2026 CVE Vulnerabilities
65,619 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-35446 | HIGH | 8.6 | 0.2% | Apr 8, 2026 | LORIS (Longitudinal Online Research and Imaging System) is a self-hosted web application that provides data- and project... |
| CVE-2026-35407 | MEDIUM | 6.5 | 0.3% | Apr 8, 2026 | Saleor is an e-commerce platform. From 2.10.0 to before 3.23.0a3, 3.22.47, 3.21.54, and 3.20.118, a business-logic and a... |
| CVE-2026-35403 | MEDIUM | 5.4 | 0.2% | Apr 8, 2026 | LORIS (Longitudinal Online Research and Imaging System) is a self-hosted web application that provides data- and project... |
| CVE-2026-35401 | HIGH | 7.5 | 0.3% | Apr 8, 2026 | Saleor is an e-commerce platform. From 2.0.0 to before 3.23.0a3, 3.22.47, 3.21.54, and 3.20.118, a malicious actor can i... |
| CVE-2026-35400 | MEDIUM | 4.3 | 0.2% | Apr 8, 2026 | LORIS (Longitudinal Online Research and Imaging System) is a self-hosted web application that provides data- and project... |
| CVE-2026-35169 | MEDIUM | 5.4 | 0.2% | Apr 8, 2026 | LORIS (Longitudinal Online Research and Imaging System) is a self-hosted web application that provides data- and project... |
| CVE-2026-35165 | MEDIUM | 6.5 | 0.2% | Apr 8, 2026 | LORIS (Longitudinal Online Research and Imaging System) is a self-hosted web application that provides data- and project... |
| CVE-2026-34985 | MEDIUM | 6.5 | 0.2% | Apr 8, 2026 | LORIS (Longitudinal Online Research and Imaging System) is a self-hosted web application that provides data- and project... |
| CVE-2026-34837 | MEDIUM | 4.3 | 0.2% | Apr 8, 2026 | Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.1, he REST endpoint POST /api/v1/ai_ass... |
| CVE-2026-34782 | MEDIUM | 4.3 | 0.2% | Apr 8, 2026 | Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.1 and 6.5.4, the REST endpoint POST /ap... |
| CVE-2026-34724 | HIGH | 7.2 | 0.3% | Apr 8, 2026 | Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.1, a server-side template injection vul... |
| CVE-2026-34723 | HIGH | 7.5 | 0.4% | Apr 8, 2026 | Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.1 and 6.5.4, unauthenticated remote att... |
| CVE-2026-34722 | MEDIUM | 4.3 | 0.2% | Apr 8, 2026 | Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.1 and 6.5.4, the used endpoint for tick... |
| CVE-2026-34721 | MEDIUM | 6.5 | 0.1% | Apr 8, 2026 | Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.1 and 6.5.4, the OAuth callback endpoin... |
| CVE-2026-34720 | MEDIUM | 4.3 | 0.1% | Apr 8, 2026 | Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.1 and 6.5.4, the SSO mechanism in Zamma... |
| CVE-2026-34719 | MEDIUM | 4.3 | 0.2% | Apr 8, 2026 | Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.1 and 6.5.4, the webhook model was miss... |
| CVE-2026-34718 | MEDIUM | 6.1 | 0.1% | Apr 8, 2026 | Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.1 and 6.5.4, the HTML sanitizer for tic... |
| CVE-2026-34392 | HIGH | 7.5 | 0.3% | Apr 8, 2026 | LORIS (Longitudinal Online Research and Imaging System) is a self-hosted web application that provides data- and project... |
| CVE-2026-34248 | MEDIUM | 5.7 | 0.2% | Apr 8, 2026 | Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.1, customers in shared organizations (m... |
| CVE-2026-34166 | MEDIUM | 5.3 | 0.5% | Apr 8, 2026 | LiquidJS is a Shopify / GitHub Pages compatible template engine in pure JavaScript. Prior to 10.25.3, the replace filter... |
| CVE-2026-33350 | HIGH | 7.5 | 0.2% | Apr 8, 2026 | LORIS (Longitudinal Online Research and Imaging System) is a self-hosted web application that provides data- and project... |
| CVE-2026-30818 | HIGH | 8 | 1.2% | Apr 8, 2026 | An OS command injection vulnerability in the dnsmasq module of TP-Link Archer AX53 v1.0 allows an authenticated adjacent... |
| CVE-2026-30817 | MEDIUM | 5.7 | 0.3% | Apr 8, 2026 | An external configuration control vulnerability in the OpenVPN module of TP-Link AX53 v1.0 allows an authenticated adjac... |
| CVE-2026-30816 | MEDIUM | 5.7 | 0.3% | Apr 8, 2026 | An external control of configuration vulnerability in the OpenVPN module of TP-Link AX53 v1.0 allows an authenticated ad... |
| CVE-2026-30815 | HIGH | 8 | 1.2% | Apr 8, 2026 | An OS command injection vulnerability in the OpenVPN module of TP-Link Archer AX53 v1.0 allows an authenticated adjacent... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now