2026 CVE Vulnerabilities

66,381 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-34610MEDIUM5.9The leancrypto library is a cryptographic library that exclusively contains only PQC-resistant cryptographic algorithms....
CVE-2026-34608HIGH8.2NanoMQ MQTT Broker (NanoMQ) is an all-around Edge Messaging Platform. Prior to version 0.24.10, in NanoMQ's webhook_inpr...
CVE-2026-34606MEDIUM6.1Frappe Learning Management System (LMS) is a learning system that helps users structure their content. From version 2.27...
CVE-2026-34601HIGH7.5xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) `DOMParser` and `XMLSerializer` module. In xmldom ...
CVE-2026-34598MEDIUM6.1YesWiki is a wiki system written in PHP. Prior to version 4.6.0, a stored and blind XSS vulnerability exists in the form...
CVE-2026-34593HIGH7.5Ash Framework is a declarative, extensible framework for building Elixir applications. Prior to version 3.22.0, Ash.Type...
CVE-2026-34591MEDIUM6.5Poetry is a dependency manager for Python. From version 1.4.0 to before version 2.3.3, a crafted wheel can contain ../ p...
CVE-2026-34590MEDIUM5.4Postiz is an AI social media scheduling tool. Prior to version 2.21.4, the POST /webhooks/ endpoint for creating webhook...
CVE-2026-34584MEDIUM5.4listmonk is a standalone, self-hosted, newsletter and mailing list manager. From version 4.1.0 to before version 6.1.0, ...
CVE-2026-34577HIGH8.6Postiz is an AI social media scheduling tool. Prior to version 2.21.3, the GET /public/stream endpoint in PublicControll...
CVE-2026-34576HIGH7.7Postiz is an AI social media scheduling tool. Prior to version 2.21.3, the POST /public/v1/upload-from-url endpoint acce...
CVE-2026-34526MEDIUM5SillyTavern is a locally installed user interface that allows users to interact with text generation large language mode...
CVE-2026-34524HIGH8.8SillyTavern is a locally installed user interface that allows users to interact with text generation large language mode...
CVE-2026-34523MEDIUM5.3SillyTavern is a locally installed user interface that allows users to interact with text generation large language mode...
CVE-2026-34522HIGH8.1SillyTavern is a locally installed user interface that allows users to interact with text generation large language mode...
CVE-2026-34124MEDIUM6.5A denial-of-service vulnerability was identified in TP-Link Tapo C520WS v2.6 within the HTTP request path parsing logic....
CVE-2026-34122MEDIUM6.5A stack-based buffer overflow vulnerability was identified in TP-Link Tapo C520WS v2.6 within a configuration handling c...
CVE-2026-34121HIGH8.8An authentication bypass vulnerability within the HTTP handling of the DS configuration service in TP-Link Tapo C520WS v...
CVE-2026-34120MEDIUM6.5A heap-based buffer overflow vulnerability was identified in TP-Link Tapo C520WS v2.6 within the asynchronous parsing of...
CVE-2026-34119MEDIUM6.5A heap-based buffer overflow vulnerability was identified in TP-Link Tapo C520WS v2.6 within the HTTP parsing loop when ...
CVE-2026-34118MEDIUM6.5A heap-based buffer overflow vulnerability was identified in TP-Link Tapo C100/C101 v5, C520WS v2.6 in the HTTP POST bod...
CVE-2026-33271MEDIUM6.7Local privilege escalation due to insecure folder permissions. The following products are affected: Acronis True Image (...
CVE-2026-32762MEDIUM6.5Rack is a modular Ruby web server interface. From versions 3.0.0.beta1 to before 3.1.21 and 3.2.0 to before 3.2.6, Rack:...
CVE-2026-28728MEDIUM6.7Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis True Image (...
CVE-2026-27774MEDIUM6.7Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis True Image (...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now