2026 CVE Vulnerabilities

64,729 CVEs published in 2026.

Filter:LOWClear
CVE IDSeverityCVSSDescription
CVE-2026-61633LOW2NanoMQ is an MQTT broker. Prior to 0.24.14, the NanoMQ client function nni_mqtt_msg_decode_unsubscribe() in nng/src/supp...
CVE-2026-44639LOW3.7NanoMQ is an MQTT broker. Prior to 0.24.14, NanoMQ's MQTT v5 property decoder in nng/src/supplemental/mqtt/mqtt_codec.c ...
CVE-2026-84449LOW3.7libheif is a HEIF and AVIF file format decoder and encoder. Prior to 1.19.6, Op_RGB24_32_to_YCbCr::convert_colorspace() ...
CVE-2026-84400LOW3.1CareCam CM2507 IP cameras contain an insufficiently protected network maintenance mechanism that can activate a remote d...
CVE-2026-93676LOW3.2xdg-dbus-proxy incorrectly filters D-Bus broadcast messages, bypassing configured path, interface, and member restrictio...
CVE-2026-93505LOW3.5A vulnerability was found in SveltyCMS 0.0.6. This vulnerability affects unknown code of the file src/utils/media/media-...
CVE-2026-16512LOW3.1gptp_handle_msg() in subsys/net/l2/ethernet/gptp/gptp.c dereferenced the gPTP header returned by GPTP_HDR() and switched...
CVE-2026-93601LOW2.2rustls-webpki (the Rust webpki fork used by rustls) versions >= 0.101.0 and prior to 0.103.12 and 0.104.0-alpha.6 incorr...
CVE-2026-93600LOW2.2rustls-webpki (rustls/webpki) versions 0.101.0 through 0.103.11 and 0.104.0-alpha releases before 0.104.0-alpha.6 ignore...
CVE-2026-93590LOW3.7ImageMagick before 7.1.2-31 contains a policy bypass vulnerability in the UHDR encoder that fails to perform policy chec...
CVE-2026-93589LOW3.7ImageMagick before 7.1.2-31 and 6.9.13-56 contains a division-by-zero flaw in the FLIF encoder. An incorrect value for t...
CVE-2026-93588LOW3.1ImageMagick before 7.1.2-31 and before 6.9.13-56 contains a NULL pointer dereference in the PNM coder. When the coder re...
CVE-2026-93587LOW3.3ImageMagick before 7.1.2-31 and before 6.9.13-56 contains a policy bypass in the PCD (and, per the upstream advisory, CU...
CVE-2026-93586LOW2.9ImageMagick before 7.1.2-31 and before 6.9.13-56 contains a use-after-free vulnerability in the ImagesToBlob method, cau...
CVE-2026-28199LOW3.3An authenticated user with access to the NetBackup Flex OS management shell could read arbitrary files from the underly...
CVE-2026-21806LOW3.1HCL BigFix Service Management is affected by an Administrative Session Concurrency vulnerability. The application allows...
CVE-2026-56597LOW3.1HCL BigFix Service Management is affected by a Sensitive Information Leakage vulnerability, which could allow an unauthe...
CVE-2026-56595LOW3.1HCL BigFix Service Management is affected by a CORS Misconfiguration vulnerability due to improperly validated origin he...
CVE-2026-40538LOW3.7An improper restriction of excessive authentication attempts vulnerability in Auto block in Synology DiskStation Manager...
CVE-2026-13683LOW2.7An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in EventScheduler ...
CVE-2026-13666LOW3.5An improper neutralization of CRLF sequences ('CRLF Injection') vulnerability in Sharing API in Synology DiskStation Man...
CVE-2026-89008LOW2.7The Bookit — Booking & Appointment Calendar WordPress plugin before 2.6.0.5 does not perform an authorization check on o...
CVE-2026-89007LOW2.7The Bookit — Booking & Appointment Calendar WordPress plugin before 2.6.0.5 does not perform a capability check in one o...
CVE-2026-88844LOW2.7The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.50 does not verify that the requesting user owns the c...
CVE-2026-84904LOW3.8The King Addons for Elementor WordPress plugin before 51.1.81 does not perform per-object authorization checks on a gro...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now