2026 CVE Vulnerabilities

62,897 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-42588HIGH8.1Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ Br...
CVE-2026-42360MEDIUM6.5A bug in Apache Airflow's rendered-template field handling caused nested sensitive-key masking (e.g. nested `password` /...
CVE-2026-42359HIGH8.8A bug in Apache Airflow's XCom PATCH endpoint `PATCH /api/v2/xcomEntries/{key}` allowed an authenticated UI/API user wit...
CVE-2026-42358MEDIUM6.5A bug in Apache Airflow's Variable response masker caused nested-key redaction (triggered by secret-suffixed key names l...
CVE-2026-42253MEDIUM6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache ActiveMQ, A...
CVE-2026-42252CRITICAL9.1Apache Airflow's official documentation at `core-concepts/dag-run.html` ("Passing Parameters when triggering Dags") show...
CVE-2026-41084HIGH7.5A bug in Apache Airflow's bulk Task Instances API (`PATCH/DELETE /api/v2/dags/{dag_id}/dagRuns/{dag_run_id}/taskInstance...
CVE-2026-41017MEDIUM5.9Apache Airflow's `JWTRefreshMiddleware` set the JWT auth cookie without the `Secure` flag, so deployments running the Ai...
CVE-2026-41014MEDIUM4.3The partitioned_dag_runs endpoints in the Airflow UI enforced only asset-level access control, not per-Dag authorization...
CVE-2026-40963LOW3.1The structure_data endpoint in the Airflow UI returned external dependency graph nodes for linked Dags without checking ...
CVE-2026-40961HIGH7.2A bug in the login redirect route in Apache Airflow allowed authenticated users to craft URLs that bypassed the `is_safe...
CVE-2026-40861MEDIUM6.5A Dag author could either (a) create a symlink under their task's log directory pointing to an arbitrary file readable b...
CVE-2026-40549MEDIUM5.1SOPlanning is vulnerable to Cross‑Site Request Forgery (CSRF) in groupe_save create, modify and delete endpoints. An att...
CVE-2026-40548MEDIUM6.4SOPlanning does not verify uploaded file extension. An authenticated attacker with access to the backup functionality ca...
CVE-2026-40547MEDIUM6.4SOPlanning is vulnerable to Path Traversal in backup endpoints. Authenticated remote attacker is able to exploit a vuln...
CVE-2026-40546HIGH8.7SOPlanning is vulnerable to SQL Injection across multiple endpoints and parameters. Attacker with low privileges can inj...
CVE-2026-40545MEDIUM5.1SOPlanning is vulnerable to Reflected XSS via the taches parameter. An attacker can craft a malicious URL which, when op...
CVE-2026-40544MEDIUM5.1SOPlanning is vulnerable to Stored Cross-Site Scripting (XSS) via /process/upload_backup endpoint. An authenticated atta...
CVE-2026-40543HIGH8.8SOPlanning does not enforce authorization for backup functionalities. An unauthenticated attacker can directly query bac...
CVE-2026-32325HIGH8.5Privilege chaining issue exists in ServerView Agents for Windows V11.60.04 and earlier. If this vulnerability is exploit...
CVE-2026-27788HIGH8.5Incorrect permission assignment for critical resource issue exists in ServerView Agents for Windows V11.60.04 and earlie...
CVE-2026-10517Rejected reason: Retracted following review by Red Hat Product Security and confirmation from the upstream Clair/Clairco...
CVE-2026-10243HIGH7.3A security vulnerability has been detected in code-projects Smart Parking System 1.0. Affected is an unknown function of...
CVE-2026-10242MEDIUM6.3A weakness has been identified in itsourcecode Content Management System 1.0. This impacts an unknown function of the fi...
CVE-2026-10241MEDIUM6.3A security flaw has been discovered in jeecgboot The server processes these URLs up to 3.9.1. This affects the function ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now