2026 CVE Vulnerabilities

47,375 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-46726HIGH7.5Improper Input Validation, Exposure of Sensitive Information to an Unauthorized Actor, Server-Side Request Forgery (SSRF...
CVE-2026-46592HIGH7.5Improper Input Validation, Unintended Proxy or Intermediary ('Confused Deputy') vulnerability in Apache Camel CXF SOAP c...
CVE-2026-46591HIGH8.2Improper Neutralization of Special Elements in Data Query Logic vulnerability in Apache Camel Neo4J component. The came...
CVE-2026-46590HIGH8.8Deserialization of Untrusted Data vulnerability in Apache Camel PQC component. The camel-pqc component persists post-qu...
CVE-2026-46585HIGH7.5Improper Input Validation, Authorization Bypass Through User-Controlled Key vulnerability in Apache Camel Lucene Compone...
CVE-2026-46457HIGH7.5Improper Input Validation vulnerability in Apache Camel NATS component. The camel-nats component maps inbound NATS mess...
CVE-2026-44934HIGH7A information disclosure when DEBUG loglevel is set in SUSE Rancher AI Agent 1.0 before 1.0.2 could leak API keys or LLM...
CVE-2026-43866HIGH7.3Deserialization of Untrusted Data vulnerability in Apache Camel, Apache Camel JMS component. JmsBinding.extractBodyFrom...
CVE-2026-43865HIGH8.1Deserialization of Untrusted Data vulnerability in Apache Camel Hazelcast component. The camel-hazelcast component crea...
CVE-2026-42527HIGH8.1Deserialization of Untrusted Data vulnerability in Apache Camel. The default ObjectInputFilter pattern shipped with sev...
CVE-2026-40859HIGH8.1Deserialization of Untrusted Data vulnerability in Apache Camel. The camel-vertx-http component deserializes HTTP respo...
CVE-2026-24012HIGH7.5Uncontrolled Resource Consumption vulnerability in Apache IoTDB.  Some interface fails to impose reasonable limits on t...
CVE-2026-14809HIGH8.7Prog Management System developed by PROG MIS has a SQL Injection vulnerability, allowing unauthenticated remote attacker...
CVE-2026-14802HIGH7.3A vulnerability was detected in react create-react-app up to 5.0.1 on macOS. This affects the function startBrowserProce...
CVE-2026-12083HIGH8.1The Admin and Site Enhancements (ASE) WordPress plugin before 8.8.4, admin-site-enhancements-pro WordPress plugin before...
CVE-2026-11962HIGH8.8The FileOrganizer WordPress plugin before 1.2.0 does not validate the file type on several of its file-management opera...
CVE-2026-11855HIGH8.8The Simple Membership WordPress plugin before 4.7.5 does not verify the authenticity of Stripe webhook requests when no ...
CVE-2026-11766HIGH8The Ultimate Member WordPress plugin before 2.12.0 does not properly sanitise and escape the value of custom textarea p...
CVE-2026-10830HIGH8.8The AllCoach WordPress plugin before 1.0.2 does not verify that an email address submitted to a public account-registra...
CVE-2026-14789HIGH7.8A vulnerability was detected in radareorg radare2 up to 6.1.6. Affected by this issue is some unknown functionality of t...
CVE-2026-14788HIGH7.8A security vulnerability has been detected in radareorg radare2 up to 6.1.6. Affected by this vulnerability is the funct...
CVE-2026-14787HIGH7.8A weakness has been identified in radareorg radare2 up to 6.1.6. Affected is the function cmd_print in the library libr/...
CVE-2026-14778HIGH7.3A security vulnerability has been detected in SourceCodester Onlne Examination & Learning Management System 1.0. This af...
CVE-2026-14772HIGH7.3A vulnerability has been found in SourceCodester Class and Exam Timetabling System 1.0/1.php. The impacted element is an...
CVE-2026-14771HIGH7.3A flaw has been found in SourceCodester Class and Exam Timetabling System 1.0/1.php. The affected element is an unknown ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now