2026 CVE Vulnerabilities
43,031 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-68971 | — | — | — | Aug 12, 2026 | Apache Airflow's asset materialization endpoint (`POST /api/v2/assets/{asset_id}/materialize`) and the XCom result check... |
| CVE-2026-68970 | — | — | — | Aug 12, 2026 | Apache Airflow's Task SDK did not mask the contents of a Variable whose JSON value is a list, so secrets stored in that ... |
| CVE-2026-68969 | — | — | — | Aug 12, 2026 | Apache Airflow wrote Variable values and Connection `extra` contents to the audit log in cleartext when they were submit... |
| CVE-2026-68968 | — | — | — | Aug 12, 2026 | Apache Airflow's Backfill API authorized a request against a Dag id supplied by the caller whenever the `backfill_id` pa... |
| CVE-2026-68076 | — | — | — | Aug 12, 2026 | Apache Airflow's environment-variable secrets backend resolved a team-scoped Connection or Variable from the wrong team'... |
| CVE-2026-67587 | — | — | — | Aug 12, 2026 | Apache Airflow's Task SDK rebuilt a `Callback` object from serialized data by re-running its constructor, which imports ... |
| CVE-2026-65017 | — | — | — | Aug 12, 2026 | Apache Airflow's Config API did not mask team-scoped sensitive configuration values in multi-team deployments. When an a... |
| CVE-2026-59244 | — | — | — | Aug 12, 2026 | Apache Airflow's secrets masker did not mask `var.json` Variable values whose value is a dict in the Rendered Templates ... |
| CVE-2026-59242 | — | — | — | Aug 12, 2026 | Apache Airflow's XCom `GET /api/v2/{...}/xcomEntries/{key}?deserialize=true` endpoint passed a string-literal payload th... |
| CVE-2026-58076 | — | — | — | Aug 12, 2026 | Apache Airflow's serialization layer reconstructed exception nodes by calling `import_string()` on a class name taken fr... |
| CVE-2026-54183 | — | — | — | Aug 12, 2026 | Apache Airflow's secrets masker hides values stored under sensitive key names when they are displayed in the UI. The mas... |
| CVE-2026-68868 | — | — | — | Aug 12, 2026 | The Google Cloud Secret Manager secrets backend in Apache Airflow's Google provider never applied the team scope when re... |
| CVE-2026-19566 | — | — | — | Aug 12, 2026 | Net::CIDR::Set versions before 0.23 for Perl allow memory exhaustion and malformed set ranges via unbounded IPv6 prefix ... |
| CVE-2026-19217 | — | — | — | Aug 12, 2026 | The Royal Addons for Elementor WordPress plugin before 1.7.1065 does not validate a widget setting used to build an HTM... |
| CVE-2026-18391 | — | — | — | Aug 12, 2026 | The WooCommerce Subscriptions WordPress plugin before 9.1.0 does not validate user input before unserializing it on stor... |
| CVE-2026-18366 | — | — | — | Aug 12, 2026 | The Events Manager WordPress plugin before 7.4.1 does not properly scope its capability mapping, discarding the access ... |
| CVE-2026-18230 | — | — | — | Aug 12, 2026 | The WP Directory Kit WordPress plugin before 1.5.6 does not sanitise and escape a parameter before using it in a SQL sta... |
| CVE-2026-18057 | — | — | — | Aug 12, 2026 | The Events Manager WordPress plugin before 7.4.1 does not sanitise and escape a user-controlled value before using it i... |
| CVE-2026-18049 | — | — | — | Aug 12, 2026 | The WP Photo Album Plus WordPress plugin before 9.2.07.002 does not perform any capability or nonce check on one of its ... |
| CVE-2026-18048 | — | — | — | Aug 12, 2026 | The WP Photo Album Plus WordPress plugin before 9.2.07.002 does not validate a client-controlled value used to build a f... |
| CVE-2026-18046 | — | — | — | Aug 12, 2026 | The Cookie Consent WordPress plugin before 0.0.10 does not correctly enforce its intended administrator-only capability... |
| CVE-2026-18035 | — | — | — | Aug 12, 2026 | The User Access Manager WordPress plugin before 2.3.15 does not apply its access restrictions to REST API requests, allo... |
| CVE-2026-17013 | — | — | — | Aug 12, 2026 | The WP Photo Album Plus WordPress plugin before 9.2.07.002 does not sanitise and escape a parameter before reflecting it... |
| CVE-2026-16977 | — | — | — | Aug 12, 2026 | The Form Maker by 10Web WordPress plugin before 1.15.45 does not properly parameterize a user-controlled value that is ... |
| CVE-2026-16737 | — | — | — | Aug 12, 2026 | The WP Travel Engine WordPress plugin before 6.8.5 does not perform authorization or ownership checks when loading a ca... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now