2026 CVE Vulnerabilities
43,261 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-27307 | LOW | 2.4 | 2.9% | Apr 14, 2026 | ColdFusion versions 2023.18, 2025.6 and earlier are affected by an Uncontrolled Resource Consumption vulnerability that ... |
| CVE-2026-27316 | LOW | 2.7 | 0.3% | Apr 14, 2026 | A insufficiently protected credentials vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4 all ... |
| CVE-2026-37602 | LOW | 2.7 | 0.2% | Apr 14, 2026 | SourceCodester Patient Appointment Scheduler System v1.0 is vulnerable to SQL Injection in the file /scheduler/admin/use... |
| CVE-2026-37601 | LOW | 2.7 | 0.2% | Apr 14, 2026 | SourceCodester Patient Appointment Scheduler System v1.0 is vulnerable to SQL Injection in the file /scheduler/admin/app... |
| CVE-2026-37600 | LOW | 2.7 | 0.2% | Apr 14, 2026 | SourceCodester Patient Appointment Scheduler System v1.0 is vulnerable to SQL Injection in the file /scheduler/admin/app... |
| CVE-2026-37598 | LOW | 2.7 | 0.2% | Apr 14, 2026 | SourceCodester Patient Appointment Scheduler System v1.0 is vulnerable to arbitrary code execution (RCE) via /scheduler/... |
| CVE-2026-37597 | LOW | 2.7 | 0.2% | Apr 14, 2026 | SourceCodester Online Employees Work From Home Attendance System v1.0 is vulnerable to SQL Injection in the file /wfh_at... |
| CVE-2026-37596 | LOW | 2.7 | 0.2% | Apr 14, 2026 | SourceCodester Online Employees Work From Home Attendance System v1.0 is vulnerable to SQL Injection in the file /wfh_at... |
| CVE-2026-37595 | LOW | 2.7 | 0.2% | Apr 14, 2026 | SourceCodester Online Employees Work From Home Attendance System v1.0 is vulnerable to SQL Injection in the file /wfh_at... |
| CVE-2026-37594 | LOW | 2.7 | 0.2% | Apr 14, 2026 | SourceCodester Online Employees Work From Home Attendance System v1.0 is vulnerable to SQL Injection in the file /wfh_at... |
| CVE-2026-37593 | LOW | 2.7 | 0.2% | Apr 14, 2026 | SourceCodester Online Employees Work From Home Attendance System v1.0 is vulnerable to SQL Injection in the file /wfh_at... |
| CVE-2026-37592 | LOW | 2.7 | 0.2% | Apr 14, 2026 | Sourcecodester Storage Unit Rental Management System v1.0 is vulnerable to SQL in the file /storage/admin/maintenance/ma... |
| CVE-2026-37591 | LOW | 2.7 | 0.2% | Apr 14, 2026 | Sourcecodester Storage Unit Rental Management System v1.0 is vulnerable to SQL injection in the file /storage/admin/tena... |
| CVE-2026-37590 | LOW | 2.7 | 0.2% | Apr 14, 2026 | SourceCodester Storage Unit Rental Management System v1.0 is vulnerable to SQL Injection in the file /storage/admin/rent... |
| CVE-2026-37589 | LOW | 2.7 | 0.2% | Apr 14, 2026 | SourceCodester Storage Unit Rental Management System v1.0 is vulnerable to SQL Injection in the file /storage/admin/main... |
| CVE-2026-39419 | LOW | 3.1 | 0.2% | Apr 14, 2026 | MaxKB is an open-source AI assistant for enterprise. In versions 2.7.1 and below, an authenticated user can bypass sandb... |
| CVE-2026-27675 | LOW | 2 | 0.2% | Apr 14, 2026 | SAP Landscape Transformation contains a vulnerability in an RFC-exposed function module that could allow a high privileg... |
| CVE-2026-6216 | LOW | 3.5 | 0.2% | Apr 13, 2026 | A security vulnerability has been detected in DbGate up to 7.1.4. This affects an unknown function of the file packages/... |
| CVE-2026-33659 | LOW | 3.1 | 0.3% | Apr 13, 2026 | EspoCRM is an open source customer relationship management application. In versions 9.3.3 and below, the POST /api/v1/At... |
| CVE-2026-32270 | LOW | 1.7 | 0.3% | Apr 13, 2026 | Craft Commerce is an ecommerce platform for Craft CMS. In versions 4.0.0 through 4.10.2 and 5.0.0 through 5.5.4, the Pay... |
| CVE-2026-6192 | LOW | 3.3 | 0.1% | Apr 13, 2026 | A vulnerability was identified in uclouvain openjpeg up to 2.5.4. This impacts the function opj_pi_initialise_encode in ... |
| CVE-2026-36952 | LOW | 2.7 | 0.2% | Apr 13, 2026 | Sourcecodester Online Thesis Archiving System v1.0 is vulnerable to SQL injection in the file /otas/admin/curriculum/man... |
| CVE-2026-36950 | LOW | 2.7 | 0.2% | Apr 13, 2026 | Sourcecodester Online Thesis Archiving System v1.0 is vulnerable to SQL injection in /otas/projects_per_department.php. |
| CVE-2026-6184 | LOW | 2.4 | 0.3% | Apr 13, 2026 | A weakness has been identified in code-projects Simple Content Management System 1.0. This affects an unknown part of th... |
| CVE-2026-36938 | LOW | 2.7 | 0.2% | Apr 13, 2026 | Sourcecodester Online Resort Management System v1.0 is vulnerable to SQL injection in /orms/admin/rooms/view_room.php. |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now