2026 CVE Vulnerabilities
65,693 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-39322 | HIGH | 8.8 | 0.2% | Apr 7, 2026 | PolarLearn is a free and open-source learning program. In 0-PRERELEASE-15 and earlier, POST /api/v1/auth/sign-in creates... |
| CVE-2026-32864 | HIGH | 8.5 | 0.1% | Apr 7, 2026 | There is a memory corruption vulnerability due to an out-of-bounds read in mgcore_SH_25_3!aligned_free() in NI LabVIEW. ... |
| CVE-2026-32863 | HIGH | 8.5 | 0.2% | Apr 7, 2026 | There is a memory corruption vulnerability due to an out-of-bounds read in sentry_transaction_context_set_operation() in... |
| CVE-2026-32862 | HIGH | 8.5 | 0.1% | Apr 7, 2026 | There is a memory corruption vulnerability due to an out-of-bounds write in ResFileFactory::InitResourceMgr() in NI LabV... |
| CVE-2026-32861 | HIGH | 8.5 | 0.2% | Apr 7, 2026 | There is a memory corruption vulnerability due to an out-of-bounds write when loading a corrupted LVCLASS file in NI Lab... |
| CVE-2026-32860 | HIGH | 8.5 | 0.2% | Apr 7, 2026 | There is a memory corruption vulnerability due to an out-of-bounds write when loading a corrupted LVLIB file in NI LabVI... |
| CVE-2026-5762 | MEDIUM | 5.3 | 0.3% | Apr 7, 2026 | Allocation of resources without limits or throttling vulnerability in Wikimedia Foundation MediaWiki - ReportIncident Ex... |
| CVE-2026-5736 | HIGH | 7.3 | 0.3% | Apr 7, 2026 | A vulnerability was identified in PowerJob 5.1.0/5.1.1/5.1.2. Impacted is an unknown function of the file powerjob-serve... |
| CVE-2026-39360 | MEDIUM | 4.3 | 0.2% | Apr 7, 2026 | RustFS is a distributed object storage system built in Rust. Prior to alpha.90, RustFS contains a missing authorization ... |
| CVE-2026-39355 | HIGH | 8.8 | 0.3% | Apr 7, 2026 | Genealogy is a family tree PHP application. Prior to 5.9.1, a critical broken access control vulnerability in the geneal... |
| CVE-2026-39354 | MEDIUM | 6.5 | 0.2% | Apr 7, 2026 | Scoold is a Q&A and a knowledge sharing platform for teams. Prior to 1.66.2, an authenticated authorization flaw in Scoo... |
| CVE-2026-39351 | CRITICAL | 9.1 | 0.3% | Apr 7, 2026 | Frappe is a full-stack web application framework. Prior to 16.14.0 and 15.104.0, Frappe allows unrestricted Doctype acce... |
| CVE-2026-39349 | LOW | 2.7 | 0.1% | Apr 7, 2026 | OrangeHRM is a comprehensive human resource management (HRM) system. From 5.0 to 5.8, OrangeHRM Open Source encrypts cer... |
| CVE-2026-39348 | MEDIUM | 4.3 | 0.2% | Apr 7, 2026 | OrangeHRM is a comprehensive human resource management (HRM) system. From 5.0 to 5.8, OrangeHRM Open Source omits author... |
| CVE-2026-39347 | LOW | 2.7 | 0.2% | Apr 7, 2026 | OrangeHRM is a comprehensive human resource management (HRM) system. From 5.0 to 5.8, OrangeHRM Open Source accepts chan... |
| CVE-2026-39346 | MEDIUM | 5.4 | 0.2% | Apr 7, 2026 | OrangeHRM is a comprehensive human resource management (HRM) system. From 5.0 to 5.8, OrangeHRM Open Source allowed auth... |
| CVE-2026-39345 | MEDIUM | 4.9 | 0.3% | Apr 7, 2026 | OrangeHRM is a comprehensive human resource management (HRM) system. From 5.0 to 5.8, OrangeHRM Open Source fails to res... |
| CVE-2026-22711 | MEDIUM | 6.9 | 0.3% | Apr 7, 2026 | Improper neutralization of alternate XSS syntax vulnerability in The Wikimedia Foundation Mediawiki - Wikilove Extension... |
| CVE-2026-39344 | HIGH | 8.1 | 0.3% | Apr 7, 2026 | ChurchCRM is an open-source church management system. Prior to 7.1.0, there is a Reflected Cross-Site Scripting (XSS) vu... |
| CVE-2026-39343 | HIGH | 7.2 | 0.3% | Apr 7, 2026 | ChurchCRM is an open-source church management system. Prior to 7.1.0, a SQL injection vulnerability exists in the EditEv... |
| CVE-2026-39342 | HIGH | 8.8 | 0.3% | Apr 7, 2026 | ChurchCRM is an open-source church management system. Prior to 7.1.0, the searchwhat parameter via QueryView.php with th... |
| CVE-2026-39341 | HIGH | 8.1 | 0.3% | Apr 7, 2026 | ChurchCRM is an open-source church management system. Prior to 7.1.0, the application is vulnerable to time-based SQL in... |
| CVE-2026-39340 | HIGH | 8.1 | 0.2% | Apr 7, 2026 | ChurchCRM is an open-source church management system. Prior to 7.1.0, a SQL injection vulnerability exists in PropertyTy... |
| CVE-2026-39339 | CRITICAL | 9.1 | 1.4% | Apr 7, 2026 | ChurchCRM is an open-source church management system. Prior to 7.1.0, a critical authentication bypass vulnerability in... |
| CVE-2026-39338 | MEDIUM | 6.1 | 0.2% | Apr 7, 2026 | ChurchCRM is an open-source church management system. Prior to 7.1.0, a Blind Reflected Cross-Site Scripting vulnerabili... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now