2026 CVE Vulnerabilities

65,328 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-40224HIGH7.3In systemd 259 before 260, there is local privilege escalation in systemd-machined because varlink can be used to reach ...
CVE-2026-40223MEDIUM5.5In systemd 258 before 260, a local unprivileged user can trigger an assert when a Delegate=yes and User=<unset> unit exi...
CVE-2026-40023MEDIUM5.3Apache Log4cxx's XMLLayout https://logging.apache.org/log4cxx/1.7.0/classlog4cxx_1_1xml_1_1XMLLayout.html , in versions...
CVE-2026-40021MEDIUM5.3Apache Log4net's XmlLayout https://logging.apache.org/log4net/manual/configuration/layouts.html#layout-list and XmlLa...
CVE-2026-35594MEDIUM6.5Vikunja is an open-source self-hosted task management platform. Prior to 2.3.0, Vikunja's link share authentication (Get...
CVE-2026-34727CRITICAL9.1Vikunja is an open-source self-hosted task management platform. Prior to 2.3.0, the OIDC callback handler issues a full ...
CVE-2026-34481HIGH7.5Apache Log4j's JsonTemplateLayout https://logging.apache.org/log4j/2.x/manual/json-template-layout.html , in versions u...
CVE-2026-34480HIGH7.5Apache Log4j Core's XmlLayout https://logging.apache.org/log4j/2.x/manual/layouts.html#XmlLayout , in versions up to an...
CVE-2026-34479HIGH7.5The Log4j1XmlLayout from the Apache Log4j 1-to-Log4j 2 bridge fails to escape characters forbidden by the XML 1.0 standa...
CVE-2026-34478HIGH7.5Apache Log4j Core's Rfc5424Layout https://logging.apache.org/log4j/2.x/manual/layouts.html#RFC5424Layout , in versions ...
CVE-2026-34477MEDIUM5.9The fix for CVE-2025-68161 https://logging.apache.org/security.html#CVE-2025-68161 was incomplete: it addressed hostna...
CVE-2026-29043MEDIUM5.5HDF5 is software for managing data. In 1.14.1-2 and earlier, an attacker who can control an h5 file parsed by HDF5 can t...
CVE-2026-29002HIGH8.6CouchCMS contains a privilege escalation vulnerability that allows authenticated Admin-level users to create SuperAdmin ...
CVE-2026-23781CRITICAL9.8An issue was discovered in BMC Control-M/MFT 9.0.20 through 9.0.22. A set of default debug user credentials is hardcoded...
CVE-2026-36236CRITICAL9.8SourceCodester Engineers Online Portal v1.0 is vulnerable to SQL Injection in update_password.php via the new_password p...
CVE-2026-36235CRITICAL9.8A SQL injection vulnerability was found in the scheduleSubList.php file of itsourcecode Online Student Enrollment System...
CVE-2026-36234CRITICAL9.8itsourcecode Online Student Enrollment System v1.0 is vulnerable to SQL Injection in newCourse.php via the 'coursename' ...
CVE-2026-36233CRITICAL9.8A SQL injection vulnerability was found in the assignInstructorSubjects.php file of itsourcecode Online Student Enrollme...
CVE-2026-36232CRITICAL9.8A SQL injection vulnerability was found in the instructorClasses.php file of itsourcecode Online Student Enrollment Syst...
CVE-2026-31262MEDIUM6.1Cross Site Scripting vulnerability in Altenar Sportsbook Software Platform (SB2) v.2.0 allows a remote attacker to obtai...
CVE-2026-29861CRITICAL9.8PHP-MYSQL-User-Login-System v1.0 was discovered to contain a SQL injection vulnerability via the username parameter at l...
CVE-2026-23782HIGH7.5An issue was discovered in BMC Control-M/MFT 9.0.20 through 9.0.22. An API management endpoint allows unauthenticated us...
CVE-2026-23780HIGH8.8An issue was discovered in BMC Control-M/MFT 9.0.20 through 9.0.22. A SQL injection vulnerability in the MFT API's debug...
CVE-2026-6069HIGH7.5NASM’s disasm() function contains a stack based buffer overflow when formatting disassembly output, allowing an attacker...
CVE-2026-6068CRITICAL9.6NASM contains a heap use after free vulnerability in response file (-@) processing where a dangling pointer to freed mem...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now