2026 CVE Vulnerabilities

64,922 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-7134MEDIUM4.7A vulnerability was identified in code-projects Online Lot Reservation System 1.0. Affected is an unknown function of th...
CVE-2026-6970HIGH7.3authd prior to version 0.6.4 contains a logic error in primary group ID assignment that can lead to local privilege esca...
CVE-2026-41467MEDIUM5.4ProjeQtor versions 7.0 through 12.4.3 contain a stored cross-site scripting vulnerability in the file upload functionali...
CVE-2026-41466MEDIUM5.4ProjeQtor versions 7.0 through 12.4.3 contain a stored cross-site scripting vulnerability in the checkValidHtmlText() fu...
CVE-2026-41465HIGH7.1ProjeQtor versions 7.0 through 12.4.3 contain a path traversal vulnerability in the log file viewer at dynamicDialog.php...
CVE-2026-41464HIGH7.1ProjeQtor versions 7.0 through 12.4.3 contain a missing authorization vulnerability in the objectDetail.php endpoint tha...
CVE-2026-41463HIGH8.8ProjeQtor versions 7.0 through 12.4.3 contain a ZipSlip path traversal vulnerability in the plugin upload functionality ...
CVE-2026-41462CRITICAL9.8ProjeQtor versions 7.0 through 12.4.3 contain an unauthenticated SQL injection vulnerability in the login functionality ...
CVE-2026-30352CRITICAL9.8A remote code execution (RCE) vulnerability in the /devserver/start endpoint of leonvanzyl autocoder commit 79d02a allow...
CVE-2026-30351HIGH7.5A path traversal vulnerability in the UI/static component of leonvanzyl autocoder commit 79d02a allows attackers to read...
CVE-2026-7133MEDIUM4.7A vulnerability was determined in code-projects Online Lot Reservation System 1.0. This impacts an unknown function of t...
CVE-2026-7132MEDIUM5.5A vulnerability was found in code-projects Online Lot Reservation System up to 1.0. This affects the function readfile o...
CVE-2026-7131HIGH7.3A vulnerability has been found in code-projects Online Lot Reservation System up to 1.0. The impacted element is an unkn...
CVE-2026-6357MEDIUM5.3pip prior to version 26.1 would run self-update check functionality after installing wheel files which required importin...
CVE-2026-6337——Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All r...
CVE-2026-40514CRITICAL9.1SmarterTools SmarterMail builds prior to 9610 contain a cryptographic weakness in the file and email sharing endpoints t...
CVE-2026-30350HIGH7.5An issue in the /store/items/search endpoint of Agent Protocol server commit e9a89f allows attackers to cause a Denial o...
CVE-2026-7130HIGH7.3A flaw has been found in SourceCodester Pharmacy Sales and Inventory System 1.0. The affected element is an unknown func...
CVE-2026-7129MEDIUM4.3A vulnerability was detected in SourceCodester Pharmacy Sales and Inventory System 1.0. Impacted is an unknown function ...
CVE-2026-7128HIGH7.3A security vulnerability has been detected in SourceCodester Pharmacy Sales and Inventory System 1.0. This issue affects...
CVE-2026-7127HIGH7.3A weakness has been identified in SourceCodester Pharmacy Sales and Inventory System 1.0. This vulnerability affects unk...
CVE-2026-7126HIGH7.3A security flaw has been discovered in SourceCodester Pharmacy Sales and Inventory System 1.0. This affects an unknown p...
CVE-2026-6265HIGH8.8Insecure preserved inherited permissions vulnerability in Cerberus FTP Server on Windows allows Privilege Escalation.Thi...
CVE-2026-41081MEDIUM6.5Improper Handling of TLS Client Authentication Failure Leading to Anonymous Principal Assignment in Apache Storm Versio...
CVE-2026-40557MEDIUM4.8Improper Certificate Validation via Global SSL Context Downgrade in Apache Storm Prometheus Reporter Versions Affected...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now