2026 CVE Vulnerabilities

49,638 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-10252HIGH7.3A security vulnerability has been detected in itsourcecode Online House Rental System 1.0. This affects an unknown funct...
CVE-2026-10251HIGH7.3A weakness has been identified in itsourcecode Online House Rental System 1.0. The impacted element is an unknown functi...
CVE-2026-10250HIGH7.3A security flaw has been discovered in itsourcecode Online Blood Bank Management System 1.0. The affected element is an ...
CVE-2026-10249HIGH7.3A vulnerability was identified in itsourcecode Online Blood Bank Management System 1.0. Impacted is an unknown function ...
CVE-2026-9024HIGH8.7A Stored Cross-site Scripting (XSS) vulnerability affecting Process Experience Studio in DELMIA Service Process Engineer...
CVE-2026-49361HIGH7.5Apache Fluss versions prior to 0.9.1 configure the Netty LengthFieldBasedFrameDecoder with Integer.MAX_VALUE as the maxi...
CVE-2026-49298HIGH8.8A bug in Apache Airflow's KubernetesExecutor caused JWT tokens used by worker pods to authenticate against the Execution...
CVE-2026-49157HIGH8.8Incorrect Default Permissions vulnerability in Apache ActiveMQ. This issue affects Apache ActiveMQ: before 5.19.7, from...
CVE-2026-48827HIGH7.1Path traversal vulnerability in Apache MINA SSHD bundle sshd-git. Lack of path validation in git-upload-pack, git-receiv...
CVE-2026-45505HIGH8.8Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ Br...
CVE-2026-45360HIGH7.3Apache Airflow's scheduler-side deadline-reference decoder (`SerializedCustomReference.deserialize_reference`) imported ...
CVE-2026-42588HIGH8.1Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ Br...
CVE-2026-42359HIGH8.8A bug in Apache Airflow's XCom PATCH endpoint `PATCH /api/v2/xcomEntries/{key}` allowed an authenticated UI/API user wit...
CVE-2026-41084HIGH7.5A bug in Apache Airflow's bulk Task Instances API (`PATCH/DELETE /api/v2/dags/{dag_id}/dagRuns/{dag_run_id}/taskInstance...
CVE-2026-40961HIGH7.2A bug in the login redirect route in Apache Airflow allowed authenticated users to craft URLs that bypassed the `is_safe...
CVE-2026-40546HIGH8.7SOPlanning is vulnerable to SQL Injection across multiple endpoints and parameters. Attacker with low privileges can inj...
CVE-2026-40543HIGH8.8SOPlanning does not enforce authorization for backup functionalities. An unauthenticated attacker can directly query bac...
CVE-2026-32325HIGH8.5Privilege chaining issue exists in ServerView Agents for Windows V11.60.04 and earlier. If this vulnerability is exploit...
CVE-2026-27788HIGH8.5Incorrect permission assignment for critical resource issue exists in ServerView Agents for Windows V11.60.04 and earlie...
CVE-2026-10243HIGH7.3A security vulnerability has been detected in code-projects Smart Parking System 1.0. Affected is an unknown function of...
CVE-2026-10236HIGH7.3A vulnerability has been found in SourceCodester Water Billing Management System 1.0. This issue affects some unknown pr...
CVE-2026-35563HIGH8.5It was identified that the LDAP client implementation in version 2.1.7 does not verify if the server certificate matches...
CVE-2026-10227HIGH7.3A vulnerability has been found in raisulislamg4 student_management_system_by_php up to 310d950e09013d5133c6b9210aff94443...
CVE-2026-10226HIGH7.3A flaw has been found in raisulislamg4 student_management_system_by_php up to 310d950e09013d5133c6b9210aff9444382d16d1. ...
CVE-2026-10225HIGH7.3A vulnerability was detected in raisulislamg4 student_management_system_by_php up to 310d950e09013d5133c6b9210aff9444382...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now