2026 CVE Vulnerabilities
65,702 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-39319 | HIGH | 8.8 | 0.2% | Apr 7, 2026 | ChurchCRM is an open-source church management system. Prior to 7.1.0, a second order SQL injection vulnerability was fou... |
| CVE-2026-39318 | HIGH | 8.8 | 0.3% | Apr 7, 2026 | ChurchCRM is an open-source church management system. Versions prior to 7.1.0 have an SQL injection vulnerability in the... |
| CVE-2026-39317 | — | — | — | Apr 7, 2026 | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-39334. Reason: This candidate is a ... |
| CVE-2026-35576 | HIGH | 8.7 | 0.3% | Apr 7, 2026 | ChurchCRM is an open-source church management system. Prior to 7.0.0, a stored cross-site scripting (XSS) vulnerability ... |
| CVE-2026-35575 | HIGH | 8 | 0.2% | Apr 7, 2026 | ChurchCRM is an open-source church management system. Prior to 6.5.3, a Stored Cross-Site Scripting (Stored XSS) vulnera... |
| CVE-2026-35573 | CRITICAL | 9.1 | 0.8% | Apr 7, 2026 | ChurchCRM is an open-source church management system. Prior to 6.5.3, a path traversal vulnerability in ChurchCRM's back... |
| CVE-2026-35572 | MEDIUM | 6 | 0.3% | Apr 7, 2026 | ChurchCRM is an open-source church management system. Prior to 6.5.3, it is possible to trigger server-side HTTP/HTTPS r... |
| CVE-2026-31272 | CRITICAL | 9.8 | 0.6% | Apr 7, 2026 | MRCMS 3.1.2 contains an access control vulnerability. The save() method in src/main/java/org/marker/mushroom/controller/... |
| CVE-2026-31271 | CRITICAL | 9.8 | 0.6% | Apr 7, 2026 | megagao production_ssm v1.0 contains an authorization bypass vulnerability in the user addition functionality. The inser... |
| CVE-2026-24175 | HIGH | 7.5 | 0.5% | Apr 7, 2026 | NVIDIA Triton Inference Server contains a vulnerability where an attacker could cause a server crash by sending a malfor... |
| CVE-2026-24174 | HIGH | 7.5 | 0.5% | Apr 7, 2026 | NVIDIA Triton Inference Server contains a vulnerability where an attacker could cause a server crash by sending a malfor... |
| CVE-2026-24173 | HIGH | 7.5 | 0.5% | Apr 7, 2026 | NVIDIA Triton Inference Server contains a vulnerability where an attacker could cause a server crash by sending a malfor... |
| CVE-2026-24156 | HIGH | 7.3 | 0.3% | Apr 7, 2026 | NVIDIA DALI contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exp... |
| CVE-2026-24147 | MEDIUM | 4.8 | 0.5% | Apr 7, 2026 | NVIDIA Triton Inference Server contains a vulnerability in triton server where an attacker may cause an information disc... |
| CVE-2026-24146 | HIGH | 7.5 | 0.5% | Apr 7, 2026 | NVIDIA Triton Inference Server contains a vulnerability where insufficient input validation and a large number of output... |
| CVE-2026-22682 | HIGH | 8.4 | 0.1% | Apr 7, 2026 | OpenHarness prior to commit 166fcfe contains an improper access control vulnerability in built-in file tools due to inco... |
| CVE-2026-22680 | MEDIUM | 6.9 | 0.4% | Apr 7, 2026 | OpenViking versions prior to 0.3.3 contain a missing authorization vulnerability in the task polling endpoints that allo... |
| CVE-2026-4631 | CRITICAL | 9.8 | 14.2% | Apr 7, 2026 | Cockpit's remote login feature passes user-supplied hostnames and usernames from the web interface to the SSH client wit... |
| CVE-2026-39384 | HIGH | 7.6 | 0.2% | Apr 7, 2026 | FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to 1.8.212, FreeScout does not ... |
| CVE-2026-39316 | MEDIUM | 6.2 | 0.2% | Apr 7, 2026 | OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. In versions 2.4.16 ... |
| CVE-2026-39314 | MEDIUM | 6.2 | 0.2% | Apr 7, 2026 | OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. In versions 2.4.16 ... |
| CVE-2026-39312 | HIGH | 7.5 | 0.4% | Apr 7, 2026 | SoftEtherVPN is a an open-source cross-platform multi-protocol VPN Program. In 5.2.5188 and earlier, a pre-authenticatio... |
| CVE-2026-39308 | HIGH | 7.1 | 0.3% | Apr 7, 2026 | PraisonAI is a multi-agent teams system. Prior to 1.5.113, PraisonAI's recipe registry publish endpoint writes uploaded ... |
| CVE-2026-39307 | HIGH | 8.1 | 0.3% | Apr 7, 2026 | PraisonAI is a multi-agent teams system. Prior to 1.5.113, The PraisonAI templates installation feature is vulnerable to... |
| CVE-2026-39306 | HIGH | 7.3 | 0.3% | Apr 7, 2026 | PraisonAI is a multi-agent teams system. Prior to 1.5.113, PraisonAI's recipe registry pull flow extracts attacker-contr... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now