2026 CVE Vulnerabilities
66,373 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-35383 | MEDIUM | 6.9 | 0.3% | Apr 2, 2026 | Bentley Systems iTwin Platform exposed a Cesium ion access token in the source of some web pages. An unauthenticated att... |
| CVE-2026-35053 | CRITICAL | 9.8 | 0.5% | Apr 2, 2026 | OneUptime is an open-source monitoring and observability platform. Prior to version 10.0.42, the Worker service's Manual... |
| CVE-2026-34932 | CRITICAL | 9.3 | 0.3% | Apr 2, 2026 | hoppscotch is an open source API development ecosystem. Prior to version 2026.3.0, there is a stored XSS vulnerability t... |
| CVE-2026-34931 | CRITICAL | 9.6 | 0.4% | Apr 2, 2026 | hoppscotch is an open source API development ecosystem. Prior to version 2026.3.0, there is an open redirect vulnerabili... |
| CVE-2026-34848 | MEDIUM | 5.4 | 0.1% | Apr 2, 2026 | hoppscotch is an open source API development ecosystem. Prior to version 2026.3.0, there is a stored XSS vulnerability i... |
| CVE-2026-34847 | MEDIUM | 6.1 | 0.4% | Apr 2, 2026 | hoppscotch is an open source API development ecosystem. Prior to version 2026.3.0, the /enter page contains a DOM-based ... |
| CVE-2026-34840 | HIGH | 8.1 | 0.3% | Apr 2, 2026 | OneUptime is an open-source monitoring and observability platform. Prior to version 10.0.42, OneUptime's SAML SSO implem... |
| CVE-2026-34838 | CRITICAL | 9.9 | 1.0% | Apr 2, 2026 | Group-Office is an enterprise customer relationship management and groupware tool. Prior to versions 6.8.156, 25.0.90, a... |
| CVE-2026-34834 | HIGH | 7.5 | 0.3% | Apr 2, 2026 | Bulwark Webmail is a self-hosted webmail client for Stalwart Mail Server. Prior to version 1.4.10, the verifyIdentity() ... |
| CVE-2026-34833 | HIGH | 7.5 | 0.2% | Apr 2, 2026 | Bulwark Webmail is a self-hosted webmail client for Stalwart Mail Server. Prior to version 1.4.10, the GET /api/auth/ses... |
| CVE-2026-34832 | MEDIUM | 6.5 | 0.3% | Apr 2, 2026 | Scoold is a Q&A and a knowledge sharing platform for teams. Prior to version 1.66.1, Scoold contains an authenticated au... |
| CVE-2026-34825 | MEDIUM | 6.5 | 0.4% | Apr 2, 2026 | NocoBase is an AI-powered no-code/low-code platform for building business applications and enterprise solutions. Prior t... |
| CVE-2026-34762 | LOW | 2.7 | 0.2% | Apr 2, 2026 | Ella Core is a 5G core designed for private networks. Prior to version 1.8.0, the PUT /api/v1/subscriber/{imsi} API acce... |
| CVE-2026-34761 | MEDIUM | 6.5 | 0.3% | Apr 2, 2026 | Ella Core is a 5G core designed for private networks. Prior to version 1.8.0, Ella Core panics when processing a NGAP ha... |
| CVE-2026-34760 | HIGH | 7.1 | 0.3% | Apr 2, 2026 | vLLM is an inference and serving engine for large language models (LLMs). From version 0.5.5 to before version 0.18.0, L... |
| CVE-2026-5429 | HIGH | 7.8 | 0.2% | Apr 2, 2026 | Unsanitized input during web page generation in the Kiro Agent webview in Kiro IDE before version 0.8.140 allows a remot... |
| CVE-2026-5418 | HIGH | 7.3 | 0.3% | Apr 2, 2026 | A vulnerability was identified in appsmithorg appsmith up to 1.97. Impacted is the function computeDisallowedHosts of th... |
| CVE-2026-5417 | MEDIUM | 4.7 | 0.2% | Apr 2, 2026 | A vulnerability was determined in Dataease SQLbot up to 1.6.0. This issue affects the function get_es_data_by_http of th... |
| CVE-2026-34759 | HIGH | 8.1 | 0.6% | Apr 2, 2026 | OneUptime is an open-source monitoring and observability platform. Prior to version 10.0.42, multiple notification API e... |
| CVE-2026-34758 | CRITICAL | 9.1 | 0.3% | Apr 2, 2026 | OneUptime is an open-source monitoring and observability platform. Prior to version 10.0.42, unauthenticated access to N... |
| CVE-2026-34752 | HIGH | 7.5 | 0.4% | Apr 2, 2026 | Haraka is a Node.js mail server. Prior to version 3.1.4, sending an email with __proto__: as a header name crashes the H... |
| CVE-2026-34745 | CRITICAL | 9.1 | 0.6% | Apr 2, 2026 | Fireshare facilitates self-hosted media and link sharing. Prior to version 1.5.3, the fix for CVE-2026-33645 was applied... |
| CVE-2026-34743 | MEDIUM | 5.3 | 0.4% | Apr 2, 2026 | XZ Utils provide a general-purpose data-compression library plus command-line tools. Prior to version 5.8.3, if lzma_ind... |
| CVE-2026-34742 | HIGH | 8.1 | 0.5% | Apr 2, 2026 | The Go MCP SDK used Go's standard encoding/json. Prior to version 1.4.0, the Model Context Protocol (MCP) Go SDK does no... |
| CVE-2026-34736 | MEDIUM | 5.3 | 0.2% | Apr 2, 2026 | Open edX Platform enables the authoring and delivery of online learning at any scale. From the maple release to before t... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now