2026 CVE Vulnerabilities
50,939 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-35398 | MEDIUM | 6.1 | 0.2% | Apr 6, 2026 | WeGIA is a Web manager for charitable institutions. Prior to 3.6.9, an Open Redirect vulnerability was identified in the... |
| CVE-2026-35396 | MEDIUM | 6.1 | 0.2% | Apr 6, 2026 | WeGIA is a Web manager for charitable institutions. Prior to 3.6.9, an Open Redirect vulnerability was identified in the... |
| CVE-2026-35390 | MEDIUM | 5.4 | 0.2% | Apr 6, 2026 | Bulwark Webmail is a self-hosted webmail client for Stalwart Mail Server. Prior to 1.4.11, the reverse proxy (proxy.ts) ... |
| CVE-2026-35208 | MEDIUM | 5.4 | 0.3% | Apr 6, 2026 | lichess.org is the forever free, adless and open source chess server. Any approved streamer can inject arbitrary HTML in... |
| CVE-2026-5681 | MEDIUM | 6.3 | 0.2% | Apr 6, 2026 | A flaw has been found in itsourcecode sanitize or validate this input 1.0. This impacts an unknown function of the file ... |
| CVE-2026-5679 | MEDIUM | 5.5 | 1.7% | Apr 6, 2026 | A security vulnerability has been detected in Totolink A3300R 17.0.0cu.557_B20221024. The impacted element is the functi... |
| CVE-2026-35201 | MEDIUM | 5.9 | 0.3% | Apr 6, 2026 | Discount is an implementation of John Gruber's Markdown markup language in C. From 1.3.1.1 to before 2.2.7.4, a signed l... |
| CVE-2026-35200 | MEDIUM | 5.4 | 0.2% | Apr 6, 2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 8.6.73 ... |
| CVE-2026-35199 | MEDIUM | 6.1 | 0.3% | Apr 6, 2026 | SymCrypt is the core cryptographic function library currently used by Windows. From 103.5.0 to before 103.11.0, The SymC... |
| CVE-2026-35183 | MEDIUM | 5.4 | 0.2% | Apr 6, 2026 | Brave CMS is an open-source CMS. Prior to 2.0.6, an Insecure Direct Object Reference (IDOR) vulnerability exists in the ... |
| CVE-2026-35181 | MEDIUM | 4.3 | 0.1% | Apr 6, 2026 | WWBN AVideo is an open source video platform. In versions 26.0 and prior, the player skin configuration endpoint at admi... |
| CVE-2026-35180 | MEDIUM | 4.3 | 0.1% | Apr 6, 2026 | WWBN AVideo is an open source video platform. In versions 26.0 and prior, the site customization endpoint at admin/custo... |
| CVE-2026-35179 | MEDIUM | 5.3 | 0.2% | Apr 6, 2026 | WWBN AVideo is an open source video platform. In versions 26.0 and prior, the SocialMediaPublisher plugin exposes a publ... |
| CVE-2026-0049 | MEDIUM | 6.2 | 0.1% | Apr 6, 2026 | In onHeaderDecoded of LocalImageResolver.java, there is a possible persistent denial of service due to resource exhausti... |
| CVE-2026-5675 | MEDIUM | 6.3 | 0.2% | Apr 6, 2026 | A vulnerability was found in itsourcecode Construction Management System 1.0. This affects an unknown part of the file /... |
| CVE-2026-5671 | MEDIUM | 4.3 | 0.3% | Apr 6, 2026 | A vulnerability was determined in Cyber-III Student-Management-System up to 1a938fa61e9f735078e9b291d2e6215b4942af3f. Im... |
| CVE-2026-35175 | MEDIUM | 6.5 | 0.3% | Apr 6, 2026 | Ajenti is a Linux and BSD modular server admin panel. Prior to 2.2.15, an authenticated user (using the auth_users plugi... |
| CVE-2026-35173 | MEDIUM | 6.5 | 0.2% | Apr 6, 2026 | Chyrp Lite is an ultra-lightweight blogging engine. Prior to 2026.01, an IDOR / Mass Assignment issue exists in the Post... |
| CVE-2026-35166 | MEDIUM | 5.4 | 0.2% | Apr 6, 2026 | Hugo is a static site generator. From 0.60.0 to before 0.159.2, links and image links in the default markdown to HTML re... |
| CVE-2026-35046 | MEDIUM | 5.4 | 0.2% | Apr 6, 2026 | Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. Prior to 2.6.4, Tan... |
| CVE-2026-30613 | MEDIUM | 4.6 | 0.2% | Apr 6, 2026 | An information disclosure vulnerability exists in AZIOT 1 Node Smart Switch (16amp)- WiFi/Bluetooth Enabled Software Ver... |
| CVE-2026-5670 | MEDIUM | 6.3 | 0.2% | Apr 6, 2026 | A vulnerability was found in Cyber-III Student-Management-System up to 1a938fa61e9f735078e9b291d2e6215b4942af3f. This is... |
| CVE-2026-34981 | MEDIUM | 5.8 | 0.3% | Apr 6, 2026 | The whisperX API is a tool for enhancing and analyzing audio content. From 0.3.1 to 0.5.0, FileService.download_from_url... |
| CVE-2026-34975 | MEDIUM | 4.3 | 0.2% | Apr 6, 2026 | Plunk is an open-source email platform built on top of AWS SES. Prior to 0.8.0, a CRLF header injection vulnerability wa... |
| CVE-2026-31313 | MEDIUM | 5.4 | 0.1% | Apr 6, 2026 | An authenticated stored cross-site scripting (XSS) vulnerability in the creation/editing module of Feehi CMS v2.1.1 allo... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now