2026 CVE Vulnerabilities

66,373 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-34735HIGH8.7The Hytale Modding Wiki is a free service for Hytale mods to host their documentation & wikis. In version 1.2.0 and prio...
CVE-2026-34730MEDIUM5.5Copier is a library and CLI app for rendering project templates. Prior to version 9.14.1, Copier's _external_data featur...
CVE-2026-34726MEDIUM4.4Copier is a library and CLI app for rendering project templates. Prior to version 9.14.1, Copier's _subdirectory setting...
CVE-2026-34581HIGH8.1goshs is a SimpleHTTPServer written in Go. From version 1.1.0 to before version 2.0.0-beta.2, when using the Share Token...
CVE-2026-34426HIGH7.3OpenClaw versions prior to commit b57b680 contain an approval bypass vulnerability due to inconsistent environment varia...
CVE-2026-34425MEDIUM4.3OpenClaw versions prior to commit 8aceaf5 contain a preflight validation bypass vulnerability in shell-bleed protection ...
CVE-2026-5414MEDIUM5.5A security flaw has been discovered in Newgen OmniDocs up to 12.0.00. Affected by this issue is some unknown functionali...
CVE-2026-5413LOW3.7A vulnerability was identified in Newgen OmniDocs up to 12.0.00. Affected by this vulnerability is an unknown functional...
CVE-2026-5370LOW3.5A vulnerability was identified in krayin laravel-crm up to 2.2. Impacted is the function composeMail of the file package...
CVE-2026-5368CRITICAL9.8A vulnerability was determined in projectworlds Car Rental Project 1.0. The affected element is an unknown function of t...
CVE-2026-35414HIGH8.1OpenSSH before 10.3 mishandles the authorized_keys principals option in uncommon scenarios involving a principals list i...
CVE-2026-34835MEDIUM6.5Rack is a modular Ruby web server interface. From versions 3.0.0.beta1 to before 3.1.21, and 3.2.0 to before 3.2.6, Rack...
CVE-2026-34828HIGH7.1listmonk is a standalone, self-hosted, newsletter and mailing list manager. From version 4.1.0 to before version 6.1.0, ...
CVE-2026-34827HIGH7.5Rack is a modular Ruby web server interface. From versions 3.0.0.beta1 to before 3.1.21, and 3.2.0 to before 3.2.6, Rack...
CVE-2026-34725HIGH8.2DbGate is cross-platform database manager. From version 7.0.0 to before version 7.1.5, a stored XSS vulnerability exists...
CVE-2026-34717HIGH8.1OpenProject is an open-source, web-based project management software. Prior to version 17.2.3, the =n operator in module...
CVE-2026-34715MEDIUM5.3ewe is a Gleam web server. Prior to version 3.0.6, the encode_headers function in src/ewe/internal/encoder.gleam directl...
CVE-2026-34610MEDIUM5.9The leancrypto library is a cryptographic library that exclusively contains only PQC-resistant cryptographic algorithms....
CVE-2026-34608HIGH8.2NanoMQ MQTT Broker (NanoMQ) is an all-around Edge Messaging Platform. Prior to version 0.24.10, in NanoMQ's webhook_inpr...
CVE-2026-34606MEDIUM6.1Frappe Learning Management System (LMS) is a learning system that helps users structure their content. From version 2.27...
CVE-2026-34601HIGH7.5xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) `DOMParser` and `XMLSerializer` module. In xmldom ...
CVE-2026-34598MEDIUM6.1YesWiki is a wiki system written in PHP. Prior to version 4.6.0, a stored and blind XSS vulnerability exists in the form...
CVE-2026-34593HIGH7.5Ash Framework is a declarative, extensible framework for building Elixir applications. Prior to version 3.22.0, Ash.Type...
CVE-2026-34591MEDIUM6.5Poetry is a dependency manager for Python. From version 1.4.0 to before version 2.3.3, a crafted wheel can contain ../ p...
CVE-2026-34590MEDIUM5.4Postiz is an AI social media scheduling tool. Prior to version 2.21.4, the POST /webhooks/ endpoint for creating webhook...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now