2026 CVE Vulnerabilities

49,638 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-42675HIGH7.3Missing Authorization vulnerability in Themefic Hydra Booking allows Exploiting Incorrectly Configured Access Control Se...
CVE-2026-42674HIGH7.5Authentication Bypass by Spoofing vulnerability in AAM Plugin Advanced Access Manager allows URL Encoding. This issue a...
CVE-2026-42673HIGH7.5Insertion of Sensitive Information Into Sent Data vulnerability in Logtivity Activity Logs Activity Logs, User Activity ...
CVE-2026-38950HIGH7.8An issue in ESA AnomalyMatch before 1.3.1 allow attackers to execute arbitrary code via crafted model checkpoint files. ...
CVE-2026-37227HIGH7.5FlexRIC v2.0.0 contains reachable assert(0) calls in stub message handlers for whitelisted but unimplemented E2AP messag...
CVE-2026-37225HIGH7.5FlexRIC v2.0.0 crashes when the iApp receives an E42_RIC_SUBSCRIPTION_REQUEST with an empty ricEventTriggerDefinition fi...
CVE-2026-37224HIGH7.5FlexRIC v2.0.0 crashes when receiving a duplicate E2_SETUP_REQUEST from the same or spoofed E2 Node. The iApp registry e...
CVE-2026-37223HIGH7.5FlexRIC v2.0.0 contains a reachable assertion in the iApp message dispatcher. The dispatcher validates incoming E2AP mes...
CVE-2026-37222HIGH7.5FlexRIC v2.0.0 uses hardcoded assertions to validate Information Element (IE) counts in decoded E2AP messages. A remote ...
CVE-2026-10273HIGH7.3A vulnerability was found in php-censor up to 2.1.6. This affects an unknown function of the file src/Model/Build/GitBui...
CVE-2026-10270HIGH7.5A vulnerability was detected in D-Link DI-7001 MINI up to 19.09.19A1. Impacted is the function sprintf of the file /http...
CVE-2026-10118HIGH7.8A flaw was found in Poppler's Splash backend. A remote attacker could exploit this vulnerability by crafting a malicious...
CVE-2026-48865HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThimPress LearnPre...
CVE-2026-48839HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in VeronaLabs WP Stat...
CVE-2026-42683HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in e4jvikwp VikBookin...
CVE-2026-42681HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in E2Pdf.Com e2pdf al...
CVE-2026-42251HIGH8.7Use of hard-coded credentials in KS-SOMED allowed an unauthorized attacker access to FTP server that hosted the applicat...
CVE-2026-37221HIGH7.5FlexRIC v2.0.0 crashes when receiving a RIC_SUBSCRIPTION_RESPONSE with an unknown ric_id that has no corresponding pendi...
CVE-2026-37220HIGH7.5FlexRIC v2.0.0 crashes when an SCTP association is closed before an E2_SETUP_REQUEST is sent. The near-RT RIC assumes a ...
CVE-2026-10263HIGH7.3A vulnerability was found in SourceCodester Computer Repair Shop Management System up to 1.0. Affected is an unknown fun...
CVE-2026-10262HIGH7.3A vulnerability has been found in code-projects Real State Services 1.0. This impacts an unknown function of the file /l...
CVE-2026-10261HIGH7.3A flaw has been found in CodeAstro Online Job Portal 1.0. This affects an unknown function of the file /users/applicatio...
CVE-2026-10260HIGH7.3A vulnerability was detected in CodeAstro Online Job Portal 1.0. The impacted element is an unknown function of the file...
CVE-2026-10259HIGH8.8A security vulnerability has been detected in H3C Magic B0 up to 100R002. The affected element is the function SetMobile...
CVE-2026-10253HIGH7.3A vulnerability was detected in itsourcecode Online House Rental System 1.0. This impacts an unknown function of the fil...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now