2026 CVE Vulnerabilities
65,293 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-4344 | HIGH | 7.1 | 0.2% | Apr 14, 2026 | A maliciously crafted HTML payload in a component name, when displayed during the delete confirmation dialog and clicked... |
| CVE-2026-37980 | MEDIUM | 4.8 | 0.2% | Apr 14, 2026 | A flaw was found in Keycloak, specifically in the organization selection login page. A remote attacker with `manage-real... |
| CVE-2026-37602 | LOW | 2.7 | 0.2% | Apr 14, 2026 | SourceCodester Patient Appointment Scheduler System v1.0 is vulnerable to SQL Injection in the file /scheduler/admin/use... |
| CVE-2026-37601 | LOW | 2.7 | 0.2% | Apr 14, 2026 | SourceCodester Patient Appointment Scheduler System v1.0 is vulnerable to SQL Injection in the file /scheduler/admin/app... |
| CVE-2026-37600 | LOW | 2.7 | 0.2% | Apr 14, 2026 | SourceCodester Patient Appointment Scheduler System v1.0 is vulnerable to SQL Injection in the file /scheduler/admin/app... |
| CVE-2026-37598 | LOW | 2.7 | 0.2% | Apr 14, 2026 | SourceCodester Patient Appointment Scheduler System v1.0 is vulnerable to arbitrary code execution (RCE) via /scheduler/... |
| CVE-2026-37597 | LOW | 2.7 | 0.2% | Apr 14, 2026 | SourceCodester Online Employees Work From Home Attendance System v1.0 is vulnerable to SQL Injection in the file /wfh_at... |
| CVE-2026-37596 | LOW | 2.7 | 0.2% | Apr 14, 2026 | SourceCodester Online Employees Work From Home Attendance System v1.0 is vulnerable to SQL Injection in the file /wfh_at... |
| CVE-2026-37595 | LOW | 2.7 | 0.2% | Apr 14, 2026 | SourceCodester Online Employees Work From Home Attendance System v1.0 is vulnerable to SQL Injection in the file /wfh_at... |
| CVE-2026-37594 | LOW | 2.7 | 0.2% | Apr 14, 2026 | SourceCodester Online Employees Work From Home Attendance System v1.0 is vulnerable to SQL Injection in the file /wfh_at... |
| CVE-2026-37593 | LOW | 2.7 | 0.2% | Apr 14, 2026 | SourceCodester Online Employees Work From Home Attendance System v1.0 is vulnerable to SQL Injection in the file /wfh_at... |
| CVE-2026-37592 | LOW | 2.7 | 0.2% | Apr 14, 2026 | Sourcecodester Storage Unit Rental Management System v1.0 is vulnerable to SQL in the file /storage/admin/maintenance/ma... |
| CVE-2026-37591 | LOW | 2.7 | 0.2% | Apr 14, 2026 | Sourcecodester Storage Unit Rental Management System v1.0 is vulnerable to SQL injection in the file /storage/admin/tena... |
| CVE-2026-37590 | LOW | 2.7 | 0.2% | Apr 14, 2026 | SourceCodester Storage Unit Rental Management System v1.0 is vulnerable to SQL Injection in the file /storage/admin/rent... |
| CVE-2026-37589 | LOW | 2.7 | 0.2% | Apr 14, 2026 | SourceCodester Storage Unit Rental Management System v1.0 is vulnerable to SQL Injection in the file /storage/admin/main... |
| CVE-2026-30480 | MEDIUM | 6.5 | 0.3% | Apr 14, 2026 | A Local File Inclusion (LFI) vulnerability in the NFSen module (nfsen.inc.php) of LibreNMS 22.11.0-23-gd091788f2 allows ... |
| CVE-2026-31049 | CRITICAL | 9.8 | 0.7% | Apr 14, 2026 | An issue in Hostbill v.2025-11-24 and 2025-12-01 allows a remote attacker to execute arbitrary code and escalate privile... |
| CVE-2026-5307 | — | — | — | Apr 14, 2026 | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All r... |
| CVE-2026-2450 | HIGH | 7.4 | 0.3% | Apr 14, 2026 | .NET misconfiguration: use of impersonation vulnerability in upKeeper Solutions upKeeper Instant Privilege Access allows... |
| CVE-2026-2449 | CRITICAL | 9 | 0.3% | Apr 14, 2026 | Improper neutralization of argument delimiters in a command ('argument injection') vulnerability in upKeeper Solutions u... |
| CVE-2026-2332 | CRITICAL | 9.1 | 1.3% | Apr 14, 2026 | In Eclipse Jetty, the HTTP/1.1 parser is vulnerable to request smuggling when chunk extensions are used, similar to the ... |
| CVE-2026-24069 | MEDIUM | 5.4 | 0.2% | Apr 14, 2026 | Kiuwan SAST improperly authorizes SSO logins for locally disabled mapped user accounts, allowing disabled users to conti... |
| CVE-2026-4109 | MEDIUM | 4.3 | 0.2% | Apr 14, 2026 | The Eventin – Events Calendar, Event Booking, Ticket & Registration (AI Powered) plugin for WordPress is vulnerable to u... |
| CVE-2026-33929 | MEDIUM | 4.3 | 0.7% | Apr 14, 2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache PDFBox Examples. ... |
| CVE-2026-33892 | HIGH | 7.1 | 0.2% | Apr 14, 2026 | A vulnerability has been identified in Industrial Edge Management Pro V1 (All versions >= V1.7.6 < V1.15.17), Industrial... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now