2026 CVE Vulnerabilities
45,095 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-39382 | CRITICAL | 9.3 | 0.4% | Apr 7, 2026 | dbt enables data analysts and engineers to transform their data using the same practices that software engineers use to ... |
| CVE-2026-39351 | CRITICAL | 9.1 | 0.3% | Apr 7, 2026 | Frappe is a full-stack web application framework. Prior to 16.14.0 and 15.104.0, Frappe allows unrestricted Doctype acce... |
| CVE-2026-39339 | CRITICAL | 9.1 | 1.4% | Apr 7, 2026 | ChurchCRM is an open-source church management system. Prior to 7.1.0, a critical authentication bypass vulnerability in... |
| CVE-2026-39337 | CRITICAL | 10 | 0.7% | Apr 7, 2026 | ChurchCRM is an open-source church management system. Prior to 7.1.0, critical pre-authentication remote code execution ... |
| CVE-2026-39324 | CRITICAL | 9.8 | 0.3% | Apr 7, 2026 | Rack::Session is a session management implementation for Rack. From 2.0.0 to before 2.1.2, Rack::Session::Cookie incorre... |
| CVE-2026-35573 | CRITICAL | 9.1 | 0.8% | Apr 7, 2026 | ChurchCRM is an open-source church management system. Prior to 6.5.3, a path traversal vulnerability in ChurchCRM's back... |
| CVE-2026-31272 | CRITICAL | 9.8 | 0.6% | Apr 7, 2026 | MRCMS 3.1.2 contains an access control vulnerability. The save() method in src/main/java/org/marker/mushroom/controller/... |
| CVE-2026-31271 | CRITICAL | 9.8 | 0.6% | Apr 7, 2026 | megagao production_ssm v1.0 contains an authorization bypass vulnerability in the user addition functionality. The inser... |
| CVE-2026-4631 | CRITICAL | 9.8 | 14.2% | Apr 7, 2026 | Cockpit's remote login feature passes user-supplied hostnames and usernames from the web interface to the SSH client wit... |
| CVE-2026-39305 | CRITICAL | 10 | 0.3% | Apr 7, 2026 | PraisonAI is a multi-agent teams system. Prior to 1.5.113, the Action Orchestrator feature contains a Path Traversal vul... |
| CVE-2026-35614 | CRITICAL | 9.8 | 0.3% | Apr 7, 2026 | Frappe is a full-stack web application framework. Prior to 16.14.0 and 15.104.0, Frappe has a SQL injection in bulk_upda... |
| CVE-2026-35580 | CRITICAL | 9.1 | 0.6% | Apr 7, 2026 | Emissary is a P2P based data-driven workflow engine. Prior to 8.39.0, GitHub Actions workflow files contained shell inje... |
| CVE-2026-23696 | CRITICAL | 9.9 | 5.1% | Apr 7, 2026 | Windmill CE and EE versions 1.276.0 through 1.603.2 contain an SQL injection vulnerability in the folder ownership manag... |
| CVE-2026-35490 | CRITICAL | 9.8 | 0.5% | Apr 7, 2026 | changedetection.io is a free open source web page change detection tool. Prior to 0.54.8, the @login_optionally_required... |
| CVE-2026-33816 | CRITICAL | 9.8 | 0.6% | Apr 7, 2026 | Memory-safety vulnerability in github.com/jackc/pgx/v5. |
| CVE-2026-33815 | CRITICAL | 9.8 | 0.6% | Apr 7, 2026 | Memory-safety vulnerability in github.com/jackc/pgx/v5. |
| CVE-2026-4277 | CRITICAL | 9.8 | 0.5% | Apr 7, 2026 | An issue was discovered in 6.0 before 6.0.4, 5.2 before 5.2.13, and 4.2 before 4.2.30. Add permissions on inline model i... |
| CVE-2026-35458 | CRITICAL | 9.8 | 0.5% | Apr 7, 2026 | Gotenberg is an API for converting document formats. In 8.29.1 and earlier, Gotenberg uses dlclark/regexp2 to compile us... |
| CVE-2026-30079 | CRITICAL | 9.8 | 0.5% | Apr 7, 2026 | In OpenAirInterface V2.2.0 AMF, Out of sequence messages causes incorrect state transition during UE registration proced... |
| CVE-2026-24450 | CRITICAL | 9.8 | 0.5% | Apr 7, 2026 | An integer overflow vulnerability exists in the uncompressed_fp_dng_load_raw functionality of LibRaw Commit 8dc68e2. A s... |
| CVE-2026-21413 | CRITICAL | 9.8 | 0.7% | Apr 7, 2026 | A heap-based buffer overflow vulnerability exists in the lossless_jpeg_load_raw functionality of LibRaw Commit 0b56545 a... |
| CVE-2026-20911 | CRITICAL | 9.8 | 0.5% | Apr 7, 2026 | A heap-based buffer overflow vulnerability exists in the HuffTable::initval functionality of LibRaw Commit 0b56545 and C... |
| CVE-2026-20889 | CRITICAL | 9.8 | 0.6% | Apr 7, 2026 | A heap-based buffer overflow vulnerability exists in the x3f_thumb_loader functionality of LibRaw Commit d20315b. A spec... |
| CVE-2026-20884 | CRITICAL | 9.8 | 0.5% | Apr 7, 2026 | An integer overflow vulnerability exists in the deflate_dng_load_raw functionality of LibRaw Commit 8dc68e2. A specially... |
| CVE-2026-5735 | CRITICAL | 9.8 | 0.3% | Apr 7, 2026 | Memory safety bugs present in Firefox 149.0.1 and Thunderbird 149.0.1. Some of these bugs showed evidence of memory corr... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now