2026 CVE Vulnerabilities

63,096 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-25599MEDIUM6.3Missing authentication and clear‑text transmission of data from the heat pumps to the control server, combined with the ...
CVE-2026-10250HIGH7.3A security flaw has been discovered in itsourcecode Online Blood Bank Management System 1.0. The affected element is an ...
CVE-2026-10249HIGH7.3A vulnerability was identified in itsourcecode Online Blood Bank Management System 1.0. Impacted is an unknown function ...
CVE-2026-10248MEDIUM4.7A vulnerability was determined in SourceCodester Pharmacy Sales and Inventory System up to 1.0. This issue affects the f...
CVE-2026-10247LOW3.5A vulnerability was found in SourceCodester Pharmacy Sales and Inventory System 1.0. This vulnerability affects the func...
CVE-2026-10246LOW3.5A vulnerability has been found in SourceCodester Pharmacy Sales and Inventory System 1.0. This affects the function crea...
CVE-2026-10245LOW3.5A flaw has been found in SourceCodester Pharmacy Sales and Inventory System 1.0. Affected by this issue is the function ...
CVE-2026-10244LOW3.5A vulnerability was detected in SourceCodester Pharmacy Sales and Inventory System 1.0. Affected by this vulnerability i...
CVE-2026-9024HIGH8.7A Stored Cross-site Scripting (XSS) vulnerability affecting Process Experience Studio in DELMIA Service Process Engineer...
CVE-2026-8474MEDIUM5.3A vulnerability was discovered on Stormshield Network Security  * 4.3.0 to 4.3.41,  * 4.8.0 to 4.8.15,  * ...
CVE-2026-7858CRITICAL9.8A Deserialization of Untrusted Data vulnerability affecting Teamwork Cloud from No Magic Release 2022x through No Magic ...
CVE-2026-49361HIGH7.5Apache Fluss versions prior to 0.9.1 configure the Netty LengthFieldBasedFrameDecoder with Integer.MAX_VALUE as the maxi...
CVE-2026-49298HIGH8.8A bug in Apache Airflow's KubernetesExecutor caused JWT tokens used by worker pods to authenticate against the Execution...
CVE-2026-49270MEDIUM5.9Exposure of Sensitive Information Through Metadata vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ, Apache Acti...
CVE-2026-49267MEDIUM5.9Apache Airflow's EmailOperator and the underlying `airflow.utils.email` helpers established SMTP STARTTLS connections wi...
CVE-2026-49157HIGH8.8Incorrect Default Permissions vulnerability in Apache ActiveMQ. This issue affects Apache ActiveMQ: before 5.19.7, from...
CVE-2026-48827HIGH7.1Path traversal vulnerability in Apache MINA SSHD bundle sshd-git. Lack of path validation in git-upload-pack, git-receiv...
CVE-2026-48726MEDIUM6.5A bug in Apache Airflow's auth manager logout handling left previously-issued JWT tokens valid after the user clicked lo...
CVE-2026-46764MEDIUM4.3The Event Log detail endpoint `GET /api/v2/eventLogs/{event_log_id}` in Apache Airflow fetched audit-log rows directly b...
CVE-2026-46605MEDIUM4.3Incomplete authorization by Apache ActiveMQ server before versions v6.2.6 and v5.19.7 allows authenticated connections t...
CVE-2026-45505HIGH8.8Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ Br...
CVE-2026-45426LOW3.1Exploitation requires the attacker to already be an authenticated Airflow worker holding a valid Log-server JWT issued f...
CVE-2026-45360HIGH7.3Apache Airflow's scheduler-side deadline-reference decoder (`SerializedCustomReference.deserialize_reference`) imported ...
CVE-2026-44825CRITICAL9.8Hardcoded credentials in the Basic Authentication setup tool (bin/solr auth enable) in Apache Solr versions 9.4.0 throug...
CVE-2026-42588HIGH8.1Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ Br...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now