2026 CVE Vulnerabilities

66,373 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-35383MEDIUM6.9Bentley Systems iTwin Platform exposed a Cesium ion access token in the source of some web pages. An unauthenticated att...
CVE-2026-35053CRITICAL9.8OneUptime is an open-source monitoring and observability platform. Prior to version 10.0.42, the Worker service's Manual...
CVE-2026-34932CRITICAL9.3hoppscotch is an open source API development ecosystem. Prior to version 2026.3.0, there is a stored XSS vulnerability t...
CVE-2026-34931CRITICAL9.6hoppscotch is an open source API development ecosystem. Prior to version 2026.3.0, there is an open redirect vulnerabili...
CVE-2026-34848MEDIUM5.4hoppscotch is an open source API development ecosystem. Prior to version 2026.3.0, there is a stored XSS vulnerability i...
CVE-2026-34847MEDIUM6.1hoppscotch is an open source API development ecosystem. Prior to version 2026.3.0, the /enter page contains a DOM-based ...
CVE-2026-34840HIGH8.1OneUptime is an open-source monitoring and observability platform. Prior to version 10.0.42, OneUptime's SAML SSO implem...
CVE-2026-34838CRITICAL9.9Group-Office is an enterprise customer relationship management and groupware tool. Prior to versions 6.8.156, 25.0.90, a...
CVE-2026-34834HIGH7.5Bulwark Webmail is a self-hosted webmail client for Stalwart Mail Server. Prior to version 1.4.10, the verifyIdentity() ...
CVE-2026-34833HIGH7.5Bulwark Webmail is a self-hosted webmail client for Stalwart Mail Server. Prior to version 1.4.10, the GET /api/auth/ses...
CVE-2026-34832MEDIUM6.5Scoold is a Q&A and a knowledge sharing platform for teams. Prior to version 1.66.1, Scoold contains an authenticated au...
CVE-2026-34825MEDIUM6.5NocoBase is an AI-powered no-code/low-code platform for building business applications and enterprise solutions. Prior t...
CVE-2026-34762LOW2.7Ella Core is a 5G core designed for private networks. Prior to version 1.8.0, the PUT /api/v1/subscriber/{imsi} API acce...
CVE-2026-34761MEDIUM6.5Ella Core is a 5G core designed for private networks. Prior to version 1.8.0, Ella Core panics when processing a NGAP ha...
CVE-2026-34760HIGH7.1vLLM is an inference and serving engine for large language models (LLMs). From version 0.5.5 to before version 0.18.0, L...
CVE-2026-5429HIGH7.8Unsanitized input during web page generation in the Kiro Agent webview in Kiro IDE before version 0.8.140 allows a remot...
CVE-2026-5418HIGH7.3A vulnerability was identified in appsmithorg appsmith up to 1.97. Impacted is the function computeDisallowedHosts of th...
CVE-2026-5417MEDIUM4.7A vulnerability was determined in Dataease SQLbot up to 1.6.0. This issue affects the function get_es_data_by_http of th...
CVE-2026-34759HIGH8.1OneUptime is an open-source monitoring and observability platform. Prior to version 10.0.42, multiple notification API e...
CVE-2026-34758CRITICAL9.1OneUptime is an open-source monitoring and observability platform. Prior to version 10.0.42, unauthenticated access to N...
CVE-2026-34752HIGH7.5Haraka is a Node.js mail server. Prior to version 3.1.4, sending an email with __proto__: as a header name crashes the H...
CVE-2026-34745CRITICAL9.1Fireshare facilitates self-hosted media and link sharing. Prior to version 1.5.3, the fix for CVE-2026-33645 was applied...
CVE-2026-34743MEDIUM5.3XZ Utils provide a general-purpose data-compression library plus command-line tools. Prior to version 5.8.3, if lzma_ind...
CVE-2026-34742HIGH8.1The Go MCP SDK used Go's standard encoding/json. Prior to version 1.4.0, the Model Context Protocol (MCP) Go SDK does no...
CVE-2026-34736MEDIUM5.3Open edX Platform enables the authoring and delivery of online learning at any scale. From the maple release to before t...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now