2026 CVE Vulnerabilities

64,785 CVEs published in 2026.

Filter:LOWClear
CVE IDSeverityCVSSDescription
CVE-2026-48190LOW3.5An incorrect handling of permissions in OTRS External Interface and the ConfigItem List module allows an authenticated c...
CVE-2026-10216LOW3.7A vulnerability was detected in unitedbyai droidclaw up to 0.5.3. The affected element is an unknown function of the fil...
CVE-2026-10201LOW3.3A vulnerability was determined in Assimp up to 6.0.4. This vulnerability affects the function FBXExporter::WriteObjects ...
CVE-2026-10199LOW3.3A vulnerability has been found in Assimp up to 6.0.4. Affected by this issue is the function glTF2::LazyDict in the libr...
CVE-2026-10198LOW3.3A flaw has been found in Assimp up to 6.0.4. Affected by this vulnerability is the function Assimp::glTFImporter::Import...
CVE-2026-10197LOW3.3A vulnerability was detected in Assimp up to 6.0.4. Affected is the function glTF2Importer::ImportEmbeddedTextures in th...
CVE-2026-10169LOW3.7A vulnerability was detected in OUSL-GROUP-BrinaryBrains School Student Management System up to 1e70e5ad1125b86dca4ee086...
CVE-2026-10112LOW2.4A vulnerability has been found in sambitraj STUDENT-MANAGEMENT-SYSTEM 1.0. Affected is an unknown function of the compon...
CVE-2026-4387LOW2StrongDM Desktop Application before 23.74.0 (Desktop Client before 53.77.0) on Microsoft Windows stores authentication s...
CVE-2026-45613LOW3.3Rizin is a UNIX-like reverse engineering framework and command-line toolset. There is a heap-buffer-overflow in librz/bi...
CVE-2026-45324LOW3.3Rizin is a UNIX-like reverse engineering framework and command-line toolset. There is a double free in librz/core/cmd/cm...
CVE-2026-45151LOW2.9NanoMQ MQTT Broker (NanoMQ) is an all-around Edge Messaging Platform. In 0.24.8 and earlier, quic_stream_recv can derefe...
CVE-2026-49383LOW3.3In JetBrains IntelliJ IDEA before 2026.1 xXE in the UI Designer form parser was possible
CVE-2026-33386LOW2.3QuickCMS is vulnerable to Cross-Site Scripting (XSS) through its insecure HTTP-based plugin‑fetching mechanism. A malici...
CVE-2026-49318LOW2.4Incorrect behavior order in the Infotainment / Digital Round display of the Indian Motorcycle Scout Bobber + Tech 2025 m...
CVE-2026-49317LOW2.4Incorrect behavior order in the Infotainment / Digital Round display of the Indian Motorcycle Scout Bobber + Tech 2025 m...
CVE-2026-10078LOW2.7A flaw was found in the Quay config-tool's GitLab OAuth validator. This vulnerability causes sensitive credentials, spec...
CVE-2026-9991LOW3.1Inappropriate implementation in Media in Google Chrome on Windows prior to 148.0.7778.216 allowed a remote attacker who ...
CVE-2026-9959LOW3.1Race in WebRTC in Google Chrome on Windows prior to 148.0.7778.216 allowed a remote attacker to leak cross-origin data v...
CVE-2026-9950LOW3.1Insufficient validation of untrusted input in iOS in Google Chrome on iOS prior to 148.0.7778.216 allowed a remote attac...
CVE-2026-9944LOW3.1Uninitialized Use in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the re...
CVE-2026-9920LOW3.1Uninitialized Use in GPU in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attacker who had compromis...
CVE-2026-6816LOW3.8An access bypass vulnerability in Drupal TFA Basic Plugins allows users with the administer users permission to view or ...
CVE-2026-10011LOW3.1Inappropriate implementation in Skia in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromi...
CVE-2026-45403LOW2.5AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatti...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now