2026 CVE Vulnerabilities

61,772 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-10624MEDIUM4.3A vulnerability has been found in SourceCodester Human Resource Management 1.0. Affected by this vulnerability is an unk...
CVE-2026-10620HIGH7.3A flaw has been found in code-projects Student Admission System 1.0. Affected is an unknown function of the file /index....
CVE-2026-10619HIGH7.3A vulnerability was detected in sayan365 student-management-system up to 7f3c9ce7d410332335c2affac93a385485051800. This ...
CVE-2026-8036HIGH7.8Improper input validation in NI-PAL may allow a local authenticated user to access arbitrary system memory, potentially ...
CVE-2026-8035MEDIUM5.5Improper input validation in the NI-PAL kernel driver may allow a local authenticated user to cause a denial of service ...
CVE-2026-5385HIGH8.4An unauthenticated user with write access to the knowledge base can store an XSS payload in a knowledge base item. Thi...
CVE-2026-5076CRITICAL9.8The ARMember Premium plugin for WordPress is vulnerable to an insecure password reset mechanism in all versions up to, a...
CVE-2026-5074MEDIUM6.5The ARMember Premium plugin for WordPress is vulnerable to SQL Injection via the 'sSortDir_0' parameter of the `get_priv...
CVE-2026-5073HIGH7.5The ARMember Premium plugin for WordPress is vulnerable to SQL Injection via the 'order' parameter of the 'arm_directory...
CVE-2026-49120HIGH8.5Medplum before 5.1.14 contains a server-side request forgery vulnerability in the subscription worker that allows authen...
CVE-2026-48682MEDIUM5.9FastNetMon Community Edition through 1.2.9 contains an out-of-bounds read in the IPv4 packet parser. In src/simple_packe...
CVE-2026-48598LOW3.7Improper Encoding or Escaping of Output vulnerability in elixir-tesla tesla allows multipart part header injection via u...
CVE-2026-48597MEDIUM5.9Allocation of Resources Without Limits or Throttling vulnerability in elixir-tesla tesla allows denial of service via at...
CVE-2026-48596LOW3.7Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Request/Response Splitting') vulnerability in elixir-te...
CVE-2026-48595MEDIUM5.9Improper Handling of Case Sensitivity vulnerability in elixir-tesla tesla allows credential leakage to a third-party ori...
CVE-2026-48594HIGH7.5Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in elixir-tesla tesla allows a denial of ...
CVE-2026-47265HIGH7.5AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.14.0, cookies set wit...
CVE-2026-42342HIGH7.5React Router is a router for React. In versions 7.0.0 through 7.14.x of react-router and versions 2.10.0 through 2.17.4 ...
CVE-2026-42211HIGH8.1React Router is a router for React. In versions 7.0.0 through 7.14.1, when using Framework Mode, a combination of steps ...
CVE-2026-41577HIGH7.5authentik is an open-source identity provider. Prior to versions 2025.12.5 and 2026.2.3, the SAML source response proces...
CVE-2026-40181MEDIUM6.1React Router is a router for React. In versions 7.0.0 through 7.14.0 and 6.7.0 through 6.30.3, certain URLs passed to th...
CVE-2026-38967CRITICAL9.8CrowCpp Crow through v1.3.1 HTTP is vulnerable to response header injection via unvalidated response header values.
CVE-2026-35202LOW2.3Pterodactyl is a free, open-source game server management panel. Prior to version 1.12.3, the Pterodactyl Client API has...
CVE-2026-35049MEDIUM6.5wire-ios is an iOS client for the Wire secure messaging application. Prior to version 4.16.0, upon receiving a crafted m...
CVE-2026-34993HIGH7.3AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.14.0, using ``CookieJ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now