2026 CVE Vulnerabilities

65,328 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-6182HIGH7.3A vulnerability was identified in code-projects Simple Content Management System 1.0. Affected by this vulnerability is ...
CVE-2026-36945LOW2.7Sourcecodester Computer and Mobile Repair Shop Management System v1.0 is vulnerable to SQL injection in the file /rsms/a...
CVE-2026-36944LOW2.7Sourcecodester Computer and Mobile Repair Shop Management System v1.0 is vulnerale to SQL injection in the file/rsms/adm...
CVE-2026-36943LOW2.7Sourcecodester Computer and Mobile Repair Shop Management System v1.0 is vulnerable to SQL injection in the file /rsms/a...
CVE-2026-36942LOW2.7Sourcecodester Online Resort Management System v1.0 is vulnerable to SQL injection in the file /orms/admin/activities/ma...
CVE-2026-36941LOW2.7Sourcecodester Online Resort Management System v1.0 is vulnerable to SQL Injection in the file /orms/admin/rooms/manage_...
CVE-2026-33858HIGH8.8Dag Authors, who normally should not be able to execute code in the webserver context could craft XCom payload causing t...
CVE-2026-31283CRITICAL9.8In Totara LMS v19.1.5 and before, the forgot password API does not implement rate limiting for the target email address....
CVE-2026-31282CRITICAL9.8Totara LMS v19.1.5 and before is vulnerable to Incorrect Access Control. The login page code can be manipulated to revea...
CVE-2026-31281HIGH8Totara LMS v19.1.5 and before is vulnerable to HTML Injection. An attacker can inject malicious HTML code in a message a...
CVE-2026-30999HIGH7.5A heap buffer overflow in the av_bprint_finalize() function of FFmpeg v8.0.1 allows attackers to cause a Denial of Servi...
CVE-2026-30998HIGH7.5An improper resource deallocation and closure vulnerability in the tools/zmqsend.c component of FFmpeg v8.0.1 allows att...
CVE-2026-30997HIGH7.5An out-of-bounds read in the read_global_param() function (libavcodec/av1dec.c) of FFmpeg v8.0.1 allows attackers to cau...
CVE-2026-29628MEDIUM6.2A stack overflow in the experimental/tinyobj_loader_opt.h file of tinyobjloader commit d56555b allows attackers to cause...
CVE-2026-1462HIGH8.8A vulnerability in the `TFSMLayer` class of the `keras` package, version 3.13.0, allows attacker-controlled TensorFlow S...
CVE-2026-36947LOW2.7Sourcecodester Computer and Mobile Repair Shop Management System v1.0 is vulnerable to SQL Injection in the file /rsms/a...
CVE-2026-36946LOW2.7Sourcecodester Computer and Mobile Repair Shop Management System v1.0 is vulnerable to SQL injection in the file /rsms/a...
CVE-2026-31428MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: netfilter: nfnetlink_log: fix uninitialized padding...
CVE-2026-31427MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conntrack_sip: fix use of uninitializ...
CVE-2026-31426HIGH7In the Linux kernel, the following vulnerability has been resolved: ACPI: EC: clean up handlers on probe failure in acp...
CVE-2026-31425MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: rds: ib: reject FRMR registration before IB connect...
CVE-2026-31424MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: netfilter: x_tables: restrict xt_check_match/xt_che...
CVE-2026-31423MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: net/sched: sch_hfsc: fix divide-by-zero in rtsc_min...
CVE-2026-31422MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: net/sched: cls_flow: fix NULL pointer dereference o...
CVE-2026-31421MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: net/sched: cls_fw: fix NULL pointer dereference on ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now