2026 CVE Vulnerabilities
50,973 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-34120 | MEDIUM | 6.5 | 0.2% | Apr 2, 2026 | A heap-based buffer overflow vulnerability was identified in TP-Link Tapo C520WS v2.6 within the asynchronous parsing of... |
| CVE-2026-34119 | MEDIUM | 6.5 | 0.2% | Apr 2, 2026 | A heap-based buffer overflow vulnerability was identified in TP-Link Tapo C520WS v2.6 within the HTTP parsing loop when ... |
| CVE-2026-34118 | MEDIUM | 6.5 | 0.3% | Apr 2, 2026 | A heap-based buffer overflow vulnerability was identified in TP-Link Tapo C100/C101 v5, C520WS v2.6 in the HTTP POST bod... |
| CVE-2026-33271 | MEDIUM | 6.7 | 0.1% | Apr 2, 2026 | Local privilege escalation due to insecure folder permissions. The following products are affected: Acronis True Image (... |
| CVE-2026-32762 | MEDIUM | 6.5 | 0.2% | Apr 2, 2026 | Rack is a modular Ruby web server interface. From versions 3.0.0.beta1 to before 3.1.21 and 3.2.0 to before 3.2.6, Rack:... |
| CVE-2026-28728 | MEDIUM | 6.7 | 0.1% | Apr 2, 2026 | Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis True Image (... |
| CVE-2026-27774 | MEDIUM | 6.7 | 0.1% | Apr 2, 2026 | Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis True Image (... |
| CVE-2026-26962 | MEDIUM | 6.5 | 0.2% | Apr 2, 2026 | Rack is a modular Ruby web server interface. From version 3.2.0 to before version 3.2.6, Rack::Multipart::Parser unfolds... |
| CVE-2026-35387 | MEDIUM | 6.5 | 0.2% | Apr 2, 2026 | OpenSSH before 10.3 can use unintended ECDSA algorithms. Listing of any ECDSA algorithm in PubkeyAcceptedAlgorithms or H... |
| CVE-2026-35038 | MEDIUM | 6.5 | 0.3% | Apr 2, 2026 | Signal K Server is a server application that runs on a central hub in a boat. Prior to version 2.24.0, there is an arbit... |
| CVE-2026-34831 | MEDIUM | 6.5 | 0.1% | Apr 2, 2026 | Rack is a modular Ruby web server interface. Prior to versions 2.2.23, 3.1.21, and 3.2.6, Rack::Files#fail sets the Cont... |
| CVE-2026-34786 | MEDIUM | 5.3 | 0.2% | Apr 2, 2026 | Rack is a modular Ruby web server interface. Prior to versions 2.2.23, 3.1.21, and 3.2.6, Rack::Static#applicable_rules ... |
| CVE-2026-34763 | MEDIUM | 5.3 | 0.2% | Apr 2, 2026 | Rack is a modular Ruby web server interface. Prior to versions 2.2.23, 3.1.21, and 3.2.6, Rack::Directory interpolates t... |
| CVE-2026-34083 | MEDIUM | 6.1 | 0.1% | Apr 2, 2026 | Signal K Server is a server application that runs on a central hub in a boat. Prior to version 2.24.0, SignalK Server co... |
| CVE-2026-30603 | MEDIUM | 6.8 | 0.1% | Apr 2, 2026 | An issue in the firmware update mechanism of Qianniao QN-L23PA0904 v20250721.1640 allows attackers to gain root access, ... |
| CVE-2026-26961 | MEDIUM | 5.3 | 0.3% | Apr 2, 2026 | Rack is a modular Ruby web server interface. Prior to versions 2.2.23, 3.1.21, and 3.2.6, Rack::Multipart::Parser extrac... |
| CVE-2026-26895 | MEDIUM | 5.3 | 0.3% | Apr 2, 2026 | User enumeration vulnerability in /pwreset.php in osTicket v1.18.2 allows remote attackers to enumerate valid usernames ... |
| CVE-2026-5344 | MEDIUM | 6.3 | 0.3% | Apr 2, 2026 | A security vulnerability has been detected in Textpattern up to 4.9.1. Affected by this vulnerability is the function mt... |
| CVE-2026-5342 | MEDIUM | 5.5 | 0.7% | Apr 2, 2026 | A flaw has been found in LibRaw up to 0.22.0. This affects the function LibRaw::nikon_load_padded_packed_raw of the file... |
| CVE-2026-34974 | MEDIUM | 5.4 | 0.2% | Apr 2, 2026 | phpMyFAQ is an open source FAQ web application. Prior to version 4.1.1, the regex-based SVG sanitizer in phpMyFAQ (SvgSa... |
| CVE-2026-34973 | MEDIUM | 5.3 | 0.3% | Apr 2, 2026 | phpMyFAQ is an open source FAQ web application. Prior to version 4.1.1, the searchCustomPages() method in phpmyfaq/src/p... |
| CVE-2026-34823 | MEDIUM | 5.4 | 0.1% | Apr 2, 2026 | Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the remark parameter to /manage/pas... |
| CVE-2026-34822 | MEDIUM | 5.4 | 0.1% | Apr 2, 2026 | Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the new_cert_name parameter to /man... |
| CVE-2026-34821 | MEDIUM | 5.4 | 0.2% | Apr 2, 2026 | Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the remark parameter to /manage/vpn... |
| CVE-2026-34820 | MEDIUM | 5.4 | 0.1% | Apr 2, 2026 | Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the remark parameter to /manage/ips... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now