2026 CVE Vulnerabilities

65,693 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-39337CRITICAL10ChurchCRM is an open-source church management system. Prior to 7.1.0, critical pre-authentication remote code execution ...
CVE-2026-39336MEDIUM6.1ChurchCRM is an open-source church management system. Prior to 7.1.0, a stored cross-site scripting issue affects the Di...
CVE-2026-39335MEDIUM6.1ChurchCRM is an open-source church management system. Prior to 7.1.1, there is Stored XSS in group remove control and fa...
CVE-2026-39334HIGH8.8ChurchCRM is an open-source church management system. Prior to 7.1.0, an SQL injection vulnerability was found in the en...
CVE-2026-39333HIGH8.7ChurchCRM is an open-source church management system. Prior to 7.1.0, he FindFundRaiser.php endpoint reflects user-suppl...
CVE-2026-39332HIGH8.7ChurchCRM is an open-source church management system. Prior to 7.1.0, a reflected Cross-Site Scripting (XSS) vulnerabili...
CVE-2026-39331HIGH8.1ChurchCRM is an open-source church management system. Prior to 7.1.0, an authenticated API user can modify any family re...
CVE-2026-39330HIGH8.8ChurchCRM is an open-source church management system. Prior to 7.1.0, an SQL injection vulnerability was found in the en...
CVE-2026-39329HIGH8.8ChurchCRM is an open-source church management system. Prior to 7.1.0, an SQL injection vulnerability was identified in /...
CVE-2026-39328HIGH8.9ChurchCRM is an open-source church management system. Prior to 7.1.0, a stored cross-site scripting vulnerability exists...
CVE-2026-39327HIGH8.8ChurchCRM is an open-source church management system. Prior to 7.1.0, an SQL injection vulnerability was found in the en...
CVE-2026-39326HIGH8.8ChurchCRM is an open-source church management system. Prior to 7.1.0, an SQL injection vulnerability was found in the en...
CVE-2026-39325HIGH7.2ChurchCRM is an open-source church management system. Prior to 7.1.0, an SQL injection vulnerability was found in the en...
CVE-2026-39324CRITICAL9.8Rack::Session is a session management implementation for Rack. From 2.0.0 to before 2.1.2, Rack::Session::Cookie incorre...
CVE-2026-39323——Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-39326. Reason: This candidate is a ...
CVE-2026-39321LOW3.7Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.8.0-a...
CVE-2026-39319HIGH8.8ChurchCRM is an open-source church management system. Prior to 7.1.0, a second order SQL injection vulnerability was fou...
CVE-2026-39318HIGH8.8ChurchCRM is an open-source church management system. Versions prior to 7.1.0 have an SQL injection vulnerability in the...
CVE-2026-39317——Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-39334. Reason: This candidate is a ...
CVE-2026-35576HIGH8.7ChurchCRM is an open-source church management system. Prior to 7.0.0, a stored cross-site scripting (XSS) vulnerability ...
CVE-2026-35575HIGH8ChurchCRM is an open-source church management system. Prior to 6.5.3, a Stored Cross-Site Scripting (Stored XSS) vulnera...
CVE-2026-35573CRITICAL9.1ChurchCRM is an open-source church management system. Prior to 6.5.3, a path traversal vulnerability in ChurchCRM's back...
CVE-2026-35572MEDIUM6ChurchCRM is an open-source church management system. Prior to 6.5.3, it is possible to trigger server-side HTTP/HTTPS r...
CVE-2026-31272CRITICAL9.8MRCMS 3.1.2 contains an access control vulnerability. The save() method in src/main/java/org/marker/mushroom/controller/...
CVE-2026-31271CRITICAL9.8megagao production_ssm v1.0 contains an authorization bypass vulnerability in the user addition functionality. The inser...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now