2026 CVE Vulnerabilities

64,785 CVEs published in 2026.

Filter:LOWClear
CVE IDSeverityCVSSDescription
CVE-2026-45316LOW3.5Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.3, the P...
CVE-2026-45803LOW3.5`gh` is GitHub’s official command line tool. From 1.6.0 to before 2.92.0, a security vulnerability has been identified i...
CVE-2026-41963LOW2.8Stack overflow vulnerability in the media platform. Impact: Successful exploitation of this vulnerability may affect ava...
CVE-2026-41962LOW3.6Permission control vulnerability in the app management and control module. Impact: Successful exploitation of this vulne...
CVE-2026-0428LOW1.8Insufficient parameter sanitization in TEE SOC Driver could allow an attacker to issue a malformed DRV_SOC_CMD_ID_SRIOV_...
CVE-2026-45781LOW3.5The MCP Registry provides MCP clients with a list of MCP servers, like an app store for MCP servers. Prior to 1.7.9, OCI...
CVE-2026-8579LOW3.1Insufficient validation of untrusted input in Skia in Google Chrome prior to 148.0.7778.168 allowed a remote attacker wh...
CVE-2026-8578LOW3.1Out of bounds read in GPU in Google Chrome on Linux prior to 148.0.7778.168 allowed a remote attacker who had compromise...
CVE-2026-8572LOW3.1Insufficient policy enforcement in Network in Google Chrome on Android prior to 148.0.7778.168 allowed a remote attacker...
CVE-2026-8556LOW3.1Inappropriate implementation in ANGLE in Google Chrome on Windows prior to 148.0.7778.168 allowed a remote attacker who ...
CVE-2026-8554LOW3.1Type Confusion in ANGLE in Google Chrome on Windows prior to 148.0.7778.168 allowed a remote attacker who had compromise...
CVE-2026-8553LOW3.1Use after free in GPU in Google Chrome prior to 148.0.7778.168 allowed a remote attacker who had compromised the rendere...
CVE-2026-8545LOW3.1Object corruption in Compositing in Google Chrome prior to 148.0.7778.168 allowed a remote attacker who had compromised ...
CVE-2026-8536LOW3.1Insufficient validation of untrusted input in ReadingMode in Google Chrome on Mac prior to 148.0.7778.168 allowed a remo...
CVE-2026-44638LOW2.5libsixel is a SIXEL encoder/decoder implementation derived from kmiya's sixel. From to 1.8.7-r1, a wrong NULL check aft...
CVE-2026-44589LOW3.7Nuxt OG Image generates OG Images with Vue templates in Nuxt. The isBlockedUrl() denylist introduced in nuxt-og-image@6....
CVE-2026-6923LOW3.8A side-channel attack, which requires a physical presence to the TPM, can lead to extraction of an Elliptic Curve Diffie...
CVE-2026-44515LOW2.3Nextcloud News is an RSS/Atom feed reader. Prior to 28.3.0-beta.1, Nextcloud News allows authenticated users to add feed...
CVE-2026-44348LOW2.5PoDoFo is a C++17 PDF manipulation library. From 1.0.0 to before 1.0.4, a double-free vulnerability exists in compute_ha...
CVE-2026-7471LOW3.5GitLab has remediated an issue in GitLab EE affecting all versions from 18.8 before 18.9.7, 18.10 before 18.10.6, and 18...
CVE-2026-2900LOW2.7GitLab has remediated an issue in GitLab EE affecting all versions from 16.10 before 18.9.7, 18.10 before 18.10.6, and 1...
CVE-2026-33585LOW3.8Improper management of the idle timeout parameter in the Keycloak interface of the Arqit SKA-Platform enables an attacke...
CVE-2026-0238LOW3.2A vulnerability in Palo Alto Networks Broker VM allows an authenticated administrator to inject arbitrary content into c...
CVE-2026-44582LOW3.7Next.js is a React framework for building full-stack web applications. From 13.4.6 to before 15.5.16 and 16.2.5, React S...
CVE-2026-44459LOW3.8Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.18, improper validat...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now