2026 CVE Vulnerabilities

64,779 CVEs published in 2026.

Filter:LOWClear
CVE IDSeverityCVSSDescription
CVE-2026-48289LOW3.5Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by an Improper Input Validation vuln...
CVE-2026-48288LOW3.5Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by an Improper Input Validation vuln...
CVE-2026-45642LOW3.9Improper input validation in Microsoft Azure Attestation service and Device Health Attestation Service allows an authori...
CVE-2026-45485LOW3.3Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
CVE-2026-45466LOW3.3Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
CVE-2026-45459LOW3.3Protection mechanism failure in Microsoft Office Excel allows an unauthorized attacker to bypass a security feature loca...
CVE-2026-42770LOW3.7Issue summary: When EVP_PKEY_derive_set_peer() is called with a DHX (X9.42) peer key, the peer key is not properly check...
CVE-2026-42768LOW3.7Issue summary: The CMS_decrypt and PKCS7_decrypt functions are vulnerable to Bleichenbacher-style attack when an attacke...
CVE-2026-11792LOW3.3A heap buffer overflow flaw was found in 389 Directory Server. When audit logging is enabled, the create_masked_entry_st...
CVE-2026-11764LOW3.6When creating an export of all reusable media, the secrets of connected gift cards were included in the export even if ...
CVE-2026-49738LOW2.1The path allowance check in GeneralUtility::isAllowedAbsPath() performed a plain string prefix comparison without requir...
CVE-2026-41986LOW2.4Logic bypass vulnerability in the file system. Impact: Successful exploitation of this vulnerability may affect availabi...
CVE-2026-41974LOW3.6Permission control vulnerability in service notifications. Impact: Successful exploitation of this vulnerability may aff...
CVE-2026-8981LOW3.5The Custom Block Builder WordPress plugin before 4.3.0 does not consistently check the unfiltered_html capability acros...
CVE-2026-44743LOW3.7Under certain conditions, when an unauthorized attacker accesses a specific endpoint, SAP Business Objects application l...
CVE-2026-11691LOW3.1Insufficient validation of untrusted input in New Tab Page in Google Chrome prior to 149.0.7827.103 allowed a remote att...
CVE-2026-11686LOW3.1Insufficient validation of untrusted input in Dawn in Google Chrome on macOS prior to 149.0.7827.103 allowed a remote at...
CVE-2026-11684LOW3.1Insufficient policy enforcement in Network in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who had co...
CVE-2026-11675LOW3.1Out of bounds read in Skia in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who had compromised the re...
CVE-2026-47344LOW2.1When ALLOW_INSECURE_RAW_TEXT is enabled, whitespace-variant closing tags (e.g., </style\t>) are not recognized by the sa...
CVE-2026-11534LOW3.5A vulnerability was detected in imvks786 student_management_system up to 9599b560ad3c3b83e75d328b76bedcd489ef1f46. Affec...
CVE-2026-49756LOW3.7Improper Neutralization of CRLF Sequences ('CRLF Injection') vulnerability in wojtekmach Req allows multipart parameter ...
CVE-2026-48488LOW2.7phpMyFAQ is an open source FAQ web application. Prior to version 4.1.4, attachment passwords are hashed using SHA-1, a c...
CVE-2026-11520LOW3.5A weakness has been identified in SourceCodester Inventory System 1.0. Affected by this issue is some unknown functional...
CVE-2026-11511LOW3.5A weakness has been identified in Bolt CMS up to 3.7.5. This vulnerability affects unknown code of the file src/Storage/...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now