2026 CVE Vulnerabilities
64,922 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-7134 | MEDIUM | 4.7 | 0.2% | Apr 27, 2026 | A vulnerability was identified in code-projects Online Lot Reservation System 1.0. Affected is an unknown function of th... |
| CVE-2026-6970 | HIGH | 7.3 | 0.1% | Apr 27, 2026 | authd prior to version 0.6.4 contains a logic error in primary group ID assignment that can lead to local privilege esca... |
| CVE-2026-41467 | MEDIUM | 5.4 | 0.2% | Apr 27, 2026 | ProjeQtor versions 7.0 through 12.4.3 contain a stored cross-site scripting vulnerability in the file upload functionali... |
| CVE-2026-41466 | MEDIUM | 5.4 | 0.2% | Apr 27, 2026 | ProjeQtor versions 7.0 through 12.4.3 contain a stored cross-site scripting vulnerability in the checkValidHtmlText() fu... |
| CVE-2026-41465 | HIGH | 7.1 | 0.5% | Apr 27, 2026 | ProjeQtor versions 7.0 through 12.4.3 contain a path traversal vulnerability in the log file viewer at dynamicDialog.php... |
| CVE-2026-41464 | HIGH | 7.1 | 0.3% | Apr 27, 2026 | ProjeQtor versions 7.0 through 12.4.3 contain a missing authorization vulnerability in the objectDetail.php endpoint tha... |
| CVE-2026-41463 | HIGH | 8.8 | 1.1% | Apr 27, 2026 | ProjeQtor versions 7.0 through 12.4.3 contain a ZipSlip path traversal vulnerability in the plugin upload functionality ... |
| CVE-2026-41462 | CRITICAL | 9.8 | 0.6% | Apr 27, 2026 | ProjeQtor versions 7.0 through 12.4.3 contain an unauthenticated SQL injection vulnerability in the login functionality ... |
| CVE-2026-30352 | CRITICAL | 9.8 | 0.6% | Apr 27, 2026 | A remote code execution (RCE) vulnerability in the /devserver/start endpoint of leonvanzyl autocoder commit 79d02a allow... |
| CVE-2026-30351 | HIGH | 7.5 | 0.4% | Apr 27, 2026 | A path traversal vulnerability in the UI/static component of leonvanzyl autocoder commit 79d02a allows attackers to read... |
| CVE-2026-7133 | MEDIUM | 4.7 | 0.2% | Apr 27, 2026 | A vulnerability was determined in code-projects Online Lot Reservation System 1.0. This impacts an unknown function of t... |
| CVE-2026-7132 | MEDIUM | 5.5 | 0.4% | Apr 27, 2026 | A vulnerability was found in code-projects Online Lot Reservation System up to 1.0. This affects the function readfile o... |
| CVE-2026-7131 | HIGH | 7.3 | 0.3% | Apr 27, 2026 | A vulnerability has been found in code-projects Online Lot Reservation System up to 1.0. The impacted element is an unkn... |
| CVE-2026-6357 | MEDIUM | 5.3 | 0.1% | Apr 27, 2026 | pip prior to version 26.1 would run self-update check functionality after installing wheel files which required importin... |
| CVE-2026-6337 | — | — | — | Apr 27, 2026 | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All r... |
| CVE-2026-40514 | CRITICAL | 9.1 | 0.2% | Apr 27, 2026 | SmarterTools SmarterMail builds prior to 9610 contain a cryptographic weakness in the file and email sharing endpoints t... |
| CVE-2026-30350 | HIGH | 7.5 | 0.4% | Apr 27, 2026 | An issue in the /store/items/search endpoint of Agent Protocol server commit e9a89f allows attackers to cause a Denial o... |
| CVE-2026-7130 | HIGH | 7.3 | 0.3% | Apr 27, 2026 | A flaw has been found in SourceCodester Pharmacy Sales and Inventory System 1.0. The affected element is an unknown func... |
| CVE-2026-7129 | MEDIUM | 4.3 | 0.3% | Apr 27, 2026 | A vulnerability was detected in SourceCodester Pharmacy Sales and Inventory System 1.0. Impacted is an unknown function ... |
| CVE-2026-7128 | HIGH | 7.3 | 0.3% | Apr 27, 2026 | A security vulnerability has been detected in SourceCodester Pharmacy Sales and Inventory System 1.0. This issue affects... |
| CVE-2026-7127 | HIGH | 7.3 | 0.3% | Apr 27, 2026 | A weakness has been identified in SourceCodester Pharmacy Sales and Inventory System 1.0. This vulnerability affects unk... |
| CVE-2026-7126 | HIGH | 7.3 | 0.3% | Apr 27, 2026 | A security flaw has been discovered in SourceCodester Pharmacy Sales and Inventory System 1.0. This affects an unknown p... |
| CVE-2026-6265 | HIGH | 8.8 | 0.3% | Apr 27, 2026 | Insecure preserved inherited permissions vulnerability in Cerberus FTP Server on Windows allows Privilege Escalation.Thi... |
| CVE-2026-41081 | MEDIUM | 6.5 | 0.3% | Apr 27, 2026 | Improper Handling of TLS Client Authentication Failure Leading to Anonymous Principal Assignment in Apache Storm Versio... |
| CVE-2026-40557 | MEDIUM | 4.8 | 0.2% | Apr 27, 2026 | Improper Certificate Validation via Global SSL Context Downgrade in Apache Storm Prometheus Reporter Versions Affected... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now