2026 CVE Vulnerabilities
64,788 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-36923 | LOW | 2.7 | 0.2% | Apr 13, 2026 | Sourcecodester Cab Management System 1.0 is vulnerable to SQL Injection in the file /cms/admin/bookings/view_booking.php... |
| CVE-2026-36922 | LOW | 2.7 | 0.2% | Apr 13, 2026 | Sourcecodester Cab Management System v1.0 is vulnerable to SQL injection in the file /cms/admin/categories/view_category... |
| CVE-2026-36920 | LOW | 2.7 | 0.2% | Apr 13, 2026 | Sourcecodester Online Reviewer System v1.0 is vulnerable to SQL Injection in the file /system/system/admins/assessments/... |
| CVE-2026-36919 | LOW | 2.7 | 0.2% | Apr 13, 2026 | Sourcecodester Online Reviewer System v1.0 is vulnerale to SQL Injection in the file /system/system/admins/assessments/e... |
| CVE-2026-36874 | LOW | 2.7 | 0.2% | Apr 13, 2026 | Sourcecodester Basic Library System v1.0 is vulnerable to SQL Injection in /librarysystem/load_student.php. |
| CVE-2026-36873 | LOW | 2.7 | 0.2% | Apr 13, 2026 | Sourcecodester Basic Library System v1.0 is vulnerable to SQL Injection in /librarysystem/load_admin.php. |
| CVE-2026-36872 | LOW | 2.7 | 0.2% | Apr 13, 2026 | Sourcecodester Basic Library System v1.0 is vulnerable to SQL Injection in /librarysystem/load_book.php. |
| CVE-2026-21014 | LOW | 2.8 | 0.1% | Apr 13, 2026 | Improper access control in Samsung Camera prior to version 16.5.00.28 allows local attacker to access location data. Use... |
| CVE-2026-21012 | LOW | 3.3 | 0.1% | Apr 13, 2026 | External control of file name in AODManager prior to SMR Apr-2026 Release 1 allows privileged local attacker to create f... |
| CVE-2026-21006 | LOW | 2.4 | 0.1% | Apr 13, 2026 | Improper access control in Samsung DeX prior to SMR Apr-2026 Release 1 allows physical attackers to access to hidden not... |
| CVE-2026-6162 | LOW | 3.5 | 0.2% | Apr 13, 2026 | A vulnerability has been found in PHPGurukul Company Visitor Management System 2.0. This impacts an unknown function of ... |
| CVE-2026-6106 | LOW | 3.5 | 0.3% | Apr 11, 2026 | A vulnerability was detected in 1Panel-dev MaxKB up to 2.2.1. This vulnerability affects the function StaticHeadersMiddl... |
| CVE-2026-40194 | LOW | 3.7 | 0.3% | Apr 10, 2026 | phpseclib is a PHP secure communications library. Starting in 0.1.1 and prior to 3.0.51, 2.0.53, and 1.0.28, phpseclib\N... |
| CVE-2026-40097 | LOW | 3.7 | 0.2% | Apr 10, 2026 | Step CA is an online certificate authority for secure, automated certificate management for DevOps. From 0.24.0 to befor... |
| CVE-2026-40228 | LOW | 3.3 | 0.2% | Apr 10, 2026 | In systemd 259, systemd-journald can send ANSI escape sequences to the terminals of arbitrary users when a "logger -p em... |
| CVE-2026-6003 | LOW | 2.4 | 0.2% | Apr 10, 2026 | A security vulnerability has been detected in code-projects Simple IT Discussion Forum 1.0. This issue affects some unkn... |
| CVE-2026-40109 | LOW | 3.1 | 0.1% | Apr 9, 2026 | Flux notification-controller is the event forwarder and notification dispatcher for the GitOps Toolkit controllers. Prio... |
| CVE-2026-40077 | LOW | 3.1 | 0.2% | Apr 9, 2026 | Beszel is a server monitoring platform. Prior to 0.18.7, some API endpoints in the Beszel hub accept a user-supplied sys... |
| CVE-2026-5836 | LOW | 2.4 | 0.2% | Apr 9, 2026 | A vulnerability has been found in code-projects Online Shoe Store 1.0. Affected by this issue is some unknown functional... |
| CVE-2026-5835 | LOW | 2.4 | 0.2% | Apr 9, 2026 | A flaw has been found in code-projects Online Shoe Store 1.0. Affected by this vulnerability is an unknown functionality... |
| CVE-2026-5834 | LOW | 2.4 | 0.2% | Apr 9, 2026 | A vulnerability was detected in code-projects Online Shoe Store 1.0. Affected is an unknown function of the file /admin/... |
| CVE-2026-4916 | LOW | 2.7 | 0.3% | Apr 8, 2026 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 18.8.9, 18.9 before 18.9.5, and 1... |
| CVE-2026-5810 | LOW | 3.5 | 0.2% | Apr 8, 2026 | A flaw has been found in SourceCodester Sales and Inventory System 1.0. Affected is an unknown function of the file /del... |
| CVE-2026-5806 | LOW | 3.5 | 0.2% | Apr 8, 2026 | A security vulnerability has been detected in code-projects Easy Blog Site 1.0. This affects an unknown function of the ... |
| CVE-2026-39510 | LOW | 2.7 | 0.2% | Apr 8, 2026 | Authorization Bypass Through User-Controlled Key vulnerability in WP Chill Image Photo Gallery Final Tiles Grid final-ti... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now