2026 CVE Vulnerabilities
61,795 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-42359 | HIGH | 8.8 | 0.5% | Jun 1, 2026 | A bug in Apache Airflow's XCom PATCH endpoint `PATCH /api/v2/xcomEntries/{key}` allowed an authenticated UI/API user wit... |
| CVE-2026-42358 | MEDIUM | 6.5 | 0.3% | Jun 1, 2026 | A bug in Apache Airflow's Variable response masker caused nested-key redaction (triggered by secret-suffixed key names l... |
| CVE-2026-42253 | MEDIUM | 6.1 | 1.1% | Jun 1, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache ActiveMQ, A... |
| CVE-2026-42252 | CRITICAL | 9.1 | 0.4% | Jun 1, 2026 | Apache Airflow's official documentation at `core-concepts/dag-run.html` ("Passing Parameters when triggering Dags") show... |
| CVE-2026-41084 | HIGH | 7.5 | 0.5% | Jun 1, 2026 | A bug in Apache Airflow's bulk Task Instances API (`PATCH/DELETE /api/v2/dags/{dag_id}/dagRuns/{dag_run_id}/taskInstance... |
| CVE-2026-41017 | MEDIUM | 5.9 | 0.3% | Jun 1, 2026 | Apache Airflow's `JWTRefreshMiddleware` set the JWT auth cookie without the `Secure` flag, so deployments running the Ai... |
| CVE-2026-41014 | MEDIUM | 4.3 | 0.4% | Jun 1, 2026 | The partitioned_dag_runs endpoints in the Airflow UI enforced only asset-level access control, not per-Dag authorization... |
| CVE-2026-40963 | LOW | 3.1 | 0.5% | Jun 1, 2026 | The structure_data endpoint in the Airflow UI returned external dependency graph nodes for linked Dags without checking ... |
| CVE-2026-40961 | HIGH | 7.2 | 0.6% | Jun 1, 2026 | A bug in the login redirect route in Apache Airflow allowed authenticated users to craft URLs that bypassed the `is_safe... |
| CVE-2026-40861 | MEDIUM | 6.5 | 0.7% | Jun 1, 2026 | A Dag author could either (a) create a symlink under their task's log directory pointing to an arbitrary file readable b... |
| CVE-2026-40549 | MEDIUM | 5.1 | 0.2% | Jun 1, 2026 | SOPlanning is vulnerable to Cross‑Site Request Forgery (CSRF) in groupe_save create, modify and delete endpoints. An att... |
| CVE-2026-40548 | MEDIUM | 6.4 | 0.3% | Jun 1, 2026 | SOPlanning does not verify uploaded file extension. An authenticated attacker with access to the backup functionality ca... |
| CVE-2026-40547 | MEDIUM | 6.4 | 0.4% | Jun 1, 2026 | SOPlanning is vulnerable to Path Traversal in backup endpoints. Authenticated remote attacker is able to exploit a vuln... |
| CVE-2026-40546 | HIGH | 8.7 | 0.2% | Jun 1, 2026 | SOPlanning is vulnerable to SQL Injection across multiple endpoints and parameters. Attacker with low privileges can inj... |
| CVE-2026-40545 | MEDIUM | 5.1 | 0.4% | Jun 1, 2026 | SOPlanning is vulnerable to Reflected XSS via the taches parameter. An attacker can craft a malicious URL which, when op... |
| CVE-2026-40544 | MEDIUM | 5.1 | 0.3% | Jun 1, 2026 | SOPlanning is vulnerable to Stored Cross-Site Scripting (XSS) via /process/upload_backup endpoint. An authenticated atta... |
| CVE-2026-40543 | HIGH | 8.8 | 0.3% | Jun 1, 2026 | SOPlanning does not enforce authorization for backup functionalities. An unauthenticated attacker can directly query bac... |
| CVE-2026-32325 | HIGH | 8.5 | 0.1% | Jun 1, 2026 | Privilege chaining issue exists in ServerView Agents for Windows V11.60.04 and earlier. If this vulnerability is exploit... |
| CVE-2026-27788 | HIGH | 8.5 | 0.1% | Jun 1, 2026 | Incorrect permission assignment for critical resource issue exists in ServerView Agents for Windows V11.60.04 and earlie... |
| CVE-2026-10517 | — | — | 0.3% | Jun 1, 2026 | Rejected reason: Retracted following review by Red Hat Product Security and confirmation from the upstream Clair/Clairco... |
| CVE-2026-10243 | HIGH | 7.3 | 0.6% | Jun 1, 2026 | A security vulnerability has been detected in code-projects Smart Parking System 1.0. Affected is an unknown function of... |
| CVE-2026-10242 | MEDIUM | 6.3 | 0.3% | Jun 1, 2026 | A weakness has been identified in itsourcecode Content Management System 1.0. This impacts an unknown function of the fi... |
| CVE-2026-10241 | MEDIUM | 6.3 | 0.3% | Jun 1, 2026 | A security flaw has been discovered in jeecgboot The server processes these URLs up to 3.9.1. This affects the function ... |
| CVE-2026-10240 | MEDIUM | 6.3 | 0.3% | Jun 1, 2026 | A vulnerability was identified in JeecgBoot up to 3.9.2. The impacted element is an unknown function of the file /airag/... |
| CVE-2026-10239 | MEDIUM | 6.3 | 0.3% | Jun 1, 2026 | A vulnerability was determined in JeecgBoot up to 3.9.2. The affected element is the function WordUtil.addImage of the f... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now