2026 CVE Vulnerabilities

43,274 CVEs published in 2026.

Filter:LOWClear
CVE IDSeverityCVSSDescription
CVE-2026-24656LOW3.7Deserialization of Untrusted Data vulnerability in Apache Karaf Decanter. The Decanter log socket collector exposes th...
CVE-2026-1417LOW3.3A weakness has been identified in GPAC up to 2.4.0. Affected by this issue is the function dump_isom_rtp of the file app...
CVE-2026-1416LOW3.3A security flaw has been discovered in GPAC up to 2.4.0. Affected by this vulnerability is the function DumpMovieInfo of...
CVE-2026-1415LOW3.3A vulnerability was identified in GPAC up to 2.4.0. Affected is the function gf_media_export_webvtt_metadata of the file...
CVE-2026-1406LOW3.5A vulnerability was determined in lcg0124 BootDo up to 5ccd963c74058036b466e038cff37de4056c1600. Affected by this vulner...
CVE-2026-0633LOW3.7The MetForm – Contact Form, Survey, Quiz, & Custom Form Builder for Elementor plugin for WordPress is vulnerable to Sens...
CVE-2026-22978LOW3.3In the Linux kernel, the following vulnerability has been resolved: wifi: avoid kernel-infoleak from struct iw_point s...
CVE-2026-24515LOW2.5In libexpat before 2.7.4, XML_ExternalEntityParserCreate does not copy unknown encoding handler user data.
CVE-2026-0798LOW3.5Gitea may send release notification emails for private repositories to users whose access has been revoked. When a repos...
CVE-2026-22411LOW3.8Authorization Bypass Through User-Controlled Key vulnerability in Mikado-Themes Dolcino dolcino allows Exploiting Incorr...
CVE-2026-22409LOW3.8Authorization Bypass Through User-Controlled Key vulnerability in Mikado-Themes Justicia justicia allows Exploiting Inco...
CVE-2026-22407LOW3.8Authorization Bypass Through User-Controlled Key vulnerability in Mikado-Themes Roam roam allows Exploiting Incorrectly ...
CVE-2026-22406LOW3.8Authorization Bypass Through User-Controlled Key vulnerability in Mikado-Themes Overton overton allows Exploiting Incorr...
CVE-2026-22404LOW3.8Authorization Bypass Through User-Controlled Key vulnerability in Mikado-Themes Innovio innovio allows Exploiting Incorr...
CVE-2026-1225LOW1.8ACE vulnerability in configuration file processing by QOS.CH logback-core up to and including version 1.5.24 in Java ap...
CVE-2026-24048LOW3.7Backstage is an open framework for building developer portals, and @backstage/backend-defaults provides the default impl...
CVE-2026-23996LOW3.7FastAPI Api Key provides a backend-agnostic library that provides an API key system. Version 1.1.0 has a timing side-cha...
CVE-2026-0988LOW3.7A flaw was found in glib. Missing validation of offset and count parameters in the g_buffered_input_stream_peek() functi...
CVE-2026-1035LOW3.1A flaw was found in the Keycloak server during refresh token processing, specifically in the TokenManager class responsi...
CVE-2026-21977LOW3.1Vulnerability in the Oracle Zero Data Loss Recovery Appliance Software product of Oracle Zero Data Loss Recovery Applian...
CVE-2026-21965LOW2.7Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Pluggable Auth). Supported versions that ...
CVE-2026-21947LOW3.1Vulnerability in Oracle Java SE (component: JavaFX). Supported versions that are affected are Oracle Java SE: 8u471-b50...
CVE-2026-21930LOW2.3Vulnerability in the Oracle ZFS Storage Appliance Kit product of Oracle Systems (component: Filesystems). The supporte...
CVE-2026-21640LOW2.7HackerOne community member Faraz Ahmed (PakCyberbot) has reported a format string injection in the Revive Adserver setti...
CVE-2026-1197LOW3.1A vulnerability was detected in MineAdmin 1.x/2.x. Affected by this vulnerability is an unknown functionality of the fil...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now