2026 CVE Vulnerabilities

64,803 CVEs published in 2026.

Filter:LOWClear
CVE IDSeverityCVSSDescription
CVE-2026-3963LOW3.7A security flaw has been discovered in perfree go-fastdfs-web up to 1.3.7. This affects the function rememberMeManager o...
CVE-2026-3929LOW3.1Side-channel information leakage in ResourceTiming in Google Chrome prior to 146.0.7680.71 allowed a remote attacker to ...
CVE-2026-0520LOW2.8A potential vulnerability was reported in the Lenovo FileZ Android application that, under certain conditions, could all...
CVE-2026-3950LOW3.3A vulnerability was identified in strukturag libheif up to 1.21.2. This impacts the function Track::load of the file lib...
CVE-2026-3949LOW3.3A vulnerability was determined in strukturag libheif up to 1.21.2. This affects the function vvdec_push_data2 of the fil...
CVE-2026-3946LOW3.5A vulnerability was detected in PHPEMS 11.0. The affected element is an unknown function of the file /index.php?ask=app-...
CVE-2026-3911LOW2.7A flaw was found in Keycloak. An authenticated user with the view-users role could exploit a vulnerability in the UserRe...
CVE-2026-21295LOW3.1Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by a ...
CVE-2026-0121LOW2.9In VPU, there is a possible use-after-free read due to a race condition. This could lead to local information disclosure...
CVE-2026-0115LOW2.1In Trusted Execution Environment, there is a possible key leak due to side channel information disclosure. This could le...
CVE-2026-30977LOW2RenderBlocking is a MediaWiki extension that allows interface administrators to specify render-blocking CSS and JavaScri...
CVE-2026-22629LOW3.7An improper restriction of excessive authentication attempts vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.4...
CVE-2026-21791LOW3.3HCL Sametime for Android is impacted by a sensitive information disclosure. Hostnames information is written in applica...
CVE-2026-3706LOW3.7A vulnerability was determined in mkj Dropbear up to 2025.89. Impacted is the function unpackneg of the file src/curve25...
CVE-2026-3671LOW3.3A flaw has been found in Freedom Factory dGEN1 up to 20260221. Affected by this vulnerability is the function TokenBalan...
CVE-2026-2671LOW3.1A vulnerability was detected in Mendi Neurofeedback Headset V4. Affected by this vulnerability is an unknown functionali...
CVE-2026-30848LOW3.7Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to version...
CVE-2026-3668LOW3.1A weakness has been identified in Freedom Factory dGEN1 up to 20260221. This affects the function AndroidEthereum of the...
CVE-2026-29185LOW2.7Backstage is an open framework for building developer portals. Prior to version 1.20.1, a vulnerability in the SCM URL p...
CVE-2026-27139LOW2.5On Unix platforms, when listing the contents of a directory using File.ReadDir or File.Readdir the returned FileInfo cou...
CVE-2026-28475LOW3.7OpenClaw versions prior to 2026.2.13 use non-constant-time string comparison for hook token validation, allowing attacke...
CVE-2026-28540LOW3.3Out-of-bounds character read vulnerability in Bluetooth. Impact: Successful exploitation of this vulnerability may affec...
CVE-2026-21786LOW3.3HCL Sametime for iOS is impacted by a sensitive information disclosure. Hostnames information is written in application...
CVE-2026-23811LOW3.1A vulnerability in the client isolation mechanism may allow an attacker to bypass Layer 2 (L2) communication restriction...
CVE-2026-23810LOW3.1A vulnerability in the packet processing logic may allow an authenticated attacker to craft and transmit a malicious Wi-...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now