2026 CVE Vulnerabilities
61,927 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-10254 | MEDIUM | 5.5 | 0.3% | Jun 1, 2026 | A flaw has been found in SourceCodester Pet Grooming Management Software 1.0. Affected is an unknown function of the fil... |
| CVE-2026-10253 | HIGH | 7.3 | 0.3% | Jun 1, 2026 | A vulnerability was detected in itsourcecode Online House Rental System 1.0. This impacts an unknown function of the fil... |
| CVE-2026-10252 | HIGH | 7.3 | 0.3% | Jun 1, 2026 | A security vulnerability has been detected in itsourcecode Online House Rental System 1.0. This affects an unknown funct... |
| CVE-2026-10251 | HIGH | 7.3 | 0.3% | Jun 1, 2026 | A weakness has been identified in itsourcecode Online House Rental System 1.0. The impacted element is an unknown functi... |
| CVE-2026-49328 | MEDIUM | 5.3 | 0.5% | Jun 1, 2026 | Server-Side Request Forgery (SSRF) in the UrlImageConverter component of Apache Fesod (Incubating) fesod-sheet before 2.... |
| CVE-2026-25600 | MEDIUM | 6.4 | 0.1% | Jun 1, 2026 | The PDBM application relies on a static, hard‑coded secret embedded in the PDBM.exe executable. This secret is used by ... |
| CVE-2026-25599 | MEDIUM | 6.3 | 0.1% | Jun 1, 2026 | Missing authentication and clear‑text transmission of data from the heat pumps to the control server, combined with the ... |
| CVE-2026-10250 | HIGH | 7.3 | 0.3% | Jun 1, 2026 | A security flaw has been discovered in itsourcecode Online Blood Bank Management System 1.0. The affected element is an ... |
| CVE-2026-10249 | HIGH | 7.3 | 0.3% | Jun 1, 2026 | A vulnerability was identified in itsourcecode Online Blood Bank Management System 1.0. Impacted is an unknown function ... |
| CVE-2026-10248 | MEDIUM | 4.7 | 0.2% | Jun 1, 2026 | A vulnerability was determined in SourceCodester Pharmacy Sales and Inventory System up to 1.0. This issue affects the f... |
| CVE-2026-10247 | LOW | 3.5 | 0.2% | Jun 1, 2026 | A vulnerability was found in SourceCodester Pharmacy Sales and Inventory System 1.0. This vulnerability affects the func... |
| CVE-2026-10246 | LOW | 3.5 | 0.2% | Jun 1, 2026 | A vulnerability has been found in SourceCodester Pharmacy Sales and Inventory System 1.0. This affects the function crea... |
| CVE-2026-10245 | LOW | 3.5 | 0.2% | Jun 1, 2026 | A flaw has been found in SourceCodester Pharmacy Sales and Inventory System 1.0. Affected by this issue is the function ... |
| CVE-2026-10244 | LOW | 3.5 | 0.2% | Jun 1, 2026 | A vulnerability was detected in SourceCodester Pharmacy Sales and Inventory System 1.0. Affected by this vulnerability i... |
| CVE-2026-9024 | HIGH | 8.7 | 0.2% | Jun 1, 2026 | A Stored Cross-site Scripting (XSS) vulnerability affecting Process Experience Studio in DELMIA Service Process Engineer... |
| CVE-2026-8474 | MEDIUM | 5.3 | 0.2% | Jun 1, 2026 | A vulnerability was discovered on Stormshield Network Security * 4.3.0 to 4.3.41, * 4.8.0 to 4.8.15, * ... |
| CVE-2026-7858 | CRITICAL | 9.8 | 0.5% | Jun 1, 2026 | A Deserialization of Untrusted Data vulnerability affecting Teamwork Cloud from No Magic Release 2022x through No Magic ... |
| CVE-2026-49361 | HIGH | 7.5 | 0.6% | Jun 1, 2026 | Apache Fluss versions prior to 0.9.1 configure the Netty LengthFieldBasedFrameDecoder with Integer.MAX_VALUE as the maxi... |
| CVE-2026-49298 | HIGH | 8.8 | 0.5% | Jun 1, 2026 | A bug in Apache Airflow's KubernetesExecutor caused JWT tokens used by worker pods to authenticate against the Execution... |
| CVE-2026-49270 | MEDIUM | 5.9 | 0.3% | Jun 1, 2026 | Exposure of Sensitive Information Through Metadata vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ, Apache Acti... |
| CVE-2026-49267 | MEDIUM | 5.9 | 0.2% | Jun 1, 2026 | Apache Airflow's EmailOperator and the underlying `airflow.utils.email` helpers established SMTP STARTTLS connections wi... |
| CVE-2026-49157 | HIGH | 8.8 | 0.4% | Jun 1, 2026 | Incorrect Default Permissions vulnerability in Apache ActiveMQ. This issue affects Apache ActiveMQ: before 5.19.7, from... |
| CVE-2026-48827 | HIGH | 7.1 | 0.5% | Jun 1, 2026 | Path traversal vulnerability in Apache MINA SSHD bundle sshd-git. Lack of path validation in git-upload-pack, git-receiv... |
| CVE-2026-48726 | MEDIUM | 6.5 | 0.4% | Jun 1, 2026 | A bug in Apache Airflow's auth manager logout handling left previously-issued JWT tokens valid after the user clicked lo... |
| CVE-2026-46764 | MEDIUM | 4.3 | 0.4% | Jun 1, 2026 | The Event Log detail endpoint `GET /api/v2/eventLogs/{event_log_id}` in Apache Airflow fetched audit-log rows directly b... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now