2026 CVE Vulnerabilities

53,211 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-34834HIGH7.5Bulwark Webmail is a self-hosted webmail client for Stalwart Mail Server. Prior to version 1.4.10, the verifyIdentity() ...
CVE-2026-34833HIGH7.5Bulwark Webmail is a self-hosted webmail client for Stalwart Mail Server. Prior to version 1.4.10, the GET /api/auth/ses...
CVE-2026-34760HIGH7.1vLLM is an inference and serving engine for large language models (LLMs). From version 0.5.5 to before version 0.18.0, L...
CVE-2026-5429HIGH7.8Unsanitized input during web page generation in the Kiro Agent webview in Kiro IDE before version 0.8.140 allows a remot...
CVE-2026-5418HIGH7.3A vulnerability was identified in appsmithorg appsmith up to 1.97. Impacted is the function computeDisallowedHosts of th...
CVE-2026-34759HIGH8.1OneUptime is an open-source monitoring and observability platform. Prior to version 10.0.42, multiple notification API e...
CVE-2026-34752HIGH7.5Haraka is a Node.js mail server. Prior to version 3.1.4, sending an email with __proto__: as a header name crashes the H...
CVE-2026-34742HIGH8.1The Go MCP SDK used Go's standard encoding/json. Prior to version 1.4.0, the Model Context Protocol (MCP) Go SDK does no...
CVE-2026-34735HIGH8.7The Hytale Modding Wiki is a free service for Hytale mods to host their documentation & wikis. In version 1.2.0 and prio...
CVE-2026-34581HIGH8.1goshs is a SimpleHTTPServer written in Go. From version 1.1.0 to before version 2.0.0-beta.2, when using the Share Token...
CVE-2026-34426HIGH7.3OpenClaw versions prior to commit b57b680 contain an approval bypass vulnerability due to inconsistent environment varia...
CVE-2026-35414HIGH8.1OpenSSH before 10.3 mishandles the authorized_keys principals option in uncommon scenarios involving a principals list i...
CVE-2026-34828HIGH7.1listmonk is a standalone, self-hosted, newsletter and mailing list manager. From version 4.1.0 to before version 6.1.0, ...
CVE-2026-34827HIGH7.5Rack is a modular Ruby web server interface. From versions 3.0.0.beta1 to before 3.1.21, and 3.2.0 to before 3.2.6, Rack...
CVE-2026-34725HIGH8.2DbGate is cross-platform database manager. From version 7.0.0 to before version 7.1.5, a stored XSS vulnerability exists...
CVE-2026-34717HIGH8.1OpenProject is an open-source, web-based project management software. Prior to version 17.2.3, the =n operator in module...
CVE-2026-34608HIGH8.2NanoMQ MQTT Broker (NanoMQ) is an all-around Edge Messaging Platform. Prior to version 0.24.10, in NanoMQ's webhook_inpr...
CVE-2026-34601HIGH7.5xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) `DOMParser` and `XMLSerializer` module. In xmldom ...
CVE-2026-34593HIGH7.5Ash Framework is a declarative, extensible framework for building Elixir applications. Prior to version 3.22.0, Ash.Type...
CVE-2026-34577HIGH8.6Postiz is an AI social media scheduling tool. Prior to version 2.21.3, the GET /public/stream endpoint in PublicControll...
CVE-2026-34576HIGH7.7Postiz is an AI social media scheduling tool. Prior to version 2.21.3, the POST /public/v1/upload-from-url endpoint acce...
CVE-2026-34524HIGH8.8SillyTavern is a locally installed user interface that allows users to interact with text generation large language mode...
CVE-2026-34522HIGH8.1SillyTavern is a locally installed user interface that allows users to interact with text generation large language mode...
CVE-2026-34121HIGH8.8An authentication bypass vulnerability within the HTTP handling of the DS configuration service in TP-Link Tapo C520WS v...
CVE-2026-5355HIGH8.8A vulnerability has been found in Trendnet TEW-657BRM 1.00.1. Affected by this issue is the function vpn_drop of the fil...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now