2026 CVE Vulnerabilities
65,293 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-6188 | HIGH | 7.3 | 0.3% | Apr 13, 2026 | A flaw has been found in SourceCodester Pharmacy Sales and Inventory System 1.0. Impacted is an unknown function of the ... |
| CVE-2026-6187 | HIGH | 7.3 | 0.3% | Apr 13, 2026 | A vulnerability was detected in SourceCodester Pharmacy Sales and Inventory System 1.0. This issue affects some unknown ... |
| CVE-2026-6186 | HIGH | 8.8 | 0.6% | Apr 13, 2026 | A security vulnerability has been detected in UTT HiPER 1200GW up to 2.5.3-170306. This vulnerability affects the functi... |
| CVE-2026-6184 | LOW | 2.4 | 0.3% | Apr 13, 2026 | A weakness has been identified in code-projects Simple Content Management System 1.0. This affects an unknown part of th... |
| CVE-2026-36938 | LOW | 2.7 | 0.2% | Apr 13, 2026 | Sourcecodester Online Resort Management System v1.0 is vulnerable to SQL injection in /orms/admin/rooms/view_room.php. |
| CVE-2026-36937 | LOW | 2.7 | 0.2% | Apr 13, 2026 | Sourcecodester Online Resort Management System v1.0 is vulnerable to SQL injection in /orms/admin/reservations/view_deta... |
| CVE-2026-34188 | HIGH | 7.2 | 1.1% | Apr 13, 2026 | Improper Neutralization of Special Elements used in an OS Command vulnerability allows OS Command Injection via Event Re... |
| CVE-2026-34186 | HIGH | 8.8 | 0.2% | Apr 13, 2026 | Improper Neutralization of Special Elements used in an SQL Command vulnerability allows SQL Injection via custom fields.... |
| CVE-2026-30813 | HIGH | 8.8 | 0.3% | Apr 13, 2026 | Improper Neutralization of Special Elements used in an SQL Command vulnerability allows SQL Injection via module search.... |
| CVE-2026-30812 | MEDIUM | 5.4 | 0.2% | Apr 13, 2026 | Improper Neutralization of Input During Web Page Generation vulnerability allows Stored Cross-Site Scripting via event c... |
| CVE-2026-30811 | MEDIUM | 6.5 | 0.3% | Apr 13, 2026 | Missing Authorization vulnerability allows Exposure of Sensitive Information via configuration endpoint. This issue affe... |
| CVE-2026-30809 | HIGH | 8.8 | 0.9% | Apr 13, 2026 | Improper Neutralization of Special Elements used in an OS Command vulnerability allows OS Command Injection via WebServe... |
| CVE-2026-30806 | HIGH | 8.8 | 0.9% | Apr 13, 2026 | Improper Neutralization of Special Elements used in an OS Command vulnerability allows OS Command Injection via Network ... |
| CVE-2026-30804 | HIGH | 7.2 | 0.4% | Apr 13, 2026 | Unrestricted Upload of File with Dangerous Type vulnerability allows Remote Code Execution via file upload. This issue a... |
| CVE-2026-6183 | HIGH | 7.3 | 0.3% | Apr 13, 2026 | A security flaw has been discovered in code-projects Simple Content Management System 1.0. Affected by this issue is som... |
| CVE-2026-6182 | HIGH | 7.3 | 0.3% | Apr 13, 2026 | A vulnerability was identified in code-projects Simple Content Management System 1.0. Affected by this vulnerability is ... |
| CVE-2026-36945 | LOW | 2.7 | 0.2% | Apr 13, 2026 | Sourcecodester Computer and Mobile Repair Shop Management System v1.0 is vulnerable to SQL injection in the file /rsms/a... |
| CVE-2026-36944 | LOW | 2.7 | 0.2% | Apr 13, 2026 | Sourcecodester Computer and Mobile Repair Shop Management System v1.0 is vulnerale to SQL injection in the file/rsms/adm... |
| CVE-2026-36943 | LOW | 2.7 | 0.2% | Apr 13, 2026 | Sourcecodester Computer and Mobile Repair Shop Management System v1.0 is vulnerable to SQL injection in the file /rsms/a... |
| CVE-2026-36942 | LOW | 2.7 | 0.2% | Apr 13, 2026 | Sourcecodester Online Resort Management System v1.0 is vulnerable to SQL injection in the file /orms/admin/activities/ma... |
| CVE-2026-36941 | LOW | 2.7 | 0.2% | Apr 13, 2026 | Sourcecodester Online Resort Management System v1.0 is vulnerable to SQL Injection in the file /orms/admin/rooms/manage_... |
| CVE-2026-33858 | HIGH | 8.8 | 0.6% | Apr 13, 2026 | Dag Authors, who normally should not be able to execute code in the webserver context could craft XCom payload causing t... |
| CVE-2026-31283 | CRITICAL | 9.8 | 0.4% | Apr 13, 2026 | In Totara LMS v19.1.5 and before, the forgot password API does not implement rate limiting for the target email address.... |
| CVE-2026-31282 | CRITICAL | 9.8 | 0.4% | Apr 13, 2026 | Totara LMS v19.1.5 and before is vulnerable to Incorrect Access Control. The login page code can be manipulated to revea... |
| CVE-2026-31281 | HIGH | 8 | 0.3% | Apr 13, 2026 | Totara LMS v19.1.5 and before is vulnerable to HTML Injection. An attacker can inject malicious HTML code in a message a... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now