2026 CVE Vulnerabilities
50,972 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-34848 | MEDIUM | 5.4 | 0.1% | Apr 2, 2026 | hoppscotch is an open source API development ecosystem. Prior to version 2026.3.0, there is a stored XSS vulnerability i... |
| CVE-2026-34847 | MEDIUM | 6.1 | 0.4% | Apr 2, 2026 | hoppscotch is an open source API development ecosystem. Prior to version 2026.3.0, the /enter page contains a DOM-based ... |
| CVE-2026-34832 | MEDIUM | 6.5 | 0.3% | Apr 2, 2026 | Scoold is a Q&A and a knowledge sharing platform for teams. Prior to version 1.66.1, Scoold contains an authenticated au... |
| CVE-2026-34825 | MEDIUM | 6.5 | 0.4% | Apr 2, 2026 | NocoBase is an AI-powered no-code/low-code platform for building business applications and enterprise solutions. Prior t... |
| CVE-2026-34761 | MEDIUM | 6.5 | 0.3% | Apr 2, 2026 | Ella Core is a 5G core designed for private networks. Prior to version 1.8.0, Ella Core panics when processing a NGAP ha... |
| CVE-2026-5417 | MEDIUM | 4.7 | 0.2% | Apr 2, 2026 | A vulnerability was determined in Dataease SQLbot up to 1.6.0. This issue affects the function get_es_data_by_http of th... |
| CVE-2026-34743 | MEDIUM | 5.3 | 0.4% | Apr 2, 2026 | XZ Utils provide a general-purpose data-compression library plus command-line tools. Prior to version 5.8.3, if lzma_ind... |
| CVE-2026-34736 | MEDIUM | 5.3 | 0.2% | Apr 2, 2026 | Open edX Platform enables the authoring and delivery of online learning at any scale. From the maple release to before t... |
| CVE-2026-34730 | MEDIUM | 5.5 | 0.3% | Apr 2, 2026 | Copier is a library and CLI app for rendering project templates. Prior to version 9.14.1, Copier's _external_data featur... |
| CVE-2026-34726 | MEDIUM | 4.4 | 0.4% | Apr 2, 2026 | Copier is a library and CLI app for rendering project templates. Prior to version 9.14.1, Copier's _subdirectory setting... |
| CVE-2026-34425 | MEDIUM | 4.3 | 0.3% | Apr 2, 2026 | OpenClaw versions prior to commit 8aceaf5 contain a preflight validation bypass vulnerability in shell-bleed protection ... |
| CVE-2026-5414 | MEDIUM | 5.5 | 0.3% | Apr 2, 2026 | A security flaw has been discovered in Newgen OmniDocs up to 12.0.00. Affected by this issue is some unknown functionali... |
| CVE-2026-34835 | MEDIUM | 6.5 | 0.2% | Apr 2, 2026 | Rack is a modular Ruby web server interface. From versions 3.0.0.beta1 to before 3.1.21, and 3.2.0 to before 3.2.6, Rack... |
| CVE-2026-34715 | MEDIUM | 5.3 | 0.3% | Apr 2, 2026 | ewe is a Gleam web server. Prior to version 3.0.6, the encode_headers function in src/ewe/internal/encoder.gleam directl... |
| CVE-2026-34610 | MEDIUM | 5.9 | 0.2% | Apr 2, 2026 | The leancrypto library is a cryptographic library that exclusively contains only PQC-resistant cryptographic algorithms.... |
| CVE-2026-34606 | MEDIUM | 6.1 | 0.2% | Apr 2, 2026 | Frappe Learning Management System (LMS) is a learning system that helps users structure their content. From version 2.27... |
| CVE-2026-34598 | MEDIUM | 6.1 | 0.2% | Apr 2, 2026 | YesWiki is a wiki system written in PHP. Prior to version 4.6.0, a stored and blind XSS vulnerability exists in the form... |
| CVE-2026-34591 | MEDIUM | 6.5 | 0.5% | Apr 2, 2026 | Poetry is a dependency manager for Python. From version 1.4.0 to before version 2.3.3, a crafted wheel can contain ../ p... |
| CVE-2026-34590 | MEDIUM | 5.4 | 0.2% | Apr 2, 2026 | Postiz is an AI social media scheduling tool. Prior to version 2.21.4, the POST /webhooks/ endpoint for creating webhook... |
| CVE-2026-34584 | MEDIUM | 5.4 | 0.2% | Apr 2, 2026 | listmonk is a standalone, self-hosted, newsletter and mailing list manager. From version 4.1.0 to before version 6.1.0, ... |
| CVE-2026-34526 | MEDIUM | 5 | 0.2% | Apr 2, 2026 | SillyTavern is a locally installed user interface that allows users to interact with text generation large language mode... |
| CVE-2026-34523 | MEDIUM | 5.3 | 0.4% | Apr 2, 2026 | SillyTavern is a locally installed user interface that allows users to interact with text generation large language mode... |
| CVE-2026-34124 | MEDIUM | 6.5 | 0.3% | Apr 2, 2026 | A denial-of-service vulnerability was identified in TP-Link Tapo C520WS v2.6 within the HTTP request path parsing logic.... |
| CVE-2026-34122 | MEDIUM | 6.5 | 0.3% | Apr 2, 2026 | A stack-based buffer overflow vulnerability was identified in TP-Link Tapo C520WS v2.6 within a configuration handling c... |
| CVE-2026-34120 | MEDIUM | 6.5 | 0.2% | Apr 2, 2026 | A heap-based buffer overflow vulnerability was identified in TP-Link Tapo C520WS v2.6 within the asynchronous parsing of... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now