2026 CVE Vulnerabilities

65,293 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-4344HIGH7.1A maliciously crafted HTML payload in a component name, when displayed during the delete confirmation dialog and clicked...
CVE-2026-37980MEDIUM4.8A flaw was found in Keycloak, specifically in the organization selection login page. A remote attacker with `manage-real...
CVE-2026-37602LOW2.7SourceCodester Patient Appointment Scheduler System v1.0 is vulnerable to SQL Injection in the file /scheduler/admin/use...
CVE-2026-37601LOW2.7SourceCodester Patient Appointment Scheduler System v1.0 is vulnerable to SQL Injection in the file /scheduler/admin/app...
CVE-2026-37600LOW2.7SourceCodester Patient Appointment Scheduler System v1.0 is vulnerable to SQL Injection in the file /scheduler/admin/app...
CVE-2026-37598LOW2.7SourceCodester Patient Appointment Scheduler System v1.0 is vulnerable to arbitrary code execution (RCE) via /scheduler/...
CVE-2026-37597LOW2.7SourceCodester Online Employees Work From Home Attendance System v1.0 is vulnerable to SQL Injection in the file /wfh_at...
CVE-2026-37596LOW2.7SourceCodester Online Employees Work From Home Attendance System v1.0 is vulnerable to SQL Injection in the file /wfh_at...
CVE-2026-37595LOW2.7SourceCodester Online Employees Work From Home Attendance System v1.0 is vulnerable to SQL Injection in the file /wfh_at...
CVE-2026-37594LOW2.7SourceCodester Online Employees Work From Home Attendance System v1.0 is vulnerable to SQL Injection in the file /wfh_at...
CVE-2026-37593LOW2.7SourceCodester Online Employees Work From Home Attendance System v1.0 is vulnerable to SQL Injection in the file /wfh_at...
CVE-2026-37592LOW2.7Sourcecodester Storage Unit Rental Management System v1.0 is vulnerable to SQL in the file /storage/admin/maintenance/ma...
CVE-2026-37591LOW2.7Sourcecodester Storage Unit Rental Management System v1.0 is vulnerable to SQL injection in the file /storage/admin/tena...
CVE-2026-37590LOW2.7SourceCodester Storage Unit Rental Management System v1.0 is vulnerable to SQL Injection in the file /storage/admin/rent...
CVE-2026-37589LOW2.7SourceCodester Storage Unit Rental Management System v1.0 is vulnerable to SQL Injection in the file /storage/admin/main...
CVE-2026-30480MEDIUM6.5A Local File Inclusion (LFI) vulnerability in the NFSen module (nfsen.inc.php) of LibreNMS 22.11.0-23-gd091788f2 allows ...
CVE-2026-31049CRITICAL9.8An issue in Hostbill v.2025-11-24 and 2025-12-01 allows a remote attacker to execute arbitrary code and escalate privile...
CVE-2026-5307——Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All r...
CVE-2026-2450HIGH7.4.NET misconfiguration: use of impersonation vulnerability in upKeeper Solutions upKeeper Instant Privilege Access allows...
CVE-2026-2449CRITICAL9Improper neutralization of argument delimiters in a command ('argument injection') vulnerability in upKeeper Solutions u...
CVE-2026-2332CRITICAL9.1In Eclipse Jetty, the HTTP/1.1 parser is vulnerable to request smuggling when chunk extensions are used, similar to the ...
CVE-2026-24069MEDIUM5.4Kiuwan SAST improperly authorizes SSO logins for locally disabled mapped user accounts, allowing disabled users to conti...
CVE-2026-4109MEDIUM4.3The Eventin – Events Calendar, Event Booking, Ticket & Registration (AI Powered) plugin for WordPress is vulnerable to u...
CVE-2026-33929MEDIUM4.3Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache PDFBox Examples. ...
CVE-2026-33892HIGH7.1A vulnerability has been identified in Industrial Edge Management Pro V1 (All versions >= V1.7.6 < V1.15.17), Industrial...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now