2026 CVE Vulnerabilities

43,053 CVEs published in 2026.

Filter:LOWClear
CVE IDSeverityCVSSDescription
CVE-2026-15687LOW2.4A security issue was discovered in the Kubernetes Java client library where a compromised pod may be able to create new ...
CVE-2026-15037LOW2.9Improper output neutralization (XML injection) in QDom comment, CDATA, and processing-instruction serialization in Qt XM...
CVE-2026-52686LOW3.7The issue is a DNSSEC validation bypass where wildcard expansion proofs (NSEC/NSEC3 records) are accepted without signat...
CVE-2026-52684LOW3.7If the auth responds very slowly and the records expire in between, the capping of TTLs is not enforced for lack of data...
CVE-2026-55708LOW3.1In NLnet Labs Unbound 1.6.0 up to and including 1.25.1, the 'view_local_data' and 'view_local_datas' commands of 'unboun...
CVE-2026-54478LOW3.7In NLnet Labs Unbound 1.18.0 up to and including 1.25.1, when Unbound listens on a 'proxy-protocol-port' interface with ...
CVE-2026-53910LOW2.1diff3 tool from GNU diffutils is vulnerable to a heap‑based buffer overflow due to multiple signed integer overflows in ...
CVE-2026-50243LOW3.7In NLnet Labs Unbound 1.6.2 up to and including 1.25.1, when Unbound is configured with the 'respip' module in front of ...
CVE-2026-46582LOW3.7In NLnet Labs Unbound 1.6.0 up to and including 1.25.1, a replay of a wildcard rrset as another piece of data, could be ...
CVE-2026-44687LOW3.7In NLnet Labs Unbound 1.13.2 up to and including 1.25.1, stub or forward zones where the name is below an intermediate l...
CVE-2026-42955LOW3.7In NLnet Labs Unbound 1.16.2 up to and including 1.25.1, a similar vulnerability as with CVE-2026-40622 in the 'ghost do...
CVE-2026-41637LOW3.7In NLnet Labs Unbound 1.22.0 up to and including 1.25.1, client terminated DNS-over-QUIC (DoQ) queries are not accounted...
CVE-2026-44187LOW3.3A flaw was found in the Ansible Lightspeed extension for Visual Studio Code. This vulnerability allows an attacker with ...
CVE-2026-16517LOW2.9A signed integer overflow vulnerability was found in libarchive's ZIP writer. In the archive_write_zip_header function i...
CVE-2026-16417LOW3.1Uninitialized Use in Skia in Google Chrome prior to 150.0.7871.182 allowed a remote attacker who had compromised the ren...
CVE-2026-62508LOW3.1Vulnerability in the Oracle Time and Labor product of Oracle E-Business Suite (component: Internal Operations). Support...
CVE-2026-61303LOW1.9Vulnerability in the Oracle EDI Gateway product of Oracle E-Business Suite (component: Internal Operations). Supported ...
CVE-2026-61214LOW2.2Vulnerability in the Oracle HRMS (UK) product of Oracle E-Business Suite (component: UK Payroll). Supported versions th...
CVE-2026-61187LOW2.8Vulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (component: Install). The...
CVE-2026-61104LOW3.7Vulnerability in the PeopleSoft Enterprise CS Student Records product of Oracle PeopleSoft (component: Research Tracking...
CVE-2026-61096LOW2.9Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Pluggable Auth). Supported...
CVE-2026-61081LOW2.7Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Performance Schema). Suppo...
CVE-2026-61071LOW3.3Vulnerability in the PeopleSoft Enterprise FIN Engineering Argentina product of Oracle PeopleSoft (component: Engineerin...
CVE-2026-61048LOW3.1Vulnerability in the Oracle Inventory Optimization product of Oracle E-Business Suite (component: User Interface). Supp...
CVE-2026-61047LOW1.9Vulnerability in the Oracle Production Scheduling product of Oracle E-Business Suite (component: Internal Operations). ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now