2026 CVE Vulnerabilities

64,729 CVEs published in 2026.

Filter:LOWClear
CVE IDSeverityCVSSDescription
CVE-2026-84903LOW2.7The King Addons for Elementor WordPress plugin before 51.1.81 does not perform any capability, post-status, or password...
CVE-2026-81340LOW3.8The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.50 does not perform per-object ownership or capability...
CVE-2026-68493LOW3.1After guessing a 62^15 complex unique identifier, a malicious logged in user was able to retrieve a list of memberships ...
CVE-2026-93394LOW3.7A flaw in libmongoc's SCRAM authentication implementation caused the client to continue the authentication handshake and...
CVE-2026-93384LOW3.7Server-side request forgery in Omnibox in Google Chrome on on Android prior to 153.0.8010.52 allowed a remote attacker l...
CVE-2026-93380LOW3.1Race condition in FileSystem in Google Chrome prior to 153.0.8010.52 allowed a remote attacker who had compromised the r...
CVE-2026-93378LOW3.1Missing authorization in Storage in Google Chrome prior to 153.0.8010.52 allowed a remote attacker who had compromised t...
CVE-2026-45723LOW2.7Omni manages Kubernetes on bare metal, virtual machines, or in a cloud. Prior to 1.6.6 and 1.7.3, managementServer.Creat...
CVE-2026-55061LOW1uniget is a universal installer and updater for (container) tools. Prior to 0.27.6, the hooks edit command in cmd/uniget...
CVE-2026-54649LOW2.1punchin-email is a Cloudflare Email Worker that provides two-way role aliases while relaying mail to a private inbox. Pr...
CVE-2026-85716LOW3.7The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HT...
CVE-2026-54579LOW2.3mport is the MidnightBSD Package Manager. Prior to 2.7.8, ping() in libmport/ping.c accepted ICMP replies without valida...
CVE-2026-54578LOW2mport is the MidnightBSD Package Manager. Prior to 2.7.8, mport_verify_package() in libmport/verify.c could continue aft...
CVE-2026-54577LOW2mport is the MidnightBSD Package Manager. Prior to 2.7.8, the audit command in mport/mport.c computed option-adjusted lo...
CVE-2026-75588LOW2.6Mattermost Desktop App versions <=6.2 6.2.2.0 fail to validate the URL scheme when checking whether a target URL is inte...
CVE-2026-61700LOW3.7MariaDB Connector/J is used to connect applications developed in Java to MariaDB and MySQL databases. Prior to 2.7.14, 3...
CVE-2026-12284LOW3.7Mattermost Desktop App versions <=6.2 6.2.2.0 fails to validate the IPC sender in the leaveCall handler which allows a m...
CVE-2026-54471LOW3.5Dell SmartFabric Manager, versions prior to 2.2.1, contains an Improper Handling of Insufficient Permissions or Privileg...
CVE-2026-92962LOW2.1vm2 is a sandbox for running untrusted JavaScript. In vm2 versions up to and including 3.11.3, the defaultSandboxPrepare...
CVE-2026-82759LOW1.8Use of a One-Way Hash with a Predictable Salt vulnerability in team-alembic AshAuthentication allows readers of the audi...
CVE-2026-82723LOW1.8Insertion of Sensitive Information into Log File vulnerability in team-alembic AshAuthentication allows disclosure of us...
CVE-2026-81637LOW2.3Insufficient Session Expiration vulnerability in team-alembic AshAuthentication allows an attacker who obtains a victim'...
CVE-2026-81439LOW3.7Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Incorrect Authorization vulnerability. A l...
CVE-2026-81438LOW3.7Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains Use of a Broken or Risky Cryptographic Algori...
CVE-2026-78426LOW3.7The NeuVector JWT verifier accepts noncanonical Base64URL encodings of the same RSA signature field. An attacker holding...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now