2026 CVE Vulnerabilities
50,909 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-34985 | MEDIUM | 6.5 | 0.2% | Apr 8, 2026 | LORIS (Longitudinal Online Research and Imaging System) is a self-hosted web application that provides data- and project... |
| CVE-2026-34837 | MEDIUM | 4.3 | 0.2% | Apr 8, 2026 | Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.1, he REST endpoint POST /api/v1/ai_ass... |
| CVE-2026-34782 | MEDIUM | 4.3 | 0.2% | Apr 8, 2026 | Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.1 and 6.5.4, the REST endpoint POST /ap... |
| CVE-2026-34722 | MEDIUM | 4.3 | 0.2% | Apr 8, 2026 | Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.1 and 6.5.4, the used endpoint for tick... |
| CVE-2026-34721 | MEDIUM | 6.5 | 0.1% | Apr 8, 2026 | Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.1 and 6.5.4, the OAuth callback endpoin... |
| CVE-2026-34720 | MEDIUM | 4.3 | 0.1% | Apr 8, 2026 | Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.1 and 6.5.4, the SSO mechanism in Zamma... |
| CVE-2026-34719 | MEDIUM | 4.3 | 0.2% | Apr 8, 2026 | Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.1 and 6.5.4, the webhook model was miss... |
| CVE-2026-34718 | MEDIUM | 6.1 | 0.1% | Apr 8, 2026 | Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.1 and 6.5.4, the HTML sanitizer for tic... |
| CVE-2026-34248 | MEDIUM | 5.7 | 0.2% | Apr 8, 2026 | Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.1, customers in shared organizations (m... |
| CVE-2026-34166 | MEDIUM | 5.3 | 0.5% | Apr 8, 2026 | LiquidJS is a Shopify / GitHub Pages compatible template engine in pure JavaScript. Prior to 10.25.3, the replace filter... |
| CVE-2026-30817 | MEDIUM | 5.7 | 0.3% | Apr 8, 2026 | An external configuration control vulnerability in the OpenVPN module of TP-Link AX53 v1.0 allows an authenticated adjac... |
| CVE-2026-30816 | MEDIUM | 5.7 | 0.3% | Apr 8, 2026 | An external control of configuration vulnerability in the OpenVPN module of TP-Link AX53 v1.0 allows an authenticated ad... |
| CVE-2026-20709 | MEDIUM | 6.6 | 0.1% | Apr 8, 2026 | Use of Default Cryptographic Key in the hardware for some Intel(R) Pentium(R) Processor Silver Series, Intel(R) Celeron(... |
| CVE-2026-0814 | MEDIUM | 4.3 | 0.3% | Apr 8, 2026 | The Advanced Contact form 7 DB plugin for WordPress is vulnerable to unauthorized access of data due to a missing capabi... |
| CVE-2026-0811 | MEDIUM | 5.4 | 0.1% | Apr 8, 2026 | The Advanced Contact form 7 DB plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, a... |
| CVE-2026-33459 | MEDIUM | 6.5 | 0.2% | Apr 8, 2026 | Uncontrolled Resource Consumption (CWE-400) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130)... |
| CVE-2026-32591 | MEDIUM | 5.5 | 0.3% | Apr 8, 2026 | A flaw was found in Red Hat Quay's Proxy Cache configuration feature. When an organization administrator configures an u... |
| CVE-2026-33461 | MEDIUM | 6.5 | 0.3% | Apr 8, 2026 | Incorrect Authorization (CWE-863) in Kibana can lead to information disclosure via Privilege Abuse (CAPEC-122). A user w... |
| CVE-2026-33460 | MEDIUM | 4.3 | 0.2% | Apr 8, 2026 | Incorrect Authorization (CWE-863) in Kibana can lead to cross-space information disclosure via Privilege Abuse (CAPEC-12... |
| CVE-2026-2377 | MEDIUM | 6.5 | 0.4% | Apr 8, 2026 | A flaw was found in Red Hat Quay and mirror registry for Red Hat OpenShift. The log export feature in these products all... |
| CVE-2026-39865 | MEDIUM | 5.9 | 0.7% | Apr 8, 2026 | Axios is a promise based HTTP client for the browser and Node.js. Starting in version 1.13.0 and prior to 1.13.2, Axios ... |
| CVE-2026-39410 | MEDIUM | 4.8 | 0.3% | Apr 8, 2026 | Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.12, a discrepancy be... |
| CVE-2026-39409 | MEDIUM | 5.3 | 0.3% | Apr 8, 2026 | Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.12, ipRestriction() ... |
| CVE-2026-39407 | MEDIUM | 5.3 | 0.5% | Apr 8, 2026 | Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.12, a path handling ... |
| CVE-2026-39406 | MEDIUM | 5.3 | 0.4% | Apr 8, 2026 | @hono/node-server allows running the Hono application on Node.js. Prior to 1.19.13, a path handling inconsistency in ser... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now