2026 CVE Vulnerabilities
43,261 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-36937 | LOW | 2.7 | 0.2% | Apr 13, 2026 | Sourcecodester Online Resort Management System v1.0 is vulnerable to SQL injection in /orms/admin/reservations/view_deta... |
| CVE-2026-36945 | LOW | 2.7 | 0.2% | Apr 13, 2026 | Sourcecodester Computer and Mobile Repair Shop Management System v1.0 is vulnerable to SQL injection in the file /rsms/a... |
| CVE-2026-36944 | LOW | 2.7 | 0.2% | Apr 13, 2026 | Sourcecodester Computer and Mobile Repair Shop Management System v1.0 is vulnerale to SQL injection in the file/rsms/adm... |
| CVE-2026-36943 | LOW | 2.7 | 0.2% | Apr 13, 2026 | Sourcecodester Computer and Mobile Repair Shop Management System v1.0 is vulnerable to SQL injection in the file /rsms/a... |
| CVE-2026-36942 | LOW | 2.7 | 0.2% | Apr 13, 2026 | Sourcecodester Online Resort Management System v1.0 is vulnerable to SQL injection in the file /orms/admin/activities/ma... |
| CVE-2026-36941 | LOW | 2.7 | 0.2% | Apr 13, 2026 | Sourcecodester Online Resort Management System v1.0 is vulnerable to SQL Injection in the file /orms/admin/rooms/manage_... |
| CVE-2026-36947 | LOW | 2.7 | 0.2% | Apr 13, 2026 | Sourcecodester Computer and Mobile Repair Shop Management System v1.0 is vulnerable to SQL Injection in the file /rsms/a... |
| CVE-2026-36946 | LOW | 2.7 | 0.3% | Apr 13, 2026 | Sourcecodester Computer and Mobile Repair Shop Management System v1.0 is vulnerable to SQL injection in the file /rsms/a... |
| CVE-2026-36923 | LOW | 2.7 | 0.2% | Apr 13, 2026 | Sourcecodester Cab Management System 1.0 is vulnerable to SQL Injection in the file /cms/admin/bookings/view_booking.php... |
| CVE-2026-36922 | LOW | 2.7 | 0.2% | Apr 13, 2026 | Sourcecodester Cab Management System v1.0 is vulnerable to SQL injection in the file /cms/admin/categories/view_category... |
| CVE-2026-36920 | LOW | 2.7 | 0.2% | Apr 13, 2026 | Sourcecodester Online Reviewer System v1.0 is vulnerable to SQL Injection in the file /system/system/admins/assessments/... |
| CVE-2026-36919 | LOW | 2.7 | 0.2% | Apr 13, 2026 | Sourcecodester Online Reviewer System v1.0 is vulnerale to SQL Injection in the file /system/system/admins/assessments/e... |
| CVE-2026-36874 | LOW | 2.7 | 0.2% | Apr 13, 2026 | Sourcecodester Basic Library System v1.0 is vulnerable to SQL Injection in /librarysystem/load_student.php. |
| CVE-2026-36873 | LOW | 2.7 | 0.2% | Apr 13, 2026 | Sourcecodester Basic Library System v1.0 is vulnerable to SQL Injection in /librarysystem/load_admin.php. |
| CVE-2026-36872 | LOW | 2.7 | 0.2% | Apr 13, 2026 | Sourcecodester Basic Library System v1.0 is vulnerable to SQL Injection in /librarysystem/load_book.php. |
| CVE-2026-21014 | LOW | 2.8 | 0.1% | Apr 13, 2026 | Improper access control in Samsung Camera prior to version 16.5.00.28 allows local attacker to access location data. Use... |
| CVE-2026-21012 | LOW | 3.3 | 0.1% | Apr 13, 2026 | External control of file name in AODManager prior to SMR Apr-2026 Release 1 allows privileged local attacker to create f... |
| CVE-2026-21006 | LOW | 2.4 | 0.1% | Apr 13, 2026 | Improper access control in Samsung DeX prior to SMR Apr-2026 Release 1 allows physical attackers to access to hidden not... |
| CVE-2026-6162 | LOW | 3.5 | 0.2% | Apr 13, 2026 | A vulnerability has been found in PHPGurukul Company Visitor Management System 2.0. This impacts an unknown function of ... |
| CVE-2026-6106 | LOW | 3.5 | 0.3% | Apr 11, 2026 | A vulnerability was detected in 1Panel-dev MaxKB up to 2.2.1. This vulnerability affects the function StaticHeadersMiddl... |
| CVE-2026-40194 | LOW | 3.7 | 0.3% | Apr 10, 2026 | phpseclib is a PHP secure communications library. Starting in 0.1.1 and prior to 3.0.51, 2.0.53, and 1.0.28, phpseclib\N... |
| CVE-2026-40097 | LOW | 3.7 | 0.2% | Apr 10, 2026 | Step CA is an online certificate authority for secure, automated certificate management for DevOps. From 0.24.0 to befor... |
| CVE-2026-40228 | LOW | 3.3 | 0.2% | Apr 10, 2026 | In systemd 259, systemd-journald can send ANSI escape sequences to the terminals of arbitrary users when a "logger -p em... |
| CVE-2026-6003 | LOW | 2.4 | 0.2% | Apr 10, 2026 | A security vulnerability has been detected in code-projects Simple IT Discussion Forum 1.0. This issue affects some unkn... |
| CVE-2026-40109 | LOW | 3.1 | 0.1% | Apr 9, 2026 | Flux notification-controller is the event forwarder and notification dispatcher for the GitOps Toolkit controllers. Prio... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now