2026 CVE Vulnerabilities

65,693 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-39322HIGH8.8PolarLearn is a free and open-source learning program. In 0-PRERELEASE-15 and earlier, POST /api/v1/auth/sign-in creates...
CVE-2026-32864HIGH8.5There is a memory corruption vulnerability due to an out-of-bounds read in mgcore_SH_25_3!aligned_free() in NI LabVIEW. ...
CVE-2026-32863HIGH8.5There is a memory corruption vulnerability due to an out-of-bounds read in sentry_transaction_context_set_operation() in...
CVE-2026-32862HIGH8.5There is a memory corruption vulnerability due to an out-of-bounds write in ResFileFactory::InitResourceMgr() in NI LabV...
CVE-2026-32861HIGH8.5There is a memory corruption vulnerability due to an out-of-bounds write when loading a corrupted LVCLASS file in NI Lab...
CVE-2026-32860HIGH8.5There is a memory corruption vulnerability due to an out-of-bounds write when loading a corrupted LVLIB file in NI LabVI...
CVE-2026-5762MEDIUM5.3Allocation of resources without limits or throttling vulnerability in Wikimedia Foundation MediaWiki - ReportIncident Ex...
CVE-2026-5736HIGH7.3A vulnerability was identified in PowerJob 5.1.0/5.1.1/5.1.2. Impacted is an unknown function of the file powerjob-serve...
CVE-2026-39360MEDIUM4.3RustFS is a distributed object storage system built in Rust. Prior to alpha.90, RustFS contains a missing authorization ...
CVE-2026-39355HIGH8.8Genealogy is a family tree PHP application. Prior to 5.9.1, a critical broken access control vulnerability in the geneal...
CVE-2026-39354MEDIUM6.5Scoold is a Q&A and a knowledge sharing platform for teams. Prior to 1.66.2, an authenticated authorization flaw in Scoo...
CVE-2026-39351CRITICAL9.1Frappe is a full-stack web application framework. Prior to 16.14.0 and 15.104.0, Frappe allows unrestricted Doctype acce...
CVE-2026-39349LOW2.7OrangeHRM is a comprehensive human resource management (HRM) system. From 5.0 to 5.8, OrangeHRM Open Source encrypts cer...
CVE-2026-39348MEDIUM4.3OrangeHRM is a comprehensive human resource management (HRM) system. From 5.0 to 5.8, OrangeHRM Open Source omits author...
CVE-2026-39347LOW2.7OrangeHRM is a comprehensive human resource management (HRM) system. From 5.0 to 5.8, OrangeHRM Open Source accepts chan...
CVE-2026-39346MEDIUM5.4OrangeHRM is a comprehensive human resource management (HRM) system. From 5.0 to 5.8, OrangeHRM Open Source allowed auth...
CVE-2026-39345MEDIUM4.9OrangeHRM is a comprehensive human resource management (HRM) system. From 5.0 to 5.8, OrangeHRM Open Source fails to res...
CVE-2026-22711MEDIUM6.9Improper neutralization of alternate XSS syntax vulnerability in The Wikimedia Foundation Mediawiki - Wikilove Extension...
CVE-2026-39344HIGH8.1ChurchCRM is an open-source church management system. Prior to 7.1.0, there is a Reflected Cross-Site Scripting (XSS) vu...
CVE-2026-39343HIGH7.2ChurchCRM is an open-source church management system. Prior to 7.1.0, a SQL injection vulnerability exists in the EditEv...
CVE-2026-39342HIGH8.8ChurchCRM is an open-source church management system. Prior to 7.1.0, the searchwhat parameter via QueryView.php with th...
CVE-2026-39341HIGH8.1ChurchCRM is an open-source church management system. Prior to 7.1.0, the application is vulnerable to time-based SQL in...
CVE-2026-39340HIGH8.1ChurchCRM is an open-source church management system. Prior to 7.1.0, a SQL injection vulnerability exists in PropertyTy...
CVE-2026-39339CRITICAL9.1ChurchCRM is an open-source church management system. Prior to 7.1.0, a critical authentication bypass vulnerability in...
CVE-2026-39338MEDIUM6.1ChurchCRM is an open-source church management system. Prior to 7.1.0, a Blind Reflected Cross-Site Scripting vulnerabili...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now