2026 CVE Vulnerabilities

57,083 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-46590HIGH8.8Deserialization of Untrusted Data vulnerability in Apache Camel PQC component. The camel-pqc component persists post-qu...
CVE-2026-46585HIGH7.5Improper Input Validation, Authorization Bypass Through User-Controlled Key vulnerability in Apache Camel Lucene Compone...
CVE-2026-46584LOW3.7Improper Input Validation, Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Camel Mail...
CVE-2026-46457HIGH7.5Improper Input Validation vulnerability in Apache Camel NATS component. The camel-nats component maps inbound NATS mess...
CVE-2026-46456CRITICAL9.8Improper Input Validation vulnerability in Apache Camel AWS2-SQS Component. The camel-aws2-sqs component map inbound m...
CVE-2026-46455CRITICAL9.8Insufficient Session Expiration vulnerability in Apache Camel Keycloak Component. The camel-keycloak security helper Ke...
CVE-2026-46454CRITICAL9.8Improper Input Validation vulnerability in Apache Camel Cometd Component. The camel-cometd component maps inbound Bayeu...
CVE-2026-46453MEDIUM5.3Improper Input Validation, Authorization Bypass Through User-Controlled Key vulnerability in Apache Camel ElasticSearch ...
CVE-2026-44934HIGH7A information disclosure when DEBUG loglevel is set in SUSE Rancher AI Agent 1.0 before 1.0.2 could leak API keys or LLM...
CVE-2026-43867CRITICAL9.8Deserialization of Untrusted Data vulnerability in Apache Camel PQC Component. The camel-pqc component persists post-qu...
CVE-2026-43866HIGH7.3Deserialization of Untrusted Data vulnerability in Apache Camel, Apache Camel JMS component. JmsBinding.extractBodyFrom...
CVE-2026-43865HIGH8.1Deserialization of Untrusted Data vulnerability in Apache Camel Hazelcast component. The camel-hazelcast component crea...
CVE-2026-42527HIGH8.1Deserialization of Untrusted Data vulnerability in Apache Camel. The default ObjectInputFilter pattern shipped with sev...
CVE-2026-40859HIGH8.1Deserialization of Untrusted Data vulnerability in Apache Camel. The camel-vertx-http component deserializes HTTP respo...
CVE-2026-40047CRITICAL9.1Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in Apache Camel Docling...
CVE-2026-24014CRITICAL9.8Apache IoTDB DataNode’s internal RPC interface for creating Trigger instances uses the uploaded Trigger JAR name to buil...
CVE-2026-24013CRITICAL9.1Authentication Bypass by Spoofing vulnerability in Apache IoTDB. Certain Thrift RPC query handlers lack strict validatio...
CVE-2026-24012HIGH7.5Uncontrolled Resource Consumption vulnerability in Apache IoTDB.  Some interface fails to impose reasonable limits on t...
CVE-2026-1433MEDIUM4.8uniFLOW Universal Login Manager (ULM) Standalone contains an information disclosure vulnerability that may allow an auth...
CVE-2026-14809HIGH8.7Prog Management System developed by PROG MIS has a SQL Injection vulnerability, allowing unauthenticated remote attacker...
CVE-2026-6382CRITICAL9.1The FileOrganizer WordPress plugin before 1.1.9, Advanced File Manager WordPress plugin before 5.4.12, File Manager Pr...
CVE-2026-14808CRITICAL9.8Prog Management System developed by PROG MIS has a Exposure of Sensitive Information vulnerability, allowing unauthe...
CVE-2026-14807CRITICAL9.8ERP App developed by PROG MIS has a Use of Hard-coded Credentials vulnerability, allowing unauthenticated remote attacke...
CVE-2026-14802HIGH7.3A vulnerability was detected in react create-react-app up to 5.0.1 on macOS. This affects the function startBrowserProce...
CVE-2026-14801MEDIUM4.8A security vulnerability has been detected in GPAC 26.03-DEV-rev342-g80071f700-master. The impacted element is the funct...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now