2026 CVE Vulnerabilities
50,938 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-39360 | MEDIUM | 4.3 | 0.2% | Apr 7, 2026 | RustFS is a distributed object storage system built in Rust. Prior to alpha.90, RustFS contains a missing authorization ... |
| CVE-2026-39354 | MEDIUM | 6.5 | 0.2% | Apr 7, 2026 | Scoold is a Q&A and a knowledge sharing platform for teams. Prior to 1.66.2, an authenticated authorization flaw in Scoo... |
| CVE-2026-39348 | MEDIUM | 4.3 | 0.2% | Apr 7, 2026 | OrangeHRM is a comprehensive human resource management (HRM) system. From 5.0 to 5.8, OrangeHRM Open Source omits author... |
| CVE-2026-39346 | MEDIUM | 5.4 | 0.2% | Apr 7, 2026 | OrangeHRM is a comprehensive human resource management (HRM) system. From 5.0 to 5.8, OrangeHRM Open Source allowed auth... |
| CVE-2026-39345 | MEDIUM | 4.9 | 0.3% | Apr 7, 2026 | OrangeHRM is a comprehensive human resource management (HRM) system. From 5.0 to 5.8, OrangeHRM Open Source fails to res... |
| CVE-2026-22711 | MEDIUM | 6.9 | 0.3% | Apr 7, 2026 | Improper neutralization of alternate XSS syntax vulnerability in The Wikimedia Foundation Mediawiki - Wikilove Extension... |
| CVE-2026-39338 | MEDIUM | 6.1 | 0.2% | Apr 7, 2026 | ChurchCRM is an open-source church management system. Prior to 7.1.0, a Blind Reflected Cross-Site Scripting vulnerabili... |
| CVE-2026-39336 | MEDIUM | 6.1 | 0.2% | Apr 7, 2026 | ChurchCRM is an open-source church management system. Prior to 7.1.0, a stored cross-site scripting issue affects the Di... |
| CVE-2026-39335 | MEDIUM | 6.1 | 0.3% | Apr 7, 2026 | ChurchCRM is an open-source church management system. Prior to 7.1.1, there is Stored XSS in group remove control and fa... |
| CVE-2026-35572 | MEDIUM | 6 | 0.3% | Apr 7, 2026 | ChurchCRM is an open-source church management system. Prior to 6.5.3, it is possible to trigger server-side HTTP/HTTPS r... |
| CVE-2026-24147 | MEDIUM | 4.8 | 0.5% | Apr 7, 2026 | NVIDIA Triton Inference Server contains a vulnerability in triton server where an attacker may cause an information disc... |
| CVE-2026-22680 | MEDIUM | 6.9 | 0.4% | Apr 7, 2026 | OpenViking versions prior to 0.3.3 contain a missing authorization vulnerability in the task polling endpoints that allo... |
| CVE-2026-39316 | MEDIUM | 6.2 | 0.2% | Apr 7, 2026 | OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. In versions 2.4.16 ... |
| CVE-2026-39314 | MEDIUM | 6.2 | 0.2% | Apr 7, 2026 | OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. In versions 2.4.16 ... |
| CVE-2026-35613 | MEDIUM | 4.7 | 0.1% | Apr 7, 2026 | coursevault-preview is a utility for previewing course material files from a configured directory. coursevault-preview v... |
| CVE-2026-35608 | MEDIUM | 6.1 | 0.2% | Apr 7, 2026 | QuickDrop is an easy-to-use file sharing application. Prior to 1.5.3, a stored XSS vulnerability exists in the file prev... |
| CVE-2026-35592 | MEDIUM | 6.5 | 0.3% | Apr 7, 2026 | pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev97, the _safe_extractall() func... |
| CVE-2026-35586 | MEDIUM | 6.8 | 0.1% | Apr 7, 2026 | pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev97, the ADMIN_ONLY_CORE_OPTIONS... |
| CVE-2026-35584 | MEDIUM | 6.5 | 0.3% | Apr 7, 2026 | FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to 1.8.212, the endpoint GET /t... |
| CVE-2026-35583 | MEDIUM | 5.3 | 0.3% | Apr 7, 2026 | Emissary is a P2P based data-driven workflow engine. Prior to 8.39.0, the configuration API endpoint (/api/configuration... |
| CVE-2026-32588 | MEDIUM | 6.5 | 0.5% | Apr 7, 2026 | Authenticated DoS over CQL in Apache Cassandra 4.0, 4.1, 5.0 allows authenticated user to raise query latencies via repe... |
| CVE-2026-27315 | MEDIUM | 5.5 | 0.2% | Apr 7, 2026 | Sensitive Information Leak in cqlsh in Apache Cassandra 4.0 allows access to sensitive information, like passwords, from... |
| CVE-2026-5745 | MEDIUM | 5.5 | 0.2% | Apr 7, 2026 | A flaw was found in libarchive. A NULL pointer dereference vulnerability exists in the ACL parsing logic, specifically w... |
| CVE-2026-35571 | MEDIUM | 4.8 | 0.2% | Apr 7, 2026 | Emissary is a P2P based data-driven workflow engine. Prior to 8.39.0, Mustache navigation templates interpolated configu... |
| CVE-2026-35516 | MEDIUM | 5 | 0.3% | Apr 7, 2026 | LinkAce is a self-hosted archive to collect website links. Prior to 2.5.4, LinkRepository::update and CheckLinksCommand:... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now