2026 CVE Vulnerabilities

65,045 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-6573MEDIUM6.3A vulnerability was detected in PHPEMS 11.0. This affects the function temppage of the file /app/exam/controller/exams.m...
CVE-2026-6572MEDIUM5.6A security vulnerability has been detected in Collabora KodExplorer up to 4.52. Affected by this issue is some unknown f...
CVE-2026-6571MEDIUM6.3A weakness has been identified in kodcloud KodExplorer up to 4.52. Affected by this vulnerability is the function roleGr...
CVE-2026-6570LOW2.7A security flaw has been discovered in kodcloud KodExplorer up to 4.52. Affected is the function initInstall of the file...
CVE-2026-6569HIGH7.3A vulnerability was identified in kodcloud KodExplorer up to 4.52. This impacts the function fileGet of the file /app/co...
CVE-2026-6568HIGH7.3A vulnerability was determined in kodcloud KodExplorer up to 4.52. This affects the function share.class.php::initShareO...
CVE-2026-6564MEDIUM4.3A vulnerability was found in EMQ EMQX Enterprise up to 6.1.0. The impacted element is an unknown function of the compone...
CVE-2026-6563HIGH8.8A vulnerability has been found in H3C Magic B1 up to 100R004. The affected element is the function SetAPWifiorLedInfoByI...
CVE-2026-6562HIGH7.3A flaw has been found in dameng100 muucmf 1.9.5.20260309. Impacted is the function getListByPage of the file /index/Sear...
CVE-2026-6561MEDIUM4.7A vulnerability was detected in EyouCMS up to 1.7.1. This issue affects the function edit_adminlogo of the file applicat...
CVE-2026-6560HIGH8.8A security vulnerability has been detected in H3C Magic B0 up to 100R002. This vulnerability affects the function Edit_B...
CVE-2026-6559MEDIUM5.3A weakness has been identified in Wavlink WL-WN579A3 220323. This affects the function sub_401F80 of the file /cgi-bin/l...
CVE-2026-0868MEDIUM6.4The EMC – Easily Embed Calendly Scheduling Features plugin for WordPress is vulnerable to Stored Cross-Site Scripting vi...
CVE-2026-6056——Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-41242CRITICAL9.8protobufjs compiles protobuf definitions into JavaScript (JS) functions. In versions prior to 8.0.1 and 7.5.5, attackers...
CVE-2026-40948MEDIUM5.4The Keycloak authentication manager in `apache-airflow-providers-keycloak` did not generate or validate the OAuth 2.0 `s...
CVE-2026-2986MEDIUM6.4The Contextual Related Posts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'other_attributes...
CVE-2026-2505MEDIUM5.4The Categories Images plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including...
CVE-2026-0894MEDIUM6.4The Content Blocks (Custom Post Widget) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin...
CVE-2026-41254HIGH7.5Little CMS (lcms2) through 2.18 has an integer overflow in CubeSize in cmslut.c because the overflow check is performed ...
CVE-2026-32690LOW3.7Secrets in Variables saved as JSON dictionaries were not properly redacted - in case thee variables were retrieved by th...
CVE-2026-32228HIGH7.5UI / API User with asset materialize permission could trigger dags they had no access to. Users are advised to migrate t...
CVE-2026-30912HIGH7.5In case of SQL errors, exception/stack trace of errors was exposed in API even if "api/expose_stack_traces" was set to f...
CVE-2026-30898HIGH8.8An example of BashOperator in Airflow documentation suggested a way of passing dag_run.conf in the way that could cause ...
CVE-2026-25917HIGH7.2Dag Authors, who normally should not be able to execute code in the webserver context could craft XCom payload causing t...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now