2026 CVE Vulnerabilities

64,729 CVEs published in 2026.

Filter:LOWClear
CVE IDSeverityCVSSDescription
CVE-2026-81654LOW3.1The Photo Gallery, Sliders, Proofing and WordPress plugin before 4.5.0 does not check that a user holds its options ca...
CVE-2026-81652LOW2.7The Photo Gallery, Sliders, Proofing and WordPress plugin before 4.5.0 does not verify that the requesting user is ent...
CVE-2026-81651LOW3.1The Photo Gallery, Sliders, Proofing and WordPress plugin before 4.5.0 does not verify that the user saving a gallery ...
CVE-2026-86551LOW3.3The Z80Ultra (NX741J) product contains a vulnerability where non-privileged programs can retrieve the Wi-Fi MAC address ...
CVE-2026-93989LOW3.1vLLM through 0.29.0 fails to properly validate bad_words token indices against the model's generation output width in Sa...
CVE-2026-93956LOW3.5A flaw has been found in olivier-ls PHP-FTS up to 1.1.2. Affected by this issue is the function SearchEngine::buildHighl...
CVE-2026-93987LOW3.4rclone versions 1.56.0 through 1.75.0 contain a path traversal vulnerability in the `rclone serve docker` volume plugin....
CVE-2026-93986LOW3.1rclone before 1.75.1 fails to confine names from server and third-party listing responses to the listed directory, allow...
CVE-2026-93982LOW3.3OpenPanel through commit bad75bdd writes Model Context Protocol authentication tokens from URL query parameters to plain...
CVE-2026-92420LOW3.8The Hydra Booking — Appointment Scheduling & Booking Calendar WordPress plugin before 1.2.2 does not verify that a booki...
CVE-2026-92403LOW3.7The Secure Custom Fields WordPress plugin before 6.9.4 does not properly verify that a front-end form submission corresp...
CVE-2026-93894LOW2.3In Vinyl Cache before 9.0,2, workspace buffer overflow vulnerability was found in the .upper() and .lower() string type ...
CVE-2026-63451LOW3.3Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Fr...
CVE-2026-63450LOW3.7Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Pr...
CVE-2026-63449LOW3.7Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Fr...
CVE-2026-57225LOW3.3Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Fr...
CVE-2026-93841LOW3.7vLLM through 0.29.0 contains a memory corruption vulnerability in the Triton _bincount_kernel where prompt token IDs ind...
CVE-2026-93840LOW3.7vLLM before 0.29.0 validates allowed_token_ids against tokenizer length instead of model output logits width in Sampling...
CVE-2026-57226LOW3.7Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Pr...
CVE-2026-11545LOW3.7IBM WebSphere Application Server 8.5 and 9.0 could allow a remote attacker to obtain sensitive information from the admi...
CVE-2026-93650LOW3.7A vulnerability was determined in Saleor up to 3.20.118/3.21.54/3.22.47/3.23.14. This vulnerability affects the function...
CVE-2026-81181LOW3.7SysReptor is a fully customizable pentest reporting platform. Prior to 2026.68, the password authentication flow for pro...
CVE-2026-81178LOW3.5SysReptor is a fully customizable pentest reporting platform. Prior to 2026.55, an unauthenticated holder of a public no...
CVE-2026-91142LOW3.6A flaw was found in Cockpit. An integer overflow vulnerability in the `do_lastlog()` function, specifically in the offse...
CVE-2026-85478LOW3.5A CM2507 IP camera running firmware version HMT.CM2507 v251211.1507 exposes an interactive bootloader through a physical...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now