2026 CVE Vulnerabilities

42,999 CVEs published in 2026.

Filter:LOWClear
CVE IDSeverityCVSSDescription
CVE-2026-49262LOW3In the Aimeos Pagible content management system prior to version 0.10.4, the administrative proxy route (`cmsproxy`) is ...
CVE-2026-70467LOW3.8A server-side request forgery (ssrf) vulnerability in Fortinet FortiSIEM 7.5.0, FortiSIEM 7.4.0 through 7.4.2, FortiSIEM...
CVE-2026-18044LOW3.7The Estatik Real Estate Plugin WordPress plugin before 4.3.4 does not validate the same recipient list that it later use...
CVE-2026-64951LOW3.5A rogue Velociraptor client can upload a malformed sparse file such that if the GUI attempts to expand the file, a panic...
CVE-2026-73283LOW2.5In sshd in OpenSSH before 10.5, the restrict keyword (in authorized_keys) was supposed to be applicable to tunnel forwar...
CVE-2026-73281LOW3.5In ssh-agent in OpenSSH before 10.5, some operations can occur remotely but were intended to occur only locally, includi...
CVE-2026-65655LOW2.3When OAuth authentication is enabled and browser-facing TLS terminates at a reverse proxy that forwards the callback to ...
CVE-2026-48412LOW2.7Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An att...
CVE-2026-73087LOW2.3Dozzle is a realtime log viewer for docker containers. From 10.5.2 until 10.6.15, the isBlockedIP SSRF guard in internal...
CVE-2026-28729LOW2.4Integer overflow in the UEFI firmware for the Intel(R) Slim Bootloader may allow an information disclosure. System softw...
CVE-2026-25194LOW1.8Out-of-bounds write in the firmware for the Intel(R) Slim Bootloader may allow a denial of service. System software adve...
CVE-2026-73071LOW3.3Vim is an open source, command line text editor. From 9.2.0511 until 9.2.0844, json_decode_item() in src/json.c can reta...
CVE-2026-11736LOW1.9A stack-based buffer overflow vulnerability affects certain NETGEAR models allowing an authenticated admin user to make ...
CVE-2026-11735LOW1.9A stack-based buffer overflow vulnerability affects the listed NETGEAR models allowing an authenticated admin user to ma...
CVE-2026-11734LOW1.1A buffer overflow vulnerability in the listed NETGEAR models allows an authenticated admin user to cause the affected de...
CVE-2026-11733LOW1.1A buffer overflow vulnerability in the listed NETGEAR models allows a device administrator to temporarily interrupt the ...
CVE-2026-73157LOW2.3Affected versions of cti-transmute render data obtained from a remote MISP instance into the event-browser interface usi...
CVE-2026-11985LOW3.6On the Zephyr ARM port, enabling the hardware FPU (CONFIG_FPU) forces the "Floating point ABI" choice, which defaults to...
CVE-2026-66774LOW3.7SAP Approuter does not consistently handle certain error conditions. An attacker with low privileges could exploit this ...
CVE-2026-58245LOW3.8SAP Advanced Planning and Optimization (Model Mix Planning) contains a hardcoded credential within the source code of th...
CVE-2026-58239LOW3.7SAP Approuter does not sufficiently validate tenant context in inbound requests. An unauthenticated attacker could send ...
CVE-2026-44762LOW3.7SAP Data Services Management Console allows an overly permissive Content Security Policy (CSP) configuration and lacks c...
CVE-2026-11812LOW2.5The UpdateHub management subsystem (subsys/mgmt/updatehub/updatehub.c) drives every update operation through a single fi...
CVE-2026-11811LOW3.7The UpdateHub over-the-air update client's start_coap_client() in subsys/mgmt/updatehub/updatehub.c leaks the CoAP/DTLS ...
CVE-2026-19411LOW3.9A NULL pointer vulnerability has been found in the the shim application of dp.c library. A missing NULL pointer could al...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now