2026 CVE Vulnerabilities

50,972 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-34848MEDIUM5.4hoppscotch is an open source API development ecosystem. Prior to version 2026.3.0, there is a stored XSS vulnerability i...
CVE-2026-34847MEDIUM6.1hoppscotch is an open source API development ecosystem. Prior to version 2026.3.0, the /enter page contains a DOM-based ...
CVE-2026-34832MEDIUM6.5Scoold is a Q&A and a knowledge sharing platform for teams. Prior to version 1.66.1, Scoold contains an authenticated au...
CVE-2026-34825MEDIUM6.5NocoBase is an AI-powered no-code/low-code platform for building business applications and enterprise solutions. Prior t...
CVE-2026-34761MEDIUM6.5Ella Core is a 5G core designed for private networks. Prior to version 1.8.0, Ella Core panics when processing a NGAP ha...
CVE-2026-5417MEDIUM4.7A vulnerability was determined in Dataease SQLbot up to 1.6.0. This issue affects the function get_es_data_by_http of th...
CVE-2026-34743MEDIUM5.3XZ Utils provide a general-purpose data-compression library plus command-line tools. Prior to version 5.8.3, if lzma_ind...
CVE-2026-34736MEDIUM5.3Open edX Platform enables the authoring and delivery of online learning at any scale. From the maple release to before t...
CVE-2026-34730MEDIUM5.5Copier is a library and CLI app for rendering project templates. Prior to version 9.14.1, Copier's _external_data featur...
CVE-2026-34726MEDIUM4.4Copier is a library and CLI app for rendering project templates. Prior to version 9.14.1, Copier's _subdirectory setting...
CVE-2026-34425MEDIUM4.3OpenClaw versions prior to commit 8aceaf5 contain a preflight validation bypass vulnerability in shell-bleed protection ...
CVE-2026-5414MEDIUM5.5A security flaw has been discovered in Newgen OmniDocs up to 12.0.00. Affected by this issue is some unknown functionali...
CVE-2026-34835MEDIUM6.5Rack is a modular Ruby web server interface. From versions 3.0.0.beta1 to before 3.1.21, and 3.2.0 to before 3.2.6, Rack...
CVE-2026-34715MEDIUM5.3ewe is a Gleam web server. Prior to version 3.0.6, the encode_headers function in src/ewe/internal/encoder.gleam directl...
CVE-2026-34610MEDIUM5.9The leancrypto library is a cryptographic library that exclusively contains only PQC-resistant cryptographic algorithms....
CVE-2026-34606MEDIUM6.1Frappe Learning Management System (LMS) is a learning system that helps users structure their content. From version 2.27...
CVE-2026-34598MEDIUM6.1YesWiki is a wiki system written in PHP. Prior to version 4.6.0, a stored and blind XSS vulnerability exists in the form...
CVE-2026-34591MEDIUM6.5Poetry is a dependency manager for Python. From version 1.4.0 to before version 2.3.3, a crafted wheel can contain ../ p...
CVE-2026-34590MEDIUM5.4Postiz is an AI social media scheduling tool. Prior to version 2.21.4, the POST /webhooks/ endpoint for creating webhook...
CVE-2026-34584MEDIUM5.4listmonk is a standalone, self-hosted, newsletter and mailing list manager. From version 4.1.0 to before version 6.1.0, ...
CVE-2026-34526MEDIUM5SillyTavern is a locally installed user interface that allows users to interact with text generation large language mode...
CVE-2026-34523MEDIUM5.3SillyTavern is a locally installed user interface that allows users to interact with text generation large language mode...
CVE-2026-34124MEDIUM6.5A denial-of-service vulnerability was identified in TP-Link Tapo C520WS v2.6 within the HTTP request path parsing logic....
CVE-2026-34122MEDIUM6.5A stack-based buffer overflow vulnerability was identified in TP-Link Tapo C520WS v2.6 within a configuration handling c...
CVE-2026-34120MEDIUM6.5A heap-based buffer overflow vulnerability was identified in TP-Link Tapo C520WS v2.6 within the asynchronous parsing of...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now