2026 CVE Vulnerabilities

64,766 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-44245MEDIUM6.1Kyverno is a policy engine designed for cloud native platform engineering teams. Prior to 2.5.2, Vue 3's v-html directiv...
CVE-2026-43685HIGH7.2A Remote Code Execution vulnerability in Claris FileMaker Cloud allowed a user with Admin Console privileges to inject a...
CVE-2026-43680HIGH7.2A Remote Code Execution vulnerability in Claris FileMaker Cloud allowed a user with Admin Console privileges to bypass a...
CVE-2026-42289HIGH8.8ChurchCRM is an open-source church management system. Prior to 7.3.2, UserEditor.php processes user account creation and...
CVE-2026-42288CRITICAL10ChurchCRM is an open-source church management system. Prior to 7.3.2, The fix for CVE-2026-39337 is incomplete. The pre-...
CVE-2026-42158LOW2.3Flowsint is an open-source OSINT graph exploration tool designed for cybersecurity investigation, transparency, and veri...
CVE-2026-42157MEDIUM5.1Flowsint is an open-source OSINT graph exploration tool designed for cybersecurity investigation, transparency, and veri...
CVE-2026-42156HIGH7.1Flowsint is an open-source OSINT graph exploration tool designed for cybersecurity investigation, transparency, and veri...
CVE-2026-41901CRITICAL9Thymeleaf is a server-side Java template engine for web and standalone environments. Prior to 3.1.5.RELEASE, a security ...
CVE-2026-1250HIGH7.5The Court Reservation – Manage Your Court Bookings Online plugin for WordPress is vulnerable to generic SQL Injection vi...
CVE-2026-8449——Rejected reason: This CVE ID has been rejected or withdrawn.
CVE-2026-45227HIGH8.8Heym before 0.0.21 contains a sandbox escape vulnerability in the custom Python tool executor that allows authenticated ...
CVE-2026-45226HIGH7.6Heym before 0.0.21 contains an authorization bypass vulnerability in workflow execution that allows authenticated users ...
CVE-2026-45225HIGH7.6Heym before 0.0.21 contains a path traversal vulnerability in the file upload endpoint that allows authenticated users t...
CVE-2026-44871HIGH8.8Command injection vulnerabilities exist in the command line interface (CLI) service accessed by the PAPI protocol of AOS...
CVE-2026-44307HIGH8.7Mako is a template library written in Python. Prior to 1.3.12, on Windows, a URI using backslash traversal (e.g. \..\..\...
CVE-2026-44306MEDIUM5.3Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.73.21 and 6.15.0, responses from the f...
CVE-2026-44305MEDIUM6.8Lemur manages TLS certificate creation. Prior to 1.9.0, when LDAP TLS is enabled (LDAP_USE_TLS = True), Lemur's LDAP aut...
CVE-2026-44304HIGH8.1Lemur manages TLS certificate creation. Prior to 1.9.0, Lemur's LDAP authentication module (lemur/auth/ldap.py) construc...
CVE-2026-44302HIGH7.5Snappier is a high performance C# implementation of the Snappy compression algorithm. Prior to 1.3.1, Snappier.SnappyStr...
CVE-2026-44301HIGH8.1Hugo is a static site generator. From 0.43 to before 0.161.0, when building a Hugo site that uses Node-based asset pipel...
CVE-2026-44296HIGH7.5Deskflow is a keyboard and mouse sharing app. Prior to 1.26.0.167, a remote, unauthenticated denial of service (DoS) vul...
CVE-2026-44262CRITICAL9.4Scramble generates API documentation for Laravel project. From 0.13.2 to before 0.13.22, when documentation endpoints ar...
CVE-2026-44260HIGH8.1efw4.X is an Enterprise Framework for Web. Prior to 4.08.010, the readonly flag set on the <efw:elFinder> JSP tag is int...
CVE-2026-44259MEDIUM4.6efw4.X is an Enterprise Framework for Web. Prior to 4.08.010, the previewServlet serves files with their detected MIME t...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now