2026 CVE Vulnerabilities

61,795 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-42359HIGH8.8A bug in Apache Airflow's XCom PATCH endpoint `PATCH /api/v2/xcomEntries/{key}` allowed an authenticated UI/API user wit...
CVE-2026-42358MEDIUM6.5A bug in Apache Airflow's Variable response masker caused nested-key redaction (triggered by secret-suffixed key names l...
CVE-2026-42253MEDIUM6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache ActiveMQ, A...
CVE-2026-42252CRITICAL9.1Apache Airflow's official documentation at `core-concepts/dag-run.html` ("Passing Parameters when triggering Dags") show...
CVE-2026-41084HIGH7.5A bug in Apache Airflow's bulk Task Instances API (`PATCH/DELETE /api/v2/dags/{dag_id}/dagRuns/{dag_run_id}/taskInstance...
CVE-2026-41017MEDIUM5.9Apache Airflow's `JWTRefreshMiddleware` set the JWT auth cookie without the `Secure` flag, so deployments running the Ai...
CVE-2026-41014MEDIUM4.3The partitioned_dag_runs endpoints in the Airflow UI enforced only asset-level access control, not per-Dag authorization...
CVE-2026-40963LOW3.1The structure_data endpoint in the Airflow UI returned external dependency graph nodes for linked Dags without checking ...
CVE-2026-40961HIGH7.2A bug in the login redirect route in Apache Airflow allowed authenticated users to craft URLs that bypassed the `is_safe...
CVE-2026-40861MEDIUM6.5A Dag author could either (a) create a symlink under their task's log directory pointing to an arbitrary file readable b...
CVE-2026-40549MEDIUM5.1SOPlanning is vulnerable to Cross‑Site Request Forgery (CSRF) in groupe_save create, modify and delete endpoints. An att...
CVE-2026-40548MEDIUM6.4SOPlanning does not verify uploaded file extension. An authenticated attacker with access to the backup functionality ca...
CVE-2026-40547MEDIUM6.4SOPlanning is vulnerable to Path Traversal in backup endpoints. Authenticated remote attacker is able to exploit a vuln...
CVE-2026-40546HIGH8.7SOPlanning is vulnerable to SQL Injection across multiple endpoints and parameters. Attacker with low privileges can inj...
CVE-2026-40545MEDIUM5.1SOPlanning is vulnerable to Reflected XSS via the taches parameter. An attacker can craft a malicious URL which, when op...
CVE-2026-40544MEDIUM5.1SOPlanning is vulnerable to Stored Cross-Site Scripting (XSS) via /process/upload_backup endpoint. An authenticated atta...
CVE-2026-40543HIGH8.8SOPlanning does not enforce authorization for backup functionalities. An unauthenticated attacker can directly query bac...
CVE-2026-32325HIGH8.5Privilege chaining issue exists in ServerView Agents for Windows V11.60.04 and earlier. If this vulnerability is exploit...
CVE-2026-27788HIGH8.5Incorrect permission assignment for critical resource issue exists in ServerView Agents for Windows V11.60.04 and earlie...
CVE-2026-10517Rejected reason: Retracted following review by Red Hat Product Security and confirmation from the upstream Clair/Clairco...
CVE-2026-10243HIGH7.3A security vulnerability has been detected in code-projects Smart Parking System 1.0. Affected is an unknown function of...
CVE-2026-10242MEDIUM6.3A weakness has been identified in itsourcecode Content Management System 1.0. This impacts an unknown function of the fi...
CVE-2026-10241MEDIUM6.3A security flaw has been discovered in jeecgboot The server processes these URLs up to 3.9.1. This affects the function ...
CVE-2026-10240MEDIUM6.3A vulnerability was identified in JeecgBoot up to 3.9.2. The impacted element is an unknown function of the file /airag/...
CVE-2026-10239MEDIUM6.3A vulnerability was determined in JeecgBoot up to 3.9.2. The affected element is the function WordUtil.addImage of the f...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now