2026 CVE Vulnerabilities
53,146 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-39342 | HIGH | 8.8 | 0.3% | Apr 7, 2026 | ChurchCRM is an open-source church management system. Prior to 7.1.0, the searchwhat parameter via QueryView.php with th... |
| CVE-2026-39341 | HIGH | 8.1 | 0.3% | Apr 7, 2026 | ChurchCRM is an open-source church management system. Prior to 7.1.0, the application is vulnerable to time-based SQL in... |
| CVE-2026-39340 | HIGH | 8.1 | 0.2% | Apr 7, 2026 | ChurchCRM is an open-source church management system. Prior to 7.1.0, a SQL injection vulnerability exists in PropertyTy... |
| CVE-2026-39334 | HIGH | 8.8 | 0.3% | Apr 7, 2026 | ChurchCRM is an open-source church management system. Prior to 7.1.0, an SQL injection vulnerability was found in the en... |
| CVE-2026-39333 | HIGH | 8.7 | 0.2% | Apr 7, 2026 | ChurchCRM is an open-source church management system. Prior to 7.1.0, he FindFundRaiser.php endpoint reflects user-suppl... |
| CVE-2026-39332 | HIGH | 8.7 | 0.2% | Apr 7, 2026 | ChurchCRM is an open-source church management system. Prior to 7.1.0, a reflected Cross-Site Scripting (XSS) vulnerabili... |
| CVE-2026-39331 | HIGH | 8.1 | 0.2% | Apr 7, 2026 | ChurchCRM is an open-source church management system. Prior to 7.1.0, an authenticated API user can modify any family re... |
| CVE-2026-39330 | HIGH | 8.8 | 0.2% | Apr 7, 2026 | ChurchCRM is an open-source church management system. Prior to 7.1.0, an SQL injection vulnerability was found in the en... |
| CVE-2026-39329 | HIGH | 8.8 | 0.2% | Apr 7, 2026 | ChurchCRM is an open-source church management system. Prior to 7.1.0, an SQL injection vulnerability was identified in /... |
| CVE-2026-39328 | HIGH | 8.9 | 0.2% | Apr 7, 2026 | ChurchCRM is an open-source church management system. Prior to 7.1.0, a stored cross-site scripting vulnerability exists... |
| CVE-2026-39327 | HIGH | 8.8 | 0.2% | Apr 7, 2026 | ChurchCRM is an open-source church management system. Prior to 7.1.0, an SQL injection vulnerability was found in the en... |
| CVE-2026-39326 | HIGH | 8.8 | 0.2% | Apr 7, 2026 | ChurchCRM is an open-source church management system. Prior to 7.1.0, an SQL injection vulnerability was found in the en... |
| CVE-2026-39325 | HIGH | 7.2 | 0.3% | Apr 7, 2026 | ChurchCRM is an open-source church management system. Prior to 7.1.0, an SQL injection vulnerability was found in the en... |
| CVE-2026-39319 | HIGH | 8.8 | 0.2% | Apr 7, 2026 | ChurchCRM is an open-source church management system. Prior to 7.1.0, a second order SQL injection vulnerability was fou... |
| CVE-2026-39318 | HIGH | 8.8 | 0.3% | Apr 7, 2026 | ChurchCRM is an open-source church management system. Versions prior to 7.1.0 have an SQL injection vulnerability in the... |
| CVE-2026-35576 | HIGH | 8.7 | 0.3% | Apr 7, 2026 | ChurchCRM is an open-source church management system. Prior to 7.0.0, a stored cross-site scripting (XSS) vulnerability ... |
| CVE-2026-35575 | HIGH | 8 | 0.2% | Apr 7, 2026 | ChurchCRM is an open-source church management system. Prior to 6.5.3, a Stored Cross-Site Scripting (Stored XSS) vulnera... |
| CVE-2026-24175 | HIGH | 7.5 | 0.5% | Apr 7, 2026 | NVIDIA Triton Inference Server contains a vulnerability where an attacker could cause a server crash by sending a malfor... |
| CVE-2026-24174 | HIGH | 7.5 | 0.5% | Apr 7, 2026 | NVIDIA Triton Inference Server contains a vulnerability where an attacker could cause a server crash by sending a malfor... |
| CVE-2026-24173 | HIGH | 7.5 | 0.5% | Apr 7, 2026 | NVIDIA Triton Inference Server contains a vulnerability where an attacker could cause a server crash by sending a malfor... |
| CVE-2026-24156 | HIGH | 7.3 | 0.3% | Apr 7, 2026 | NVIDIA DALI contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exp... |
| CVE-2026-24146 | HIGH | 7.5 | 0.5% | Apr 7, 2026 | NVIDIA Triton Inference Server contains a vulnerability where insufficient input validation and a large number of output... |
| CVE-2026-22682 | HIGH | 8.4 | 0.1% | Apr 7, 2026 | OpenHarness prior to commit 166fcfe contains an improper access control vulnerability in built-in file tools due to inco... |
| CVE-2026-39384 | HIGH | 7.6 | 0.2% | Apr 7, 2026 | FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to 1.8.212, FreeScout does not ... |
| CVE-2026-39312 | HIGH | 7.5 | 0.4% | Apr 7, 2026 | SoftEtherVPN is a an open-source cross-platform multi-protocol VPN Program. In 5.2.5188 and earlier, a pre-authenticatio... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now