2026 CVE Vulnerabilities
47,998 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-49267 | MEDIUM | 5.9 | 0.2% | Jun 1, 2026 | Apache Airflow's EmailOperator and the underlying `airflow.utils.email` helpers established SMTP STARTTLS connections wi... |
| CVE-2026-48726 | MEDIUM | 6.5 | 0.4% | Jun 1, 2026 | A bug in Apache Airflow's auth manager logout handling left previously-issued JWT tokens valid after the user clicked lo... |
| CVE-2026-46764 | MEDIUM | 4.3 | 0.4% | Jun 1, 2026 | The Event Log detail endpoint `GET /api/v2/eventLogs/{event_log_id}` in Apache Airflow fetched audit-log rows directly b... |
| CVE-2026-46605 | MEDIUM | 4.3 | 0.3% | Jun 1, 2026 | Incomplete authorization by Apache ActiveMQ server before versions v6.2.6 and v5.19.7 allows authenticated connections t... |
| CVE-2026-42360 | MEDIUM | 6.5 | 0.3% | Jun 1, 2026 | A bug in Apache Airflow's rendered-template field handling caused nested sensitive-key masking (e.g. nested `password` /... |
| CVE-2026-42358 | MEDIUM | 6.5 | 0.3% | Jun 1, 2026 | A bug in Apache Airflow's Variable response masker caused nested-key redaction (triggered by secret-suffixed key names l... |
| CVE-2026-42253 | MEDIUM | 6.1 | 1.1% | Jun 1, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache ActiveMQ, A... |
| CVE-2026-41017 | MEDIUM | 5.9 | 0.3% | Jun 1, 2026 | Apache Airflow's `JWTRefreshMiddleware` set the JWT auth cookie without the `Secure` flag, so deployments running the Ai... |
| CVE-2026-41014 | MEDIUM | 4.3 | 0.4% | Jun 1, 2026 | The partitioned_dag_runs endpoints in the Airflow UI enforced only asset-level access control, not per-Dag authorization... |
| CVE-2026-40861 | MEDIUM | 6.5 | 0.7% | Jun 1, 2026 | A Dag author could either (a) create a symlink under their task's log directory pointing to an arbitrary file readable b... |
| CVE-2026-40549 | MEDIUM | 5.1 | 0.2% | Jun 1, 2026 | SOPlanning is vulnerable to Cross‑Site Request Forgery (CSRF) in groupe_save create, modify and delete endpoints. An att... |
| CVE-2026-40548 | MEDIUM | 6.4 | 0.3% | Jun 1, 2026 | SOPlanning does not verify uploaded file extension. An authenticated attacker with access to the backup functionality ca... |
| CVE-2026-40547 | MEDIUM | 6.4 | 0.4% | Jun 1, 2026 | SOPlanning is vulnerable to Path Traversal in backup endpoints. Authenticated remote attacker is able to exploit a vuln... |
| CVE-2026-40545 | MEDIUM | 5.1 | 0.4% | Jun 1, 2026 | SOPlanning is vulnerable to Reflected XSS via the taches parameter. An attacker can craft a malicious URL which, when op... |
| CVE-2026-40544 | MEDIUM | 5.1 | 0.3% | Jun 1, 2026 | SOPlanning is vulnerable to Stored Cross-Site Scripting (XSS) via /process/upload_backup endpoint. An authenticated atta... |
| CVE-2026-10242 | MEDIUM | 6.3 | 0.3% | Jun 1, 2026 | A weakness has been identified in itsourcecode Content Management System 1.0. This impacts an unknown function of the fi... |
| CVE-2026-10241 | MEDIUM | 6.3 | 0.3% | Jun 1, 2026 | A security flaw has been discovered in jeecgboot The server processes these URLs up to 3.9.1. This affects the function ... |
| CVE-2026-10240 | MEDIUM | 6.3 | 0.3% | Jun 1, 2026 | A vulnerability was identified in JeecgBoot up to 3.9.2. The impacted element is an unknown function of the file /airag/... |
| CVE-2026-10239 | MEDIUM | 6.3 | 0.3% | Jun 1, 2026 | A vulnerability was determined in JeecgBoot up to 3.9.2. The affected element is the function WordUtil.addImage of the f... |
| CVE-2026-10237 | MEDIUM | 4.7 | 0.3% | Jun 1, 2026 | A vulnerability was found in SourceCodester Water Billing Management System 1.0. Impacted is an unknown function of the ... |
| CVE-2026-45192 | MEDIUM | 6.5 | 0.4% | Jun 1, 2026 | A bug in the GET `/api/v2/connections/{connection_id}` REST API endpoint in Apache Airflow allowed an authenticated UI/A... |
| CVE-2026-10235 | MEDIUM | 6.3 | 0.2% | Jun 1, 2026 | A flaw has been found in CodeAstro Ingredients Stock Management System 1.0. This vulnerability affects unknown code of t... |
| CVE-2026-10232 | MEDIUM | 5.3 | 0.1% | Jun 1, 2026 | A weakness has been identified in Assimp up to 6.0.4. Affected by this vulnerability is the function aiNode::~aiNode of ... |
| CVE-2026-10231 | MEDIUM | 5.3 | 0.1% | Jun 1, 2026 | A security flaw has been discovered in Assimp up to 6.0.4. Affected is the function HL1MDLLoader::extract_anim_value of ... |
| CVE-2026-10230 | MEDIUM | 5.3 | 0.1% | Jun 1, 2026 | A vulnerability was identified in Assimp up to 6.0.4. This impacts the function Assimp::MDL::HalfLife::HL1MDLLoader::rea... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now