2026 CVE Vulnerabilities

65,368 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-34477MEDIUM5.9The fix for CVE-2025-68161 https://logging.apache.org/security.html#CVE-2025-68161 was incomplete: it addressed hostna...
CVE-2026-29043MEDIUM5.5HDF5 is software for managing data. In 1.14.1-2 and earlier, an attacker who can control an h5 file parsed by HDF5 can t...
CVE-2026-29002HIGH8.6CouchCMS contains a privilege escalation vulnerability that allows authenticated Admin-level users to create SuperAdmin ...
CVE-2026-23781CRITICAL9.8An issue was discovered in BMC Control-M/MFT 9.0.20 through 9.0.22. A set of default debug user credentials is hardcoded...
CVE-2026-36236CRITICAL9.8SourceCodester Engineers Online Portal v1.0 is vulnerable to SQL Injection in update_password.php via the new_password p...
CVE-2026-36235CRITICAL9.8A SQL injection vulnerability was found in the scheduleSubList.php file of itsourcecode Online Student Enrollment System...
CVE-2026-36234CRITICAL9.8itsourcecode Online Student Enrollment System v1.0 is vulnerable to SQL Injection in newCourse.php via the 'coursename' ...
CVE-2026-36233CRITICAL9.8A SQL injection vulnerability was found in the assignInstructorSubjects.php file of itsourcecode Online Student Enrollme...
CVE-2026-36232CRITICAL9.8A SQL injection vulnerability was found in the instructorClasses.php file of itsourcecode Online Student Enrollment Syst...
CVE-2026-31262MEDIUM6.1Cross Site Scripting vulnerability in Altenar Sportsbook Software Platform (SB2) v.2.0 allows a remote attacker to obtai...
CVE-2026-29861CRITICAL9.8PHP-MYSQL-User-Login-System v1.0 was discovered to contain a SQL injection vulnerability via the username parameter at l...
CVE-2026-23782HIGH7.5An issue was discovered in BMC Control-M/MFT 9.0.20 through 9.0.22. An API management endpoint allows unauthenticated us...
CVE-2026-23780HIGH8.8An issue was discovered in BMC Control-M/MFT 9.0.20 through 9.0.22. A SQL injection vulnerability in the MFT API's debug...
CVE-2026-6069HIGH7.5NASM’s disasm() function contains a stack based buffer overflow when formatting disassembly output, allowing an attacker...
CVE-2026-6068CRITICAL9.6NASM contains a heap use after free vulnerability in response file (-@) processing where a dangling pointer to freed mem...
CVE-2026-6067MEDIUM5.5A heap buffer overflow vulnerability exists in the Netwide Assembler (NASM) due to a lack of bounds checking in the obj_...
CVE-2026-40217HIGH8.8LiteLLM through 2026-04-08 allows remote attackers to execute arbitrary code via bytecode rewriting at the /guardrails/t...
CVE-2026-33092HIGH7.8Local privilege escalation due to improper handling of environment variables. The following products are affected: Acron...
CVE-2026-5774MEDIUM6.4Improper synchronization of the userTokens map in the API server in Canonical Juju 4.0.5, 3.6.20, and 2.9.56 may allow a...
CVE-2026-5412MEDIUM6.5In Juju versions prior to 2.9.57 and 3.6.21, an authorization issue exists in the Controller facade. An authenticated us...
CVE-2026-5777HIGH8.7This vulnerability exists in the Atom 3x Projector due to improper exposure of the Android Debug Bridge (ADB) service ov...
CVE-2026-39304HIGH7.5Denial of Service via Out of Memory vulnerability in Apache ActiveMQ Client, Apache ActiveMQ Broker, Apache ActiveMQ. A...
CVE-2026-31412MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: usb: gadget: f_mass_storage: Fix potential integer ...
CVE-2026-6057CRITICAL9.8FalkorDB Browser 1.9.3 contains an unauthenticated path traversal vulnerability in the file upload API that allows remot...
CVE-2026-4162HIGH7.1The Gravity SMTP plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 2.1.4. Th...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now