2026 CVE Vulnerabilities

64,788 CVEs published in 2026.

Filter:LOWClear
CVE IDSeverityCVSSDescription
CVE-2026-32970LOW3.3OpenClaw before 2026.3.11 contains a credential fallback vulnerability where unavailable local gateway.auth.token and ga...
CVE-2026-21716LOW3.3An incomplete fix for CVE-2024-36137 leaves `FileHandle.chmod()` and `FileHandle.chown()` in the promises API without th...
CVE-2026-21715LOW3.3A flaw in Node.js Permission Model filesystem enforcement leaves `fs.realpathSync.native()` without the required read pe...
CVE-2026-5037LOW3.3A vulnerability was determined in mxml up to 4.0.4. This issue affects the function index_sort of the file mxml-index.c ...
CVE-2026-4995LOW3.5A vulnerability was determined in wandb OpenUI up to 1.0. Affected by this vulnerability is an unknown functionality of ...
CVE-2026-4994LOW3.5A vulnerability was found in wandb OpenUI up to 1.0/3.5-turb. Affected is the function generic_exception_handler of the ...
CVE-2026-4993LOW3.3A vulnerability has been found in wandb OpenUI up to 0.0.0.0/1.0. This impacts an unknown function of the file backend/o...
CVE-2026-4973LOW3.5A vulnerability was detected in SourceCodester Online Quiz System up to 1.0. Affected by this vulnerability is an unknow...
CVE-2026-4972LOW2.4A security vulnerability has been detected in code-projects Online Reviewer System up to 1.0. Affected is an unknown fun...
CVE-2026-4969LOW3.5A vulnerability was identified in code-projects Social Networking Site 1.0. The impacted element is an unknown function ...
CVE-2026-4957LOW2.7A flaw has been found in OpenBMB XAgent 1.0.0. The impacted element is the function FunctionHandler.handle_tool_call of ...
CVE-2026-4909LOW2.4A weakness has been identified in code-projects Exam Form Submission 1.0. This impacts an unknown function of the file /...
CVE-2026-4899LOW2.4A security flaw has been discovered in code-projects Online Food Ordering System 1.0. Affected by this issue is some unk...
CVE-2026-0968LOW3.1A flaw was found in libssh in which a malicious SFTP (SSH File Transfer Protocol) server can exploit this by sending a m...
CVE-2026-0965LOW3.3A flaw was found in libssh where it can attempt to open arbitrary files during configuration parsing. A local attacker c...
CVE-2026-3109LOW2.2Mattermost Plugins versions <=11.4 10.11.11.0 fail to validate webhook request timestamps which allows an attacker to co...
CVE-2026-4874LOW3.1A flaw was found in Keycloak. An authenticated attacker can perform Server-Side Request Forgery (SSRF) by manipulating t...
CVE-2026-4835LOW3.5A security vulnerability has been detected in code-projects Accounting System 1.0. Impacted is an unknown function of th...
CVE-2026-4833LOW3.3A weakness has been identified in Orc discount up to 3.0.1.2. This issue affects the function compile of the file markdo...
CVE-2026-4831LOW3.7A security flaw has been discovered in kalcaddle kodbox 1.64. Impacted is the function can of the file /workspace/source...
CVE-2026-4823LOW2.5A flaw has been found in Enter Software Iperius Backup up to 8.7.3. Affected by this vulnerability is an unknown functio...
CVE-2026-4363LOW3.7GitLab has remediated an issue in GitLab EE affecting all versions from 18.1 before 18.8.7, 18.9 before 18.9.3, and 18.1...
CVE-2026-28893LOW3.3A privacy issue was addressed with improved handling of temporary files. This issue is fixed in macOS Tahoe 26.4. A docu...
CVE-2026-28864LOW3.3This issue was addressed with improved permissions checking. This issue is fixed in iOS 18.7.7 and iPadOS 18.7.7, iOS 26...
CVE-2026-20684LOW3.3A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Tahoe 26.4. An app may bypa...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now