2026 CVE Vulnerabilities

65,717 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-35604HIGH8.1File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a spec...
CVE-2026-35592MEDIUM6.5pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev97, the _safe_extractall() func...
CVE-2026-35586MEDIUM6.8pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev97, the ADMIN_ONLY_CORE_OPTIONS...
CVE-2026-35585HIGH7.2File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a spec...
CVE-2026-35584MEDIUM6.5FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to 1.8.212, the endpoint GET /t...
CVE-2026-35583MEDIUM5.3Emissary is a P2P based data-driven workflow engine. Prior to 8.39.0, the configuration API endpoint (/api/configuration...
CVE-2026-35581HIGH7.2Emissary is a P2P based data-driven workflow engine. Prior to 8.39.0, the Executrix utility class constructed shell comm...
CVE-2026-35580CRITICAL9.1Emissary is a P2P based data-driven workflow engine. Prior to 8.39.0, GitHub Actions workflow files contained shell inje...
CVE-2026-35578——Rejected reason: This CVE is a duplicate of another CVE.** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE...
CVE-2026-35574HIGH8.7ChurchCRM is an open-source church management system. Prior to 6.5.3, a stored Cross-Site Scripting (XSS) vulnerability ...
CVE-2026-35523HIGH7.5Strawberry GraphQL is a library for creating GraphQL APIs. Strawberry up until version 0.312.3 is vulnerable to an authe...
CVE-2026-32588MEDIUM6.5Authenticated DoS over CQL in Apache Cassandra 4.0, 4.1, 5.0 allows authenticated user to raise query latencies via repe...
CVE-2026-27315MEDIUM5.5Sensitive Information Leak in cqlsh in Apache Cassandra 4.0 allows access to sensitive information, like passwords, from...
CVE-2026-27314HIGH8.8Privilege escalation in Apache Cassandra 5.0 on an mTLS environment using MutualTlsAuthenticator allows a user with only...
CVE-2026-23696CRITICAL9.9Windmill CE and EE versions 1.276.0 through 1.603.2 contain an SQL injection vulnerability in the folder ownership manag...
CVE-2026-22683HIGH8.8Windmill versions 1.56.0 through 1.614.0 contain a missing authorization vulnerability that allows users with the Operat...
CVE-2026-5745MEDIUM5.5A flaw was found in libarchive. A NULL pointer dereference vulnerability exists in the ACL parsing logic, specifically w...
CVE-2026-5359——Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All r...
CVE-2026-4931HIGH8.6Smart contract Marginal v1 performs unsafe downcast, allowing attackers to settle a large debt position for a negligible...
CVE-2026-35571MEDIUM4.8Emissary is a P2P based data-driven workflow engine. Prior to 8.39.0, Mustache navigation templates interpolated configu...
CVE-2026-35567——Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-39327. Reason: This candidate is a ...
CVE-2026-35566——Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-39319. Reason: This candidate is a ...
CVE-2026-35534HIGH7.6ChurchCRM is an open-source church management system. Prior to 7.1.0, a stored cross-site scripting vulnerability exists...
CVE-2026-35526HIGH7.5Strawberry GraphQL is a library for creating GraphQL APIs. Prior to 0.312.3, Strawberry GraphQL's WebSocket subscription...
CVE-2026-35521HIGH8.8FTLDNS (pihole-FTL) provides an interactive API and also generates statistics for Pi-hole's Web interface. From 6.0 to b...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now