2026 CVE Vulnerabilities

57,076 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-11340HIGH8.3Missing Authorization vulnerability in HAVELSAN Inc. Liman MYS allows Accessing Functionality Not Properly Constrained b...
CVE-2026-49487MEDIUM6.5In Apache Airflow before 3.3.0, the REST API task-instance detail and list endpoints returned a deferred task's trigger ...
CVE-2026-49296MEDIUM6.5Before apache-airflow 3.3.0, a user authorized to read one Dag could disclose the source of other Dags co-located in the...
CVE-2026-48892MEDIUM6.5The Config API in Apache Airflow surfaced per-key secrets-backend overrides (environment variables like `AIRFLOW__SECRET...
CVE-2026-48891MEDIUM4.3A bug in Apache Airflow's `/ui/dependencies` scheduling graph endpoint applied the caller's readable-Dag filter to the t...
CVE-2026-48828MEDIUM6.5The Bulk Variables API in Apache Airflow called the redactor without passing the variable's key, so the key-based `shoul...
CVE-2026-33264CRITICAL9.8A bug in `BaseSerialization.deserialize()` allowed unrestricted `import_string()` of attacker-controlled class paths whe...
CVE-2026-14868MEDIUM5.5The encryption algorithm used to protect the configuration of user accounts, stored in the built-in user directory of Pc...
CVE-2026-14867MEDIUM5.5Credentials of built-in users are insecurely stored in the User directory of PcVue projects, all versions prior to 17.0....
CVE-2026-14476HIGH8A path traversal flaw was found in SSSD's AD GPO provider. The ad_gpo_extract_smb_components() function does not sanitiz...
CVE-2026-14474HIGH8.8A flaw was found in SSSD's LDAP sudo provider. When the ldap_sudo_search_base option is not explicitly configured, SSSD ...
CVE-2026-11610HIGH8.8A heap buffer overflow flaw was found in the SASL I/O layer of 389 Directory Server (389-ds-base). After a successful SA...
CVE-2026-58384HIGH7.8A flaw was found in GIMP's PSD parser. An integer overflow in read_RLE_channel() can cause an undersized heap allocation...
CVE-2026-13199MEDIUM5.1EEPROM firmware on Raspberry Pi 5 and Compute Module 5 devices produced non-random KASLR and RNG seed values. This resul...
CVE-2026-8377HIGH8.2Missing Authorization vulnerability in Armiya Information Technologies Ltd. Co. Access Control System (GKS) allows Colle...
CVE-2026-8309MEDIUM5.4Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Armiya Information...
CVE-2026-8306MEDIUM6.1Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Armiya Information...
CVE-2026-7380MEDIUM6.1Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in Armiya Information Techno...
CVE-2026-5799HIGH7.5Authorization bypass through User-Controlled key vulnerability in Idvlabs Software and Consulting Services Inc. Ontime a...
CVE-2026-5730HIGH7.5Authorization bypass through User-Controlled key vulnerability in Idvlabs Software and Consulting Services Inc. Ontime a...
CVE-2026-58315MEDIUM5.1Cross-site request forgery vulnerability exists in SEIKO EPSON Web Config. If a user views a malicious page while logged...
CVE-2026-57871HIGH7.1Relative path traversal vulnerability in MicroRealEstate file upload functionality allows attackers to potentially overw...
CVE-2026-57870MEDIUM5.3Broken object-level access control on the Template API in MicroRealEstate allows attackers to retrieve document template...
CVE-2026-57869HIGH7.1Broken object-level access controls and the use of a deterministic pattern during random ID generation in MicroRealEstat...
CVE-2026-57868HIGH7.1MicroRealEstate is affected by broken object-level access controls in PDF generator functionality. This issue affects M...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now