2026 CVE Vulnerabilities

64,803 CVEs published in 2026.

Filter:LOWClear
CVE IDSeverityCVSSDescription
CVE-2026-0228LOW1.3An improper certificate validation vulnerability in PAN-OS allows users to connect Terminal Server Agents on Windows to ...
CVE-2026-2345LOW3.6Proctorio Chrome Extension is a browser extension used for online proctoring. The extension contains multiple window.add...
CVE-2026-26013LOW3.7LangChain is a framework for building agents and LLM-powered applications. Prior to 1.2.11, the ChatOpenAI.get_num_token...
CVE-2026-1762LOW2.9A vulnerability in GE Vernova Enervista UR Setup on Windows allows File Manipulation.This issue affects Enervista: 8.6 a...
CVE-2026-21249LOW3.3External control of file name or path in Windows NTLM allows an unauthorized attacker to perform spoofing locally.
CVE-2026-23901LOW2.5Observable Timing Discrepancy vulnerability in Apache Shiro. This issue affects Apache Shiro: from 1.*, 2.* before 2.0....
CVE-2026-24320LOW3.1Due to improper memory management in SAP NetWeaver and ABAP Platform (Application Server ABAP), an authenticated attacke...
CVE-2026-23686LOW3.4Due to a CRLF Injection vulnerability in SAP NetWeaver Application Server Java, an authenticated attacker with administr...
CVE-2026-2246LOW3.3A security vulnerability has been detected in AprilRobotics apriltag up to 3.4.5. Affected by this vulnerability is the ...
CVE-2026-2245LOW3.3A vulnerability was identified in CCExtractor up to 183. This affects the function parse_PAT/parse_PMT in the library sr...
CVE-2026-2215LOW3.7A vulnerability was detected in rachelos WeRSS we-mp-rss up to 1.4.8. This issue affects some unknown processing of the ...
CVE-2026-2069LOW3.3A flaw has been found in ggml-org llama.cpp up to 55abc39. Impacted is the function llama_grammar_advance_stack of the f...
CVE-2026-25764LOW3.5OpenProject is an open-source, web-based project management software. Prior to versions 16.6.7 and 17.0.3, an HTML injec...
CVE-2026-22254LOW3.5Winter is a free, open-source content management system (CMS) based on the Laravel PHP framework. Versions of Winter CMS...
CVE-2026-1990LOW3.3A security vulnerability has been detected in oatpp up to 1.3.1. This impacts the function oatpp::data::type::ObjectWrap...
CVE-2026-25815LOW3.2Fortinet FortiOS through 7.6.6 allows attackers to decrypt LDAP credentials stored in device configuration files, as exp...
CVE-2026-1966LOW2.4YugabyteDB Anywhere displays LDAP bind passwords configured via gflags in cleartext within the web UI. An authenticated ...
CVE-2026-25517LOW2.7Wagtail is an open source content management system built on Django. Prior to versions 6.3.6, 7.0.4, 7.1.3, 7.2.2, and 7...
CVE-2026-20730LOW3.3A vulnerability exists in BIG-IP Edge Client and browser VPN clients on Windows that may allow attackers to gain access ...
CVE-2026-1791LOW2.7Unrestricted Upload of File with Dangerous Type vulnerability in Hillstone Networks Operation and Maintenance Security G...
CVE-2026-24513LOW3.1A security issue was discovered in ingress-nginx where the protection afforded by the `auth-url` Ingress annotation may ...
CVE-2026-25224LOW3.7Fastify is a fast and low overhead web framework, for Node.js. Prior to version 5.7.3, a denial-of-service vulnerability...
CVE-2026-24934LOW3.7The DDNS function uses an insecure HTTP connection or fails to validate the SSL/TLS certificate when querying an externa...
CVE-2026-1703LOW2When pip is installing and extracting a maliciously crafted wheel archive, files may be extracted outside the installati...
CVE-2026-1751LOW3.1A vulnerability has been discovered in GitLab CE/EE affecting all versions starting with 16.8 before 18.5.0 that could h...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now