2026 CVE Vulnerabilities

64,788 CVEs published in 2026.

Filter:LOWClear
CVE IDSeverityCVSSDescription
CVE-2026-33081LOW3.7PinchTab is a standalone HTTP server that gives AI agents direct control over a Chrome browser. Versions 0.8.2 and below...
CVE-2026-4477LOW3.1A vulnerability was determined in Yi Technology YI Home Camera 2 2.1.1_20171024151200. This affects an unknown function ...
CVE-2026-32946LOW2.7Harden-Runner is a CI/CD security agent that works like an EDR for GitHub Actions runners. In versions 2.15.1 and below,...
CVE-2026-22735LOW2.6Spring MVC and WebFlux applications are vulnerable to stream corruption when using Server-Sent Events (SSE). This issue ...
CVE-2026-33408LOW2.7Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, moderators...
CVE-2026-29104LOW2.7SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Prior to versi...
CVE-2026-4159LOW3.31-byte OOB heap read in wc_PKCS7_DecodeEnvelopedData via zero-length encrypted content. A vulnerability existed in wolfS...
CVE-2026-33394LOW2.7Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, the Post E...
CVE-2026-3230LOW2.7Missing required cryptographic step in the TLS 1.3 client HelloRetryRequest handshake logic in wolfSSL could lead to a c...
CVE-2026-32735LOW2.3openapi-to-java-records-mustache-templates allows users to generate Java Records from OpenAPI specifications. Starting i...
CVE-2026-4407LOW2.1Out-of-bounds array write in Xpdf 4.06 and earlier, due to incorrect validation of the "N" field in ICCBased color space...
CVE-2026-32943LOW3.1Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-a...
CVE-2026-32638LOW2.7StudioCMS is a server-side-rendered, Astro native, headless content management system. Prior to 0.4.4, the REST API `get...
CVE-2026-32266LOW2.4The Google Cloud Storage for Craft CMS plugin provides a Google Cloud Storage integration for Craft CMS. In versions on ...
CVE-2026-4356LOW2.4A flaw has been found in itsourcecode University Management System 1.0. Affected is an unknown function of the file /add...
CVE-2026-4355LOW3.5A vulnerability was detected in Portabilis i-Educar 2.11. This impacts an unknown function of the file /intranet/educar_...
CVE-2026-4354LOW3.5A vulnerability was identified in TRENDnet TEW-824DRU 1.010B01/1.04B01. The impacted element is the function sub_420A78 ...
CVE-2026-4359LOW3.7A compromised third party cloud server or man-in-the-middle attacker could send a malformed HTTP response and cause a cr...
CVE-2026-4285LOW2.7A vulnerability was identified in taoofagi easegen-admin up to 8f87936ac774065b92fb20aab55b274a6ea76433. Impacted is the...
CVE-2026-26230LOW3.8Mattermost versions 10.11.x <= 10.11.10 fail to properly validate permission requirements in the team member roles API e...
CVE-2026-4251LOW2.5A vulnerability was determined in CityData CityChat up to 0.12.6 on Android. Affected by this vulnerability is an unknow...
CVE-2026-4250LOW2.5A vulnerability was found in Albert Sağlık Hizmetleri ve Ticaret Albert Health up to 1.7.3 on Android. Affected is an un...
CVE-2026-4243LOW2.5A weakness has been identified in La Nacion App 10.2.25 on Android. This impacts an unknown function of the file source/...
CVE-2026-4242LOW2.5A security flaw has been discovered in BabyChakra Pregnancy & Parenting App up to 5.4.3.0 on Android. This affects an un...
CVE-2026-22545LOW3.5Mattermost versions 10.11.x <= 10.11.10 fail to validate user's authentication method when processing account auth type ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now