2026 CVE Vulnerabilities

57,098 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-43866HIGH7.3Deserialization of Untrusted Data vulnerability in Apache Camel, Apache Camel JMS component. JmsBinding.extractBodyFrom...
CVE-2026-43865HIGH8.1Deserialization of Untrusted Data vulnerability in Apache Camel Hazelcast component. The camel-hazelcast component crea...
CVE-2026-42527HIGH8.1Deserialization of Untrusted Data vulnerability in Apache Camel. The default ObjectInputFilter pattern shipped with sev...
CVE-2026-40859HIGH8.1Deserialization of Untrusted Data vulnerability in Apache Camel. The camel-vertx-http component deserializes HTTP respo...
CVE-2026-40047CRITICAL9.1Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in Apache Camel Docling...
CVE-2026-24014CRITICAL9.8Apache IoTDB DataNode’s internal RPC interface for creating Trigger instances uses the uploaded Trigger JAR name to buil...
CVE-2026-24013CRITICAL9.1Authentication Bypass by Spoofing vulnerability in Apache IoTDB. Certain Thrift RPC query handlers lack strict validatio...
CVE-2026-24012HIGH7.5Uncontrolled Resource Consumption vulnerability in Apache IoTDB.  Some interface fails to impose reasonable limits on t...
CVE-2026-1433MEDIUM4.8uniFLOW Universal Login Manager (ULM) Standalone contains an information disclosure vulnerability that may allow an auth...
CVE-2026-14809HIGH8.7Prog Management System developed by PROG MIS has a SQL Injection vulnerability, allowing unauthenticated remote attacker...
CVE-2026-6382CRITICAL9.1The FileOrganizer WordPress plugin before 1.1.9, Advanced File Manager WordPress plugin before 5.4.12, File Manager Pr...
CVE-2026-14808CRITICAL9.8Prog Management System developed by PROG MIS has a Exposure of Sensitive Information vulnerability, allowing unauthe...
CVE-2026-14807CRITICAL9.8ERP App developed by PROG MIS has a Use of Hard-coded Credentials vulnerability, allowing unauthenticated remote attacke...
CVE-2026-14802HIGH7.3A vulnerability was detected in react create-react-app up to 5.0.1 on macOS. This affects the function startBrowserProce...
CVE-2026-14801MEDIUM4.8A security vulnerability has been detected in GPAC 26.03-DEV-rev342-g80071f700-master. The impacted element is the funct...
CVE-2026-14800MEDIUM4.3A weakness has been identified in imhamzaazam ecommerceFlask up to cb7d9e24c30a99379651b7493b32048126ef402b. The affecte...
CVE-2026-12083HIGH8.1The Admin and Site Enhancements (ASE) WordPress plugin before 8.8.4, admin-site-enhancements-pro WordPress plugin before...
CVE-2026-11962HIGH8.8The FileOrganizer WordPress plugin before 1.2.0 does not validate the file type on several of its file-management opera...
CVE-2026-11855HIGH8.8The Simple Membership WordPress plugin before 4.7.5 does not verify the authenticity of Stripe webhook requests when no ...
CVE-2026-11766HIGH8The Ultimate Member WordPress plugin before 2.12.0 does not properly sanitise and escape the value of custom textarea p...
CVE-2026-10830HIGH8.8The AllCoach WordPress plugin before 1.0.2 does not verify that an email address submitted to a public account-registra...
CVE-2026-14799MEDIUM6.3A security flaw has been discovered in CodeAstro Ecommerce Website 1.0. Impacted is an unknown function of the file /cus...
CVE-2026-14798MEDIUM6.3A vulnerability was identified in CodeAstro Apartment Visitor Management System 1.0. This issue affects some unknown pro...
CVE-2026-14797MEDIUM6.3A vulnerability was determined in CodeAstro Apartment Visitor Management System 1.0. This vulnerability affects unknown ...
CVE-2026-14796MEDIUM6.3A vulnerability was found in CodeAstro Apartment Visitor Management System 1.0. This affects an unknown part of the file...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now