2026 CVE Vulnerabilities

47,526 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-46592HIGH7.5Improper Input Validation, Unintended Proxy or Intermediary ('Confused Deputy') vulnerability in Apache Camel CXF SOAP c...
CVE-2026-46591HIGH8.2Improper Neutralization of Special Elements in Data Query Logic vulnerability in Apache Camel Neo4J component. The came...
CVE-2026-46590HIGH8.8Deserialization of Untrusted Data vulnerability in Apache Camel PQC component. The camel-pqc component persists post-qu...
CVE-2026-46585HIGH7.5Improper Input Validation, Authorization Bypass Through User-Controlled Key vulnerability in Apache Camel Lucene Compone...
CVE-2026-46457HIGH7.5Improper Input Validation vulnerability in Apache Camel NATS component. The camel-nats component maps inbound NATS mess...
CVE-2026-44934HIGH7A information disclosure when DEBUG loglevel is set in SUSE Rancher AI Agent 1.0 before 1.0.2 could leak API keys or LLM...
CVE-2026-43866HIGH7.3Deserialization of Untrusted Data vulnerability in Apache Camel, Apache Camel JMS component. JmsBinding.extractBodyFrom...
CVE-2026-43865HIGH8.1Deserialization of Untrusted Data vulnerability in Apache Camel Hazelcast component. The camel-hazelcast component crea...
CVE-2026-42527HIGH8.1Deserialization of Untrusted Data vulnerability in Apache Camel. The default ObjectInputFilter pattern shipped with sev...
CVE-2026-40859HIGH8.1Deserialization of Untrusted Data vulnerability in Apache Camel. The camel-vertx-http component deserializes HTTP respo...
CVE-2026-24012HIGH7.5Uncontrolled Resource Consumption vulnerability in Apache IoTDB.  Some interface fails to impose reasonable limits on t...
CVE-2026-14809HIGH8.7Prog Management System developed by PROG MIS has a SQL Injection vulnerability, allowing unauthenticated remote attacker...
CVE-2026-14802HIGH7.3A vulnerability was detected in react create-react-app up to 5.0.1 on macOS. This affects the function startBrowserProce...
CVE-2026-12083HIGH8.1The Admin and Site Enhancements (ASE) WordPress plugin before 8.8.4, admin-site-enhancements-pro WordPress plugin before...
CVE-2026-11962HIGH8.8The FileOrganizer WordPress plugin before 1.2.0 does not validate the file type on several of its file-management opera...
CVE-2026-11855HIGH8.8The Simple Membership WordPress plugin before 4.7.5 does not verify the authenticity of Stripe webhook requests when no ...
CVE-2026-11766HIGH8The Ultimate Member WordPress plugin before 2.12.0 does not properly sanitise and escape the value of custom textarea p...
CVE-2026-10830HIGH8.8The AllCoach WordPress plugin before 1.0.2 does not verify that an email address submitted to a public account-registra...
CVE-2026-14789HIGH7.8A vulnerability was detected in radareorg radare2 up to 6.1.6. Affected by this issue is some unknown functionality of t...
CVE-2026-14788HIGH7.8A security vulnerability has been detected in radareorg radare2 up to 6.1.6. Affected by this vulnerability is the funct...
CVE-2026-14787HIGH7.8A weakness has been identified in radareorg radare2 up to 6.1.6. Affected is the function cmd_print in the library libr/...
CVE-2026-14778HIGH7.3A security vulnerability has been detected in SourceCodester Onlne Examination & Learning Management System 1.0. This af...
CVE-2026-14772HIGH7.3A vulnerability has been found in SourceCodester Class and Exam Timetabling System 1.0/1.php. The impacted element is an...
CVE-2026-14771HIGH7.3A flaw has been found in SourceCodester Class and Exam Timetabling System 1.0/1.php. The affected element is an unknown ...
CVE-2026-14770HIGH7.3A vulnerability was detected in SourceCodester Class and Exam Timetabling System 1.0. Impacted is an unknown function of...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now