2026 CVE Vulnerabilities

65,293 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-6188HIGH7.3A flaw has been found in SourceCodester Pharmacy Sales and Inventory System 1.0. Impacted is an unknown function of the ...
CVE-2026-6187HIGH7.3A vulnerability was detected in SourceCodester Pharmacy Sales and Inventory System 1.0. This issue affects some unknown ...
CVE-2026-6186HIGH8.8A security vulnerability has been detected in UTT HiPER 1200GW up to 2.5.3-170306. This vulnerability affects the functi...
CVE-2026-6184LOW2.4A weakness has been identified in code-projects Simple Content Management System 1.0. This affects an unknown part of th...
CVE-2026-36938LOW2.7Sourcecodester Online Resort Management System v1.0 is vulnerable to SQL injection in /orms/admin/rooms/view_room.php.
CVE-2026-36937LOW2.7Sourcecodester Online Resort Management System v1.0 is vulnerable to SQL injection in /orms/admin/reservations/view_deta...
CVE-2026-34188HIGH7.2Improper Neutralization of Special Elements used in an OS Command vulnerability allows OS Command Injection via Event Re...
CVE-2026-34186HIGH8.8Improper Neutralization of Special Elements used in an SQL Command vulnerability allows SQL Injection via custom fields....
CVE-2026-30813HIGH8.8Improper Neutralization of Special Elements used in an SQL Command vulnerability allows SQL Injection via module search....
CVE-2026-30812MEDIUM5.4Improper Neutralization of Input During Web Page Generation vulnerability allows Stored Cross-Site Scripting via event c...
CVE-2026-30811MEDIUM6.5Missing Authorization vulnerability allows Exposure of Sensitive Information via configuration endpoint. This issue affe...
CVE-2026-30809HIGH8.8Improper Neutralization of Special Elements used in an OS Command vulnerability allows OS Command Injection via WebServe...
CVE-2026-30806HIGH8.8Improper Neutralization of Special Elements used in an OS Command vulnerability allows OS Command Injection via Network ...
CVE-2026-30804HIGH7.2Unrestricted Upload of File with Dangerous Type vulnerability allows Remote Code Execution via file upload. This issue a...
CVE-2026-6183HIGH7.3A security flaw has been discovered in code-projects Simple Content Management System 1.0. Affected by this issue is som...
CVE-2026-6182HIGH7.3A vulnerability was identified in code-projects Simple Content Management System 1.0. Affected by this vulnerability is ...
CVE-2026-36945LOW2.7Sourcecodester Computer and Mobile Repair Shop Management System v1.0 is vulnerable to SQL injection in the file /rsms/a...
CVE-2026-36944LOW2.7Sourcecodester Computer and Mobile Repair Shop Management System v1.0 is vulnerale to SQL injection in the file/rsms/adm...
CVE-2026-36943LOW2.7Sourcecodester Computer and Mobile Repair Shop Management System v1.0 is vulnerable to SQL injection in the file /rsms/a...
CVE-2026-36942LOW2.7Sourcecodester Online Resort Management System v1.0 is vulnerable to SQL injection in the file /orms/admin/activities/ma...
CVE-2026-36941LOW2.7Sourcecodester Online Resort Management System v1.0 is vulnerable to SQL Injection in the file /orms/admin/rooms/manage_...
CVE-2026-33858HIGH8.8Dag Authors, who normally should not be able to execute code in the webserver context could craft XCom payload causing t...
CVE-2026-31283CRITICAL9.8In Totara LMS v19.1.5 and before, the forgot password API does not implement rate limiting for the target email address....
CVE-2026-31282CRITICAL9.8Totara LMS v19.1.5 and before is vulnerable to Incorrect Access Control. The login page code can be manipulated to revea...
CVE-2026-31281HIGH8Totara LMS v19.1.5 and before is vulnerable to HTML Injection. An attacker can inject malicious HTML code in a message a...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now