2026 CVE Vulnerabilities

64,803 CVEs published in 2026.

Filter:LOWClear
CVE IDSeverityCVSSDescription
CVE-2026-1743LOW3.1A vulnerability has been found in DJI Mavic Mini, Air, Spark and Mini SE up to 01.00.0500. Affected by this vulnerabilit...
CVE-2026-1705LOW2.4A vulnerability was detected in D-Link DSL-6641K N8.TR069.20131126. Affected by this issue is the function ad_virtual_se...
CVE-2026-25211LOW3.2Llama Stack (aka llama-stack) before 0.4.0rc3 does not censor the pgvector password in the initialization log.
CVE-2026-25046LOW2.9Kimi Agent SDK is a set of libraries that expose the Kimi Code (Kimi CLI) agent runtime in applications. The vsix-publis...
CVE-2026-1588LOW2.7A vulnerability was found in jishenghua jshERP up to 3.6. The impacted element is the function install of the file /jshE...
CVE-2026-23553LOW2.9In the context switch logic Xen attempts to skip an IBPB in the case of a vCPU returning to a CPU on which it was the pr...
CVE-2026-1520LOW2.4A vulnerability was identified in rethinkdb up to 2.4.3. Affected by this issue is some unknown functionality of the com...
CVE-2026-1237LOW2.1Vulnerable cross-model authorization in juju. If a charm's cross-model permissions are revoked or expire, a malicious us...
CVE-2026-1485LOW2.8A flaw was found in Glib's content type parsing logic. This buffer underflow vulnerability occurs because the length of ...
CVE-2026-1444LOW2.4A vulnerability has been found in iJason-Liu Books_Manager up to 298ba736387ca37810466349af13a0fdf828e99c. This affects ...
CVE-2026-1190LOW3.1A flaw was found in Keycloak's SAML brokering functionality. When Keycloak is configured as a client in a Security Asser...
CVE-2026-24656LOW3.7Deserialization of Untrusted Data vulnerability in Apache Karaf Decanter. The Decanter log socket collector exposes th...
CVE-2026-1417LOW3.3A weakness has been identified in GPAC up to 2.4.0. Affected by this issue is the function dump_isom_rtp of the file app...
CVE-2026-1416LOW3.3A security flaw has been discovered in GPAC up to 2.4.0. Affected by this vulnerability is the function DumpMovieInfo of...
CVE-2026-1415LOW3.3A vulnerability was identified in GPAC up to 2.4.0. Affected is the function gf_media_export_webvtt_metadata of the file...
CVE-2026-1406LOW3.5A vulnerability was determined in lcg0124 BootDo up to 5ccd963c74058036b466e038cff37de4056c1600. Affected by this vulner...
CVE-2026-0633LOW3.7The MetForm – Contact Form, Survey, Quiz, & Custom Form Builder for Elementor plugin for WordPress is vulnerable to Sens...
CVE-2026-22978LOW3.3In the Linux kernel, the following vulnerability has been resolved: wifi: avoid kernel-infoleak from struct iw_point s...
CVE-2026-24515LOW2.5In libexpat before 2.7.4, XML_ExternalEntityParserCreate does not copy unknown encoding handler user data.
CVE-2026-0798LOW3.5Gitea may send release notification emails for private repositories to users whose access has been revoked. When a repos...
CVE-2026-22411LOW3.8Authorization Bypass Through User-Controlled Key vulnerability in Mikado-Themes Dolcino dolcino allows Exploiting Incorr...
CVE-2026-22409LOW3.8Authorization Bypass Through User-Controlled Key vulnerability in Mikado-Themes Justicia justicia allows Exploiting Inco...
CVE-2026-22407LOW3.8Authorization Bypass Through User-Controlled Key vulnerability in Mikado-Themes Roam roam allows Exploiting Incorrectly ...
CVE-2026-22406LOW3.8Authorization Bypass Through User-Controlled Key vulnerability in Mikado-Themes Overton overton allows Exploiting Incorr...
CVE-2026-22404LOW3.8Authorization Bypass Through User-Controlled Key vulnerability in Mikado-Themes Innovio innovio allows Exploiting Incorr...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now