2026 CVE Vulnerabilities

45,095 CVEs published in 2026.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2026-39382CRITICAL9.3dbt enables data analysts and engineers to transform their data using the same practices that software engineers use to ...
CVE-2026-39351CRITICAL9.1Frappe is a full-stack web application framework. Prior to 16.14.0 and 15.104.0, Frappe allows unrestricted Doctype acce...
CVE-2026-39339CRITICAL9.1ChurchCRM is an open-source church management system. Prior to 7.1.0, a critical authentication bypass vulnerability in...
CVE-2026-39337CRITICAL10ChurchCRM is an open-source church management system. Prior to 7.1.0, critical pre-authentication remote code execution ...
CVE-2026-39324CRITICAL9.8Rack::Session is a session management implementation for Rack. From 2.0.0 to before 2.1.2, Rack::Session::Cookie incorre...
CVE-2026-35573CRITICAL9.1ChurchCRM is an open-source church management system. Prior to 6.5.3, a path traversal vulnerability in ChurchCRM's back...
CVE-2026-31272CRITICAL9.8MRCMS 3.1.2 contains an access control vulnerability. The save() method in src/main/java/org/marker/mushroom/controller/...
CVE-2026-31271CRITICAL9.8megagao production_ssm v1.0 contains an authorization bypass vulnerability in the user addition functionality. The inser...
CVE-2026-4631CRITICAL9.8Cockpit's remote login feature passes user-supplied hostnames and usernames from the web interface to the SSH client wit...
CVE-2026-39305CRITICAL10PraisonAI is a multi-agent teams system. Prior to 1.5.113, the Action Orchestrator feature contains a Path Traversal vul...
CVE-2026-35614CRITICAL9.8Frappe is a full-stack web application framework. Prior to 16.14.0 and 15.104.0, Frappe has a SQL injection in bulk_upda...
CVE-2026-35580CRITICAL9.1Emissary is a P2P based data-driven workflow engine. Prior to 8.39.0, GitHub Actions workflow files contained shell inje...
CVE-2026-23696CRITICAL9.9Windmill CE and EE versions 1.276.0 through 1.603.2 contain an SQL injection vulnerability in the folder ownership manag...
CVE-2026-35490CRITICAL9.8changedetection.io is a free open source web page change detection tool. Prior to 0.54.8, the @login_optionally_required...
CVE-2026-33816CRITICAL9.8Memory-safety vulnerability in github.com/jackc/pgx/v5.
CVE-2026-33815CRITICAL9.8Memory-safety vulnerability in github.com/jackc/pgx/v5.
CVE-2026-4277CRITICAL9.8An issue was discovered in 6.0 before 6.0.4, 5.2 before 5.2.13, and 4.2 before 4.2.30. Add permissions on inline model i...
CVE-2026-35458CRITICAL9.8Gotenberg is an API for converting document formats. In 8.29.1 and earlier, Gotenberg uses dlclark/regexp2 to compile us...
CVE-2026-30079CRITICAL9.8In OpenAirInterface V2.2.0 AMF, Out of sequence messages causes incorrect state transition during UE registration proced...
CVE-2026-24450CRITICAL9.8An integer overflow vulnerability exists in the uncompressed_fp_dng_load_raw functionality of LibRaw Commit 8dc68e2. A s...
CVE-2026-21413CRITICAL9.8A heap-based buffer overflow vulnerability exists in the lossless_jpeg_load_raw functionality of LibRaw Commit 0b56545 a...
CVE-2026-20911CRITICAL9.8A heap-based buffer overflow vulnerability exists in the HuffTable::initval functionality of LibRaw Commit 0b56545 and C...
CVE-2026-20889CRITICAL9.8A heap-based buffer overflow vulnerability exists in the x3f_thumb_loader functionality of LibRaw Commit d20315b. A spec...
CVE-2026-20884CRITICAL9.8An integer overflow vulnerability exists in the deflate_dng_load_raw functionality of LibRaw Commit 8dc68e2. A specially...
CVE-2026-5735CRITICAL9.8Memory safety bugs present in Firefox 149.0.1 and Thunderbird 149.0.1. Some of these bugs showed evidence of memory corr...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now