2026 CVE Vulnerabilities
43,261 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-10246 | LOW | 3.5 | 0.2% | Jun 1, 2026 | A vulnerability has been found in SourceCodester Pharmacy Sales and Inventory System 1.0. This affects the function crea... |
| CVE-2026-10245 | LOW | 3.5 | 0.2% | Jun 1, 2026 | A flaw has been found in SourceCodester Pharmacy Sales and Inventory System 1.0. Affected by this issue is the function ... |
| CVE-2026-10244 | LOW | 3.5 | 0.2% | Jun 1, 2026 | A vulnerability was detected in SourceCodester Pharmacy Sales and Inventory System 1.0. Affected by this vulnerability i... |
| CVE-2026-45426 | LOW | 3.1 | 0.3% | Jun 1, 2026 | Exploitation requires the attacker to already be an authenticated Airflow worker holding a valid Log-server JWT issued f... |
| CVE-2026-40963 | LOW | 3.1 | 0.5% | Jun 1, 2026 | The structure_data endpoint in the Airflow UI returned external dependency graph nodes for linked Dags without checking ... |
| CVE-2026-10234 | LOW | 3.5 | 0.2% | Jun 1, 2026 | A vulnerability was detected in Mettle sendportal up to 3.0.1. This affects an unknown part of the file /webview/ of the... |
| CVE-2026-10233 | LOW | 3.3 | 0.1% | Jun 1, 2026 | A security vulnerability has been detected in Assimp up to 6.0.4. Affected by this issue is the function HL1MDLLoader::r... |
| CVE-2026-10228 | LOW | 3.5 | 0.2% | Jun 1, 2026 | A vulnerability was found in raisulislamg4 student_management_system_by_php up to 310d950e09013d5133c6b9210aff9444382d16... |
| CVE-2026-48191 | LOW | 3.5 | 0.1% | Jun 1, 2026 | An incorrect handling of permissions in STORM powered by OTRS and in OTRS (2026.x and above) Document Search Article Met... |
| CVE-2026-48190 | LOW | 3.5 | 0.1% | Jun 1, 2026 | An incorrect handling of permissions in OTRS External Interface and the ConfigItem List module allows an authenticated c... |
| CVE-2026-10216 | LOW | 3.7 | 0.4% | Jun 1, 2026 | A vulnerability was detected in unitedbyai droidclaw up to 0.5.3. The affected element is an unknown function of the fil... |
| CVE-2026-10201 | LOW | 3.3 | 0.1% | Jun 1, 2026 | A vulnerability was determined in Assimp up to 6.0.4. This vulnerability affects the function FBXExporter::WriteObjects ... |
| CVE-2026-10199 | LOW | 3.3 | 0.1% | May 31, 2026 | A vulnerability has been found in Assimp up to 6.0.4. Affected by this issue is the function glTF2::LazyDict in the libr... |
| CVE-2026-10198 | LOW | 3.3 | 0.1% | May 31, 2026 | A flaw has been found in Assimp up to 6.0.4. Affected by this vulnerability is the function Assimp::glTFImporter::Import... |
| CVE-2026-10197 | LOW | 3.3 | 0.1% | May 31, 2026 | A vulnerability was detected in Assimp up to 6.0.4. Affected is the function glTF2Importer::ImportEmbeddedTextures in th... |
| CVE-2026-10169 | LOW | 3.7 | 0.3% | May 31, 2026 | A vulnerability was detected in OUSL-GROUP-BrinaryBrains School Student Management System up to 1e70e5ad1125b86dca4ee086... |
| CVE-2026-10112 | LOW | 2.4 | 0.2% | May 30, 2026 | A vulnerability has been found in sambitraj STUDENT-MANAGEMENT-SYSTEM 1.0. Affected is an unknown function of the compon... |
| CVE-2026-4387 | LOW | 2 | 0.1% | May 29, 2026 | StrongDM Desktop Application before 23.74.0 (Desktop Client before 53.77.0) on Microsoft Windows stores authentication s... |
| CVE-2026-45613 | LOW | 3.3 | 0.1% | May 29, 2026 | Rizin is a UNIX-like reverse engineering framework and command-line toolset. There is a heap-buffer-overflow in librz/bi... |
| CVE-2026-45324 | LOW | 3.3 | 0.1% | May 29, 2026 | Rizin is a UNIX-like reverse engineering framework and command-line toolset. There is a double free in librz/core/cmd/cm... |
| CVE-2026-45151 | LOW | 2.9 | 0.2% | May 29, 2026 | NanoMQ MQTT Broker (NanoMQ) is an all-around Edge Messaging Platform. In 0.24.8 and earlier, quic_stream_recv can derefe... |
| CVE-2026-49383 | LOW | 3.3 | 0.1% | May 29, 2026 | In JetBrains IntelliJ IDEA before 2026.1 xXE in the UI Designer form parser was possible |
| CVE-2026-33386 | LOW | 2.3 | 0.2% | May 29, 2026 | QuickCMS is vulnerable to Cross-Site Scripting (XSS) through its insecure HTTP-based plugin‑fetching mechanism. A malici... |
| CVE-2026-49318 | LOW | 2.4 | 0.1% | May 29, 2026 | Incorrect behavior order in the Infotainment / Digital Round display of the Indian Motorcycle Scout Bobber + Tech 2025 m... |
| CVE-2026-49317 | LOW | 2.4 | 0.1% | May 29, 2026 | Incorrect behavior order in the Infotainment / Digital Round display of the Indian Motorcycle Scout Bobber + Tech 2025 m... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now