2026 CVE Vulnerabilities
65,752 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-35442 | HIGH | 8.1 | 0.3% | Apr 6, 2026 | Directus is a real-time API and App dashboard for managing SQL database content. Prior to 11.17.0, aggregate functions (... |
| CVE-2026-35441 | MEDIUM | 6.5 | 0.4% | Apr 6, 2026 | Directus is a real-time API and App dashboard for managing SQL database content. Prior to 11.17.0, Directus' GraphQL end... |
| CVE-2026-35413 | MEDIUM | 5.3 | 0.3% | Apr 6, 2026 | Directus is a real-time API and App dashboard for managing SQL database content. Prior to 11.16.1, when GRAPHQL_INTROSPE... |
| CVE-2026-35412 | HIGH | 8.1 | 0.3% | Apr 6, 2026 | Directus is a real-time API and App dashboard for managing SQL database content. Prior to 11.16.1, Directus' TUS resumab... |
| CVE-2026-35411 | MEDIUM | 4.3 | 0.3% | Apr 6, 2026 | Directus is a real-time API and App dashboard for managing SQL database content. Prior to 11.16.1, Directus is vulnerabl... |
| CVE-2026-35410 | MEDIUM | 6.1 | 0.3% | Apr 6, 2026 | Directus is a real-time API and App dashboard for managing SQL database content. Prior to 11.16.1, an open redirect vuln... |
| CVE-2026-35409 | HIGH | 7.7 | 0.3% | Apr 6, 2026 | Directus is a real-time API and App dashboard for managing SQL database content. Prior to 11.16.0, a Server-Side Request... |
| CVE-2026-35408 | CRITICAL | 9.3 | 0.2% | Apr 6, 2026 | Directus is a real-time API and App dashboard for managing SQL database content. Prior to 11.17.0, Directus's Single Sig... |
| CVE-2026-35404 | MEDIUM | 6.1 | 0.2% | Apr 6, 2026 | Open edX Platform enables the authoring and delivery of online learning at any scale. The view_survey endpoint accepts a... |
| CVE-2026-22675 | MEDIUM | 6.1 | 0.2% | Apr 6, 2026 | OCS Inventory NG Server version 2.12.3 and prior contain a stored cross-site scripting vulnerability that allows unauthe... |
| CVE-2026-5683 | HIGH | 8 | 0.6% | Apr 6, 2026 | A vulnerability was found in Tenda CX12L 16.03.53.12. Affected by this vulnerability is the function fromP2pListFilter o... |
| CVE-2026-35472 | MEDIUM | 6.1 | 0.2% | Apr 6, 2026 | WeGIA is a Web manager for charitable institutions. Prior to 3.6.9, an Open Redirect vulnerability was identified in the... |
| CVE-2026-35399 | MEDIUM | 6.1 | 0.3% | Apr 6, 2026 | WeGIA is a Web manager for charitable institutions. Prior to 3.6.9, a stored XSS vulnerability allows an attacker to inj... |
| CVE-2026-35398 | MEDIUM | 6.1 | 0.2% | Apr 6, 2026 | WeGIA is a Web manager for charitable institutions. Prior to 3.6.9, an Open Redirect vulnerability was identified in the... |
| CVE-2026-35396 | MEDIUM | 6.1 | 0.2% | Apr 6, 2026 | WeGIA is a Web manager for charitable institutions. Prior to 3.6.9, an Open Redirect vulnerability was identified in the... |
| CVE-2026-35395 | HIGH | 8.8 | 0.4% | Apr 6, 2026 | WeGIA is a Web manager for charitable institutions. Prior to 3.6.9, WeGIA (Web gerenciador para instituições assistencia... |
| CVE-2026-35394 | HIGH | 8.8 | 0.4% | Apr 6, 2026 | Mobile Next is an MCP server for mobile development and automation. Prior to 0.0.50, the mobile_open_url tool in mobile-... |
| CVE-2026-35393 | CRITICAL | 9.8 | 0.7% | Apr 6, 2026 | goshs is a SimpleHTTPServer written in Go. Prior to 2.0.0-beta.3, the POST multipart upload directory not sanitized. Thi... |
| CVE-2026-35392 | CRITICAL | 9.8 | 0.7% | Apr 6, 2026 | goshs is a SimpleHTTPServer written in Go. Prior to 2.0.0-beta.3, PUT upload in httpserver/updown.go has no path sanitiz... |
| CVE-2026-35391 | HIGH | 7.5 | 0.1% | Apr 6, 2026 | Bulwark Webmail is a self-hosted webmail client for Stalwart Mail Server. Prior to 1.4.11, the getClientIP() function in... |
| CVE-2026-35390 | MEDIUM | 5.4 | 0.2% | Apr 6, 2026 | Bulwark Webmail is a self-hosted webmail client for Stalwart Mail Server. Prior to 1.4.11, the reverse proxy (proxy.ts) ... |
| CVE-2026-35389 | HIGH | 7.5 | 0.2% | Apr 6, 2026 | Bulwark Webmail is a self-hosted webmail client for Stalwart Mail Server. Prior to 1.4.11, S/MIME signature verification... |
| CVE-2026-35213 | HIGH | 7.5 | 0.4% | Apr 6, 2026 | @hapi/content provided HTTP Content-* headers parsing. All versions of @hapi/content through 6.0.0 are vulnerable to Reg... |
| CVE-2026-35208 | MEDIUM | 5.4 | 0.3% | Apr 6, 2026 | lichess.org is the forever free, adless and open source chess server. Any approved streamer can inject arbitrary HTML in... |
| CVE-2026-34972 | HIGH | 8.8 | 0.2% | Apr 6, 2026 | OpenFGA is a high-performance and flexible authorization/permission engine built for developers and inspired by Google Z... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now