2026 CVE Vulnerabilities
66,381 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-34610 | MEDIUM | 5.9 | 0.2% | Apr 2, 2026 | The leancrypto library is a cryptographic library that exclusively contains only PQC-resistant cryptographic algorithms.... |
| CVE-2026-34608 | HIGH | 8.2 | 0.4% | Apr 2, 2026 | NanoMQ MQTT Broker (NanoMQ) is an all-around Edge Messaging Platform. Prior to version 0.24.10, in NanoMQ's webhook_inpr... |
| CVE-2026-34606 | MEDIUM | 6.1 | 0.2% | Apr 2, 2026 | Frappe Learning Management System (LMS) is a learning system that helps users structure their content. From version 2.27... |
| CVE-2026-34601 | HIGH | 7.5 | 0.5% | Apr 2, 2026 | xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) `DOMParser` and `XMLSerializer` module. In xmldom ... |
| CVE-2026-34598 | MEDIUM | 6.1 | 0.2% | Apr 2, 2026 | YesWiki is a wiki system written in PHP. Prior to version 4.6.0, a stored and blind XSS vulnerability exists in the form... |
| CVE-2026-34593 | HIGH | 7.5 | 0.4% | Apr 2, 2026 | Ash Framework is a declarative, extensible framework for building Elixir applications. Prior to version 3.22.0, Ash.Type... |
| CVE-2026-34591 | MEDIUM | 6.5 | 0.5% | Apr 2, 2026 | Poetry is a dependency manager for Python. From version 1.4.0 to before version 2.3.3, a crafted wheel can contain ../ p... |
| CVE-2026-34590 | MEDIUM | 5.4 | 0.2% | Apr 2, 2026 | Postiz is an AI social media scheduling tool. Prior to version 2.21.4, the POST /webhooks/ endpoint for creating webhook... |
| CVE-2026-34584 | MEDIUM | 5.4 | 0.2% | Apr 2, 2026 | listmonk is a standalone, self-hosted, newsletter and mailing list manager. From version 4.1.0 to before version 6.1.0, ... |
| CVE-2026-34577 | HIGH | 8.6 | 0.5% | Apr 2, 2026 | Postiz is an AI social media scheduling tool. Prior to version 2.21.3, the GET /public/stream endpoint in PublicControll... |
| CVE-2026-34576 | HIGH | 7.7 | 0.3% | Apr 2, 2026 | Postiz is an AI social media scheduling tool. Prior to version 2.21.3, the POST /public/v1/upload-from-url endpoint acce... |
| CVE-2026-34526 | MEDIUM | 5 | 0.2% | Apr 2, 2026 | SillyTavern is a locally installed user interface that allows users to interact with text generation large language mode... |
| CVE-2026-34524 | HIGH | 8.8 | 0.6% | Apr 2, 2026 | SillyTavern is a locally installed user interface that allows users to interact with text generation large language mode... |
| CVE-2026-34523 | MEDIUM | 5.3 | 0.4% | Apr 2, 2026 | SillyTavern is a locally installed user interface that allows users to interact with text generation large language mode... |
| CVE-2026-34522 | HIGH | 8.1 | 0.4% | Apr 2, 2026 | SillyTavern is a locally installed user interface that allows users to interact with text generation large language mode... |
| CVE-2026-34124 | MEDIUM | 6.5 | 0.3% | Apr 2, 2026 | A denial-of-service vulnerability was identified in TP-Link Tapo C520WS v2.6 within the HTTP request path parsing logic.... |
| CVE-2026-34122 | MEDIUM | 6.5 | 0.3% | Apr 2, 2026 | A stack-based buffer overflow vulnerability was identified in TP-Link Tapo C520WS v2.6 within a configuration handling c... |
| CVE-2026-34121 | HIGH | 8.8 | 0.4% | Apr 2, 2026 | An authentication bypass vulnerability within the HTTP handling of the DS configuration service in TP-Link Tapo C520WS v... |
| CVE-2026-34120 | MEDIUM | 6.5 | 0.2% | Apr 2, 2026 | A heap-based buffer overflow vulnerability was identified in TP-Link Tapo C520WS v2.6 within the asynchronous parsing of... |
| CVE-2026-34119 | MEDIUM | 6.5 | 0.2% | Apr 2, 2026 | A heap-based buffer overflow vulnerability was identified in TP-Link Tapo C520WS v2.6 within the HTTP parsing loop when ... |
| CVE-2026-34118 | MEDIUM | 6.5 | 0.3% | Apr 2, 2026 | A heap-based buffer overflow vulnerability was identified in TP-Link Tapo C100/C101 v5, C520WS v2.6 in the HTTP POST bod... |
| CVE-2026-33271 | MEDIUM | 6.7 | 0.1% | Apr 2, 2026 | Local privilege escalation due to insecure folder permissions. The following products are affected: Acronis True Image (... |
| CVE-2026-32762 | MEDIUM | 6.5 | 0.2% | Apr 2, 2026 | Rack is a modular Ruby web server interface. From versions 3.0.0.beta1 to before 3.1.21 and 3.2.0 to before 3.2.6, Rack:... |
| CVE-2026-28728 | MEDIUM | 6.7 | 0.1% | Apr 2, 2026 | Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis True Image (... |
| CVE-2026-27774 | MEDIUM | 6.7 | 0.1% | Apr 2, 2026 | Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis True Image (... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now