2026 CVE Vulnerabilities

43,274 CVEs published in 2026.

Filter:LOWClear
CVE IDSeverityCVSSDescription
CVE-2026-23522LOW3.7LobeChat is an open source chat application platform. Prior to version 2.0.0-next.193, `knowledgeBase.removeFilesFromKno...
CVE-2026-1161LOW3.5A vulnerability was detected in pbrong hrms 1.0.1. The affected element is the function UpdateRecruitmentById of the fil...
CVE-2026-1136LOW3.5A weakness has been identified in lcg0124 BootDo up to e93dd428ef6f5c881aa74d49a2099ab0cf1e0fcb. Affected is the functio...
CVE-2026-0682LOW2.2The Church Admin plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including,...
CVE-2026-0519LOW3.4In Secure Access 12.70 and prior to 14.20, the logging subsystem may write an unredacted authentication token to logs u...
CVE-2026-0992LOW2.9A flaw was found in the libxml2 library. This uncontrolled resource consumption vulnerability occurs when processing XML...
CVE-2026-0989LOW3.7A flaw was identified in the RelaxNG parser of libxml2 related to how external schema inclusions are handled. The parser...
CVE-2026-0976LOW3.7A flaw was found in Keycloak. This improper input validation vulnerability occurs because Keycloak accepts RFC-compliant...
CVE-2026-22819LOW3.1Outray openSource ngrok alternative. Prior to 0.1.5, this vulnerability allows a user i.e a free plan user to get more t...
CVE-2026-22820LOW3.7Outray openSource ngrok alternative. Prior to 0.1.5, a TOCTOU race condition vulnerability allows a user to exceed the s...
CVE-2026-0510LOW3The User Management Engine (UME) in NetWeaver Application Server for Java (NW AS Java) utilizes an obsolete cryptographi...
CVE-2026-0504LOW3.8Due to insufficient input handling, the SAP Identity Management REST interface allows an authenticated administrator to ...
CVE-2026-0824LOW3.5A security flaw has been discovered in questdb ui up to 1.11.9. Impacted is an unknown function of the component Web Con...
CVE-2026-22611LOW3.7AWS SDK for .NET works with Amazon Web Services to help build scalable solutions with Amazon S3, Amazon DynamoDB, Amazon...
CVE-2026-22597LOW2.7Ghost is a Node.js content management system. In versions 5.38.0 through 5.130.5 and 6.0.0 through 6.10.3, a vulnerabili...
CVE-2026-22602LOW3.5OpenProject is an open-source, web-based project management software. Prior to version 16.6.2, a low‑privileged logged-i...
CVE-2026-22025LOW3.7CryptoLib provides a software-only solution using the CCSDS Space Data Link Security Protocol - Extended Procedures (SDL...
CVE-2026-20972LOW3.3Improper Export of Android Application Components in UwbTest prior to SMR Jan-2026 Release 1 allows local attackers to e...
CVE-2026-22714LOW2.3Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimed...
CVE-2026-0747LOW3.3Exposure of sensitive information in the TeamViewer entry dashboard component in Devolutions Remote Desktop Manager 2025...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now