2026 CVE Vulnerabilities

43,031 CVEs published in 2026.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2026-68971Apache Airflow's asset materialization endpoint (`POST /api/v2/assets/{asset_id}/materialize`) and the XCom result check...
CVE-2026-68970Apache Airflow's Task SDK did not mask the contents of a Variable whose JSON value is a list, so secrets stored in that ...
CVE-2026-68969Apache Airflow wrote Variable values and Connection `extra` contents to the audit log in cleartext when they were submit...
CVE-2026-68968Apache Airflow's Backfill API authorized a request against a Dag id supplied by the caller whenever the `backfill_id` pa...
CVE-2026-68076Apache Airflow's environment-variable secrets backend resolved a team-scoped Connection or Variable from the wrong team'...
CVE-2026-67587Apache Airflow's Task SDK rebuilt a `Callback` object from serialized data by re-running its constructor, which imports ...
CVE-2026-65017Apache Airflow's Config API did not mask team-scoped sensitive configuration values in multi-team deployments. When an a...
CVE-2026-59244Apache Airflow's secrets masker did not mask `var.json` Variable values whose value is a dict in the Rendered Templates ...
CVE-2026-59242Apache Airflow's XCom `GET /api/v2/{...}/xcomEntries/{key}?deserialize=true` endpoint passed a string-literal payload th...
CVE-2026-58076Apache Airflow's serialization layer reconstructed exception nodes by calling `import_string()` on a class name taken fr...
CVE-2026-54183Apache Airflow's secrets masker hides values stored under sensitive key names when they are displayed in the UI. The mas...
CVE-2026-68868The Google Cloud Secret Manager secrets backend in Apache Airflow's Google provider never applied the team scope when re...
CVE-2026-19566Net::CIDR::Set versions before 0.23 for Perl allow memory exhaustion and malformed set ranges via unbounded IPv6 prefix ...
CVE-2026-19217The Royal Addons for Elementor WordPress plugin before 1.7.1065 does not validate a widget setting used to build an HTM...
CVE-2026-18391The WooCommerce Subscriptions WordPress plugin before 9.1.0 does not validate user input before unserializing it on stor...
CVE-2026-18366The Events Manager WordPress plugin before 7.4.1 does not properly scope its capability mapping, discarding the access ...
CVE-2026-18230The WP Directory Kit WordPress plugin before 1.5.6 does not sanitise and escape a parameter before using it in a SQL sta...
CVE-2026-18057The Events Manager WordPress plugin before 7.4.1 does not sanitise and escape a user-controlled value before using it i...
CVE-2026-18049The WP Photo Album Plus WordPress plugin before 9.2.07.002 does not perform any capability or nonce check on one of its ...
CVE-2026-18048The WP Photo Album Plus WordPress plugin before 9.2.07.002 does not validate a client-controlled value used to build a f...
CVE-2026-18046The Cookie Consent WordPress plugin before 0.0.10 does not correctly enforce its intended administrator-only capability...
CVE-2026-18035The User Access Manager WordPress plugin before 2.3.15 does not apply its access restrictions to REST API requests, allo...
CVE-2026-17013The WP Photo Album Plus WordPress plugin before 9.2.07.002 does not sanitise and escape a parameter before reflecting it...
CVE-2026-16977The Form Maker by 10Web WordPress plugin before 1.15.45 does not properly parameterize a user-controlled value that is ...
CVE-2026-16737The WP Travel Engine WordPress plugin before 6.8.5 does not perform authorization or ownership checks when loading a ca...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now