CVE IDSeverityCVSSDescription
CVE-2026-12812LOW3.5A security vulnerability has been detected in Radware Cyber Controller up to 10.11.0. This affects an unknown part of th...
CVE-2026-56355LOW3.7GNU Savannah Administration Savane through 3.17 uses untrusted data as part of authorization.
CVE-2026-56325LOW3.1Capgo before 12.128.2 uses ILIKE pattern matching instead of exact matching for app_id lookup in the preview subdomain r...
CVE-2026-48794LOW1.3Authelia is an open-source authentication and authorization server providing two-factor authentication and single sign-o...
CVE-2026-47203LOW2.9Authelia is an open-source authentication and authorization server providing two-factor authentication and single sign-o...
CVE-2026-49358LOW3PhpWeasyPrint is a PHP library allowing PDF generation from a URL or an HTML page. Prior to version 2.6.0, `AbstractGene...
CVE-2026-8668LOW2.3A static credential embedded in Chef 360 prior to v1.7.0 permitted unauthenticated access to internal message queues.  Q...
CVE-2026-40457LOW2.1A Reflected Cross-Site Scripting (XSS) vulnerability exists in LMS (LAN Management System) before commit 9c5651b in the ...
CVE-2026-12102LOW2.7The UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP plugin for WordPre...
CVE-2026-50268LOW1.9Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applicati...
CVE-2026-12567LOW2.2The github_workflows module constructs local directory paths from user-controlled repository names without validating fo...
CVE-2026-12566LOW3.1The docker_pull module uses the realm parameter from a Docker registry's WWW-Authenticate response header as the authent...
CVE-2026-6733LOW3.7Impact: Undici's HTTP/1.1 client is vulnerable to response queue poisoning on reused keep-alive sockets. An attacker-con...
CVE-2026-39199LOW2.9snes9x 1.63 allows an out-of-bounds write and denial of service via a crafted .ups file.
CVE-2026-11525LOW3.7Impact: When undici parses a Set-Cookie header, it accepts any SameSite attribute value that contains Strict, Lax, or No...
CVE-2026-12458LOW3.1Inappropriate implementation in Passwords in Google Chrome prior to 149.0.7827.155 allowed a remote attacker who convinc...
CVE-2026-0057LOW3.3In Contacts Provider, there is a possible way to access an incoming call's phone number and associated metadata due to a...
CVE-2026-46977LOW3.2Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: VMSVGA device). The supported v...
CVE-2026-46874LOW3.2Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version th...
CVE-2026-46816LOW3.2Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: VMSVGA device). The supported v...
CVE-2026-46815LOW3.2Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: VMSVGA device). The supported v...
CVE-2026-10636LOW3.7In Zephyr's IPv4 IGMP implementation, igmp_send() in subsys/net/ip/igmp.c read the network interface back out of the pac...
CVE-2026-48709LOW3.7OliveTin gives access to predefined shell commands from a web interface. In versions 3000.0.0 and prior, The ValidateArg...
CVE-2026-12211LOW2.7A flaw has been found in Intelbras iNVU 7016 FT 3.004.00IB000.0.T Build 2025-09-26. This impacts an unknown function of ...
CVE-2026-12202LOW2.4A vulnerability has been found in Intelliants Subrion CMS up to 4.0.3. Affected by this issue is some unknown functional...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now