2026 CVE Vulnerabilities

47,998 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-49267MEDIUM5.9Apache Airflow's EmailOperator and the underlying `airflow.utils.email` helpers established SMTP STARTTLS connections wi...
CVE-2026-48726MEDIUM6.5A bug in Apache Airflow's auth manager logout handling left previously-issued JWT tokens valid after the user clicked lo...
CVE-2026-46764MEDIUM4.3The Event Log detail endpoint `GET /api/v2/eventLogs/{event_log_id}` in Apache Airflow fetched audit-log rows directly b...
CVE-2026-46605MEDIUM4.3Incomplete authorization by Apache ActiveMQ server before versions v6.2.6 and v5.19.7 allows authenticated connections t...
CVE-2026-42360MEDIUM6.5A bug in Apache Airflow's rendered-template field handling caused nested sensitive-key masking (e.g. nested `password` /...
CVE-2026-42358MEDIUM6.5A bug in Apache Airflow's Variable response masker caused nested-key redaction (triggered by secret-suffixed key names l...
CVE-2026-42253MEDIUM6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache ActiveMQ, A...
CVE-2026-41017MEDIUM5.9Apache Airflow's `JWTRefreshMiddleware` set the JWT auth cookie without the `Secure` flag, so deployments running the Ai...
CVE-2026-41014MEDIUM4.3The partitioned_dag_runs endpoints in the Airflow UI enforced only asset-level access control, not per-Dag authorization...
CVE-2026-40861MEDIUM6.5A Dag author could either (a) create a symlink under their task's log directory pointing to an arbitrary file readable b...
CVE-2026-40549MEDIUM5.1SOPlanning is vulnerable to Cross‑Site Request Forgery (CSRF) in groupe_save create, modify and delete endpoints. An att...
CVE-2026-40548MEDIUM6.4SOPlanning does not verify uploaded file extension. An authenticated attacker with access to the backup functionality ca...
CVE-2026-40547MEDIUM6.4SOPlanning is vulnerable to Path Traversal in backup endpoints. Authenticated remote attacker is able to exploit a vuln...
CVE-2026-40545MEDIUM5.1SOPlanning is vulnerable to Reflected XSS via the taches parameter. An attacker can craft a malicious URL which, when op...
CVE-2026-40544MEDIUM5.1SOPlanning is vulnerable to Stored Cross-Site Scripting (XSS) via /process/upload_backup endpoint. An authenticated atta...
CVE-2026-10242MEDIUM6.3A weakness has been identified in itsourcecode Content Management System 1.0. This impacts an unknown function of the fi...
CVE-2026-10241MEDIUM6.3A security flaw has been discovered in jeecgboot The server processes these URLs up to 3.9.1. This affects the function ...
CVE-2026-10240MEDIUM6.3A vulnerability was identified in JeecgBoot up to 3.9.2. The impacted element is an unknown function of the file /airag/...
CVE-2026-10239MEDIUM6.3A vulnerability was determined in JeecgBoot up to 3.9.2. The affected element is the function WordUtil.addImage of the f...
CVE-2026-10237MEDIUM4.7A vulnerability was found in SourceCodester Water Billing Management System 1.0. Impacted is an unknown function of the ...
CVE-2026-45192MEDIUM6.5A bug in the GET `/api/v2/connections/{connection_id}` REST API endpoint in Apache Airflow allowed an authenticated UI/A...
CVE-2026-10235MEDIUM6.3A flaw has been found in CodeAstro Ingredients Stock Management System 1.0. This vulnerability affects unknown code of t...
CVE-2026-10232MEDIUM5.3A weakness has been identified in Assimp up to 6.0.4. Affected by this vulnerability is the function aiNode::~aiNode of ...
CVE-2026-10231MEDIUM5.3A security flaw has been discovered in Assimp up to 6.0.4. Affected is the function HL1MDLLoader::extract_anim_value of ...
CVE-2026-10230MEDIUM5.3A vulnerability was identified in Assimp up to 6.0.4. This impacts the function Assimp::MDL::HalfLife::HL1MDLLoader::rea...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now