2026 CVE Vulnerabilities

65,293 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-40043HIGH7.1Pachno 1.0.6 contains an authentication bypass vulnerability in the runSwitchUser() action that allows authenticated low...
CVE-2026-40042CRITICAL9.8Pachno 1.0.6 contains an XML external entity injection vulnerability that allows unauthenticated attackers to read arbit...
CVE-2026-40041MEDIUM5.3Pachno 1.0.6 contains a cross-site request forgery vulnerability that allows attackers to perform arbitrary actions in a...
CVE-2026-40040HIGH8.8Pachno 1.0.6 contains an unrestricted file upload vulnerability that allows authenticated users to upload arbitrary file...
CVE-2026-40039HIGH7.1Pachno 1.0.6 contains an open redirection vulnerability that allows attackers to redirect users to arbitrary external we...
CVE-2026-40038HIGH7.2Pachno 1.0.6 contains a stored cross-site scripting vulnerability that allows attackers to execute arbitrary HTML and sc...
CVE-2026-29955HIGH8.8The `/registercrd` endpoint in KubePlus 4.14 in the kubeconfiggenerator component is vulnerable to command injection. Th...
CVE-2026-6196HIGH8.8A vulnerability was detected in Tenda F456 1.0.0.5. This affects the function fromexeCommand of the file /goform/exeComm...
CVE-2026-6195CRITICAL9.8A security vulnerability has been detected in Totolink A7100RU 7.4cu.2313_b20191024. Affected by this issue is the funct...
CVE-2026-6194HIGH8.8A weakness has been identified in Totolink A3002MU B20211125.1046. Affected by this vulnerability is the function sub_41...
CVE-2026-6100CRITICAL9.1Use-after-free (UAF) was possible in the `lzma.LZMADecompressor`, `bz2.BZ2Decompressor`, and `gzip.GzipFile` when a memo...
CVE-2026-32316HIGH7.5jq is a command-line JSON processor. An integer overflow vulnerability exists through version 1.8.1 within the jvp_strin...
CVE-2026-28291HIGH8.1simple-git enables running native Git commands from JavaScript. Versions up to and including 3.31.1 allow execution of a...
CVE-2026-6193HIGH7.3A security flaw has been discovered in PHPGurukul Daily Expense Tracking System 1.1. Affected is an unknown function of ...
CVE-2026-6192LOW3.3A vulnerability was identified in uclouvain openjpeg up to 2.5.4. This impacts the function opj_pi_initialise_encode in ...
CVE-2026-6191MEDIUM6.3A vulnerability was determined in itsourcecode Construction Management System 1.0. This affects an unknown function of t...
CVE-2026-6190MEDIUM6.3A vulnerability was found in itsourcecode Construction Management System 1.0. The impacted element is an unknown functio...
CVE-2026-6189HIGH7.3A vulnerability has been found in SourceCodester Pharmacy Sales and Inventory System 1.0. The affected element is an unk...
CVE-2026-39940MEDIUM5.3ChurchCRM is an open-source church management system. Prior to 7.0.0, it was possible in many places across the ChurchCR...
CVE-2026-36952LOW2.7Sourcecodester Online Thesis Archiving System v1.0 is vulnerable to SQL injection in the file /otas/admin/curriculum/man...
CVE-2026-36950LOW2.7Sourcecodester Online Thesis Archiving System v1.0 is vulnerable to SQL injection in /otas/projects_per_department.php.
CVE-2026-36948HIGH7.3Sourcecodester Online Thesis Archiving System v1.0 is vulnerale to SQL injection in the file /otas/view_archive.php.
CVE-2026-33555MEDIUM5.8An issue was discovered in HAProxy before 3.3.6. The HTTP/3 parser does not check that the received body length matches ...
CVE-2026-23891HIGH8.7Decidim is a participatory democracy framework. In versions below 0.30.5 and 0.31.0.rc1 through 0.31.0, a stored code ex...
CVE-2026-6231HIGH7.5The bson_validate function may return early on specific inputs and incorrectly report success. This behavior could resul...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now