2026 CVE Vulnerabilities

65,045 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-41253HIGH7.8In iTerm2 through 3.6.9, displaying a .txt file can cause code execution via DCS 2000p and OSC 135 data, if the working ...
CVE-2026-6518HIGH8.8The CMP – Coming Soon & Maintenance Plugin by NiteoThemes plugin for WordPress is vulnerable to arbitrary file upload an...
CVE-2026-6048MEDIUM6.4The Flipbox Addon for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Flipbox widget...
CVE-2026-4801MEDIUM6.4The Page Builder Gutenberg Blocks – CoBlocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via exter...
CVE-2026-40494CRITICAL9.8SAIL is a cross-platform library for loading and saving images with support for animation, metadata, and ICC profiles. P...
CVE-2026-40493CRITICAL9.8SAIL is a cross-platform library for loading and saving images with support for animation, metadata, and ICC profiles. P...
CVE-2026-40492CRITICAL9.8SAIL is a cross-platform library for loading and saving images with support for animation, metadata, and ICC profiles. P...
CVE-2026-40491HIGH7.8gdown is a Google Drive public file/folder downloader. Versions prior to 5.2.2 are vulnerable to a Path Traversal attack...
CVE-2026-40490MEDIUM6.8The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HT...
CVE-2026-40489HIGH8.6editorconfig-core-c is an EditorConfig core library for use by plugins supporting EditorConfig parsing. Versions up to ...
CVE-2026-40487CRITICAL9Postiz is an AI social media scheduling tool. Prior to version 2.21.6, a file upload validation bypass allows any authen...
CVE-2026-35582HIGH8.8Emissary is a P2P based data-driven workflow engine. In versions 8.42.0 and below, Executrix.getCommand() is vulnerable ...
CVE-2026-1838MEDIUM6.1The Hostel plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'shortcode_id' parameter in all ...
CVE-2026-1559MEDIUM6.4The Youzify plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'checkin_place_id' parameter in al...
CVE-2026-40572CRITICAL9NovumOS is a custom 32-bit operating system written in Zig and x86 Assembly. In versions prior to 0.24, Syscall 15 (Memo...
CVE-2026-40350HIGH8.8Movary is a self hosted web app to track and rate a user's watched movies. Prior to version 0.71.1, an ordinary authenti...
CVE-2026-40317CRITICAL9.3NovumOS is a custom 32-bit operating system written in Zig and x86 Assembly. In versions prior to 0.24, Syscall 12 (Jump...
CVE-2026-35465HIGH7.5SecureDrop Client is a desktop app for journalists to securely communicate with sources and handle submissions on the Se...
CVE-2026-40593MEDIUM4.8ChurchCRM is an open-source church management system. In versions prior to 7.2.0, the User Editor (UserEditor.php) rende...
CVE-2026-40582CRITICAL9.1ChurchCRM is an open-source church management system. In versions prior to 7.2.0, the /api/public/user/login endpoint va...
CVE-2026-40581HIGH8.1ChurchCRM is an open-source church management system. In versions prior to 7.2.0, the family record deletion endpoint (S...
CVE-2026-40485MEDIUM5.3ChurchCRM is an open-source church management system. In versions prior to 7.2.0, the public API login endpoint (/api/pu...
CVE-2026-40484CRITICAL9.1ChurchCRM is an open-source church management system. In versions prior to 7.2.0, the database backup restore functional...
CVE-2026-40483MEDIUM5.4ChurchCRM is an open-source church management system. In versions prior to 7.2.0, the Pledge Editor renders donation com...
CVE-2026-40482HIGH7.1ChurchCRM is an open-source church management system. Versions prior to 7.2.0 have SQL injection in FinancialService::ge...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now