2026 CVE Vulnerabilities

64,785 CVEs published in 2026.

Filter:LOWClear
CVE IDSeverityCVSSDescription
CVE-2026-42158LOW2.3Flowsint is an open-source OSINT graph exploration tool designed for cybersecurity investigation, transparency, and veri...
CVE-2026-44242LOW3.7Micronaut Framework is a JVM-based full stack Java framework designed for building modular, easily testable JVM applicat...
CVE-2026-44220LOW3.2ciguard is a static security auditor for CI/CD pipelines. From 0.8.0 to 0.8.1 , the discover_pipeline_files() function i...
CVE-2026-44219LOW3.7ciguard is a static security auditor for CI/CD pipelines. From 0.6.0 to 0.8.1, both SCA HTTP clients (src/ciguard/analyz...
CVE-2026-44218LOW3ciguard is a static security auditor for CI/CD pipelines. From 0.1.0 to 0.8.1, the published ghcr.io/jo-jo98/ciguard con...
CVE-2026-34685LOW3.4Adobe Commerce versions 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 and earlier are affected by an ...
CVE-2026-41611LOW3.3Improper neutralization of script-related html tags in a web page (basic xss) in Visual Studio Code allows an unauthoriz...
CVE-2026-20793LOW3.3Unchecked return value for some Intel(R) QAT software drivers for Windows before version 1.13 within Ring 3: User Applic...
CVE-2026-43514LOW3.7Observable Timing Discrepancy vulnerability when comparing AJP secret in Apache Tomcat. This issue affects Apache Tomca...
CVE-2026-32684LOW2.9The application does not impose strict enough restrictions on directory access permissions, posing a risk that other mal...
CVE-2026-40131LOW3.4SQL injection vulnerability exists in @sap/hdi-deploy package, where SQL queries are dynamically constructed using user ...
CVE-2026-45362LOW3.2Sangoma Switchvox before 8.4 places cleartext SIP authentication credentials in a backup file.
CVE-2026-28957LOW3.3An issue with app access to camera metadata was addressed with improved logic. This issue is fixed in iOS 18.7.9 and iPa...
CVE-2026-28910LOW3.3This issue was addressed with improved permissions checking. This issue is fixed in macOS Tahoe 26.4. A malicious app ma...
CVE-2026-42874LOW3.7Microdot is a minimalistic Python web framework. Prior to 2.6.1, the Response.set_cookie() method does not sanitize its ...
CVE-2026-43969LOW3.2Improper Neutralization of CRLF Sequences ('CRLF Injection') vulnerability in ninenines cowlib allows HTTP request split...
CVE-2026-5266LOW2.3Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation Echo. This vulnerabil...
CVE-2026-44658LOW2.4Zen is a firefox-based browser. Prior to 1.19.12b, RSS feed URLs entered by the user are validated to http: or https: in...
CVE-2026-3048LOW3.8An authenticated administrator who configures or tests LDAP connectivity in Sonatype Nexus Repository Manager versions 3...
CVE-2026-34094LOW3.8Vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/Page/Art...
CVE-2026-34086LOW2.1Vulnerability in Wikimedia Foundation AbuseFilter. This issue affects AbuseFilter: from * before 1.43.7, 1.44.4, 1.45.2...
CVE-2026-8276LOW3.7A flaw has been found in bettercap up to 2.41.5. Affected by this issue is some unknown functionality of the file module...
CVE-2026-8275LOW3.7A vulnerability was detected in bettercap up to 2.41.5. Affected by this vulnerability is the function ippReadChunkedBod...
CVE-2026-8262LOW2.4A vulnerability was identified in Devs Palace ERP Online up to 4.0.0. This impacts an unknown function of the file /acco...
CVE-2026-8256LOW2.4A security vulnerability has been detected in Devs Palace ERP Online up to 4.0.0. This vulnerability affects unknown cod...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now