2026 CVE Vulnerabilities

50,938 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-39360MEDIUM4.3RustFS is a distributed object storage system built in Rust. Prior to alpha.90, RustFS contains a missing authorization ...
CVE-2026-39354MEDIUM6.5Scoold is a Q&A and a knowledge sharing platform for teams. Prior to 1.66.2, an authenticated authorization flaw in Scoo...
CVE-2026-39348MEDIUM4.3OrangeHRM is a comprehensive human resource management (HRM) system. From 5.0 to 5.8, OrangeHRM Open Source omits author...
CVE-2026-39346MEDIUM5.4OrangeHRM is a comprehensive human resource management (HRM) system. From 5.0 to 5.8, OrangeHRM Open Source allowed auth...
CVE-2026-39345MEDIUM4.9OrangeHRM is a comprehensive human resource management (HRM) system. From 5.0 to 5.8, OrangeHRM Open Source fails to res...
CVE-2026-22711MEDIUM6.9Improper neutralization of alternate XSS syntax vulnerability in The Wikimedia Foundation Mediawiki - Wikilove Extension...
CVE-2026-39338MEDIUM6.1ChurchCRM is an open-source church management system. Prior to 7.1.0, a Blind Reflected Cross-Site Scripting vulnerabili...
CVE-2026-39336MEDIUM6.1ChurchCRM is an open-source church management system. Prior to 7.1.0, a stored cross-site scripting issue affects the Di...
CVE-2026-39335MEDIUM6.1ChurchCRM is an open-source church management system. Prior to 7.1.1, there is Stored XSS in group remove control and fa...
CVE-2026-35572MEDIUM6ChurchCRM is an open-source church management system. Prior to 6.5.3, it is possible to trigger server-side HTTP/HTTPS r...
CVE-2026-24147MEDIUM4.8NVIDIA Triton Inference Server contains a vulnerability in triton server where an attacker may cause an information disc...
CVE-2026-22680MEDIUM6.9OpenViking versions prior to 0.3.3 contain a missing authorization vulnerability in the task polling endpoints that allo...
CVE-2026-39316MEDIUM6.2OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. In versions 2.4.16 ...
CVE-2026-39314MEDIUM6.2OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. In versions 2.4.16 ...
CVE-2026-35613MEDIUM4.7coursevault-preview is a utility for previewing course material files from a configured directory. coursevault-preview v...
CVE-2026-35608MEDIUM6.1QuickDrop is an easy-to-use file sharing application. Prior to 1.5.3, a stored XSS vulnerability exists in the file prev...
CVE-2026-35592MEDIUM6.5pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev97, the _safe_extractall() func...
CVE-2026-35586MEDIUM6.8pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev97, the ADMIN_ONLY_CORE_OPTIONS...
CVE-2026-35584MEDIUM6.5FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to 1.8.212, the endpoint GET /t...
CVE-2026-35583MEDIUM5.3Emissary is a P2P based data-driven workflow engine. Prior to 8.39.0, the configuration API endpoint (/api/configuration...
CVE-2026-32588MEDIUM6.5Authenticated DoS over CQL in Apache Cassandra 4.0, 4.1, 5.0 allows authenticated user to raise query latencies via repe...
CVE-2026-27315MEDIUM5.5Sensitive Information Leak in cqlsh in Apache Cassandra 4.0 allows access to sensitive information, like passwords, from...
CVE-2026-5745MEDIUM5.5A flaw was found in libarchive. A NULL pointer dereference vulnerability exists in the ACL parsing logic, specifically w...
CVE-2026-35571MEDIUM4.8Emissary is a P2P based data-driven workflow engine. Prior to 8.39.0, Mustache navigation templates interpolated configu...
CVE-2026-35516MEDIUM5LinkAce is a self-hosted archive to collect website links. Prior to 2.5.4, LinkRepository::update and CheckLinksCommand:...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now