2026 CVE Vulnerabilities
45,001 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-31230 | CRITICAL | 9.8 | 0.6% | May 12, 2026 | The Adversarial Robustness Toolbox (ART) thru 1.20.1 contains a command-line argument injection vulnerability in its Kub... |
| CVE-2026-31229 | CRITICAL | 9.8 | 0.6% | May 12, 2026 | The Adversarial Robustness Toolbox (ART) thru 1.20.1 contains an insecure deserialization vulnerability (CWE-502) in its... |
| CVE-2026-29204 | CRITICAL | 9.1 | 0.3% | May 12, 2026 | Insufficient ownership check in `clientarea.php` allows an authenticated client area user to submit requests using anoth... |
| CVE-2026-26083 | CRITICAL | 9.8 | 0.7% | May 12, 2026 | A missing authorization vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.1, FortiSandbox 4.4.0 through 4.4.8, Fo... |
| CVE-2026-43992 | CRITICAL | 9.8 | 0.2% | May 12, 2026 | JunoClaw is an agentic AI platform built on Juno Network. Prior to 0.x.y-security-1, every MCP write tool (send_tokens, ... |
| CVE-2026-20794 | CRITICAL | 9.3 | 0.1% | May 12, 2026 | Buffer overflow for the Intel(R) Data Center Graphics Driver for VMware ESXi software before version 2.0.2 within Ring 1... |
| CVE-2026-43515 | CRITICAL | 9.1 | 0.8% | May 12, 2026 | Improper Authorization vulnerability when multiple method constraints define an HTTP method for the same extension in Ap... |
| CVE-2026-43512 | CRITICAL | 9.8 | 0.9% | May 12, 2026 | DEPRECATED: Authentication Bypass Issues vulnerability in digest authentication in Apache Tomcat. This issue affects Ap... |
| CVE-2026-41293 | CRITICAL | 9.8 | 1.0% | May 12, 2026 | Improper Input Validation vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0... |
| CVE-2026-34187 | CRITICAL | 9.8 | 0.3% | May 12, 2026 | Improper Neutralization of Special Elements used in an SQL Command vulnerability allows SQL Injection via graph containe... |
| CVE-2026-31228 | CRITICAL | 9.8 | 0.6% | May 12, 2026 | The Adversarial Robustness Toolbox (ART) thru 1.20.1 contains a remote code execution vulnerability in its Kubeflow comp... |
| CVE-2026-31226 | CRITICAL | 9.8 | 1.2% | May 12, 2026 | The TinyZero project thru commit 6652a63c57fa7e5ccde3fc9c598c7176ff15b839 (2025-58-24) contains a critical command injec... |
| CVE-2026-31220 | CRITICAL | 9.8 | 0.6% | May 12, 2026 | PySyft (Syft Datasite/Server) versions 0.9.5 and earlier are vulnerable to remote code execution due to insufficient val... |
| CVE-2026-31217 | CRITICAL | 9.8 | 0.4% | May 12, 2026 | The _load_model() function in the neural_magic_training.py script of the optimate project in commit a6d302f912b481c94370... |
| CVE-2026-31216 | CRITICAL | 9.1 | 0.4% | May 12, 2026 | The nexent v1.7.5.2 backend service contains an unauthorized arbitrary storage file deletion vulnerability in its file m... |
| CVE-2026-31215 | CRITICAL | 9.1 | 0.4% | May 12, 2026 | The nexent v1.7.5.2 backend service contains an unauthorized arbitrary file deletion vulnerability in its ElasticSearch ... |
| CVE-2026-31214 | CRITICAL | 9.8 | 0.5% | May 12, 2026 | The torch-checkpoint-shrink.py script in the ml-engineering project in commit 0099885db36a8f06556efe1faf552518852cb1e0 (... |
| CVE-2026-30805 | CRITICAL | 9.1 | 0.3% | May 12, 2026 | Insecure Default Initialization of Resource vulnerability allows Authentication Bypass via API access. This issue affect... |
| CVE-2026-8401 | CRITICAL | 9.8 | 0.3% | May 12, 2026 | Sandbox escape in the Profile Backup component. This vulnerability was fixed in Firefox 150.0.3, Firefox ESR 115.36, Fir... |
| CVE-2026-8043 | CRITICAL | 9.6 | 0.9% | May 12, 2026 | External control of a file name in Ivanti Xtraction before version 2026.2 allows a remote authenticated attacker to read... |
| CVE-2026-45091 | CRITICAL | 9.1 | 0.3% | May 12, 2026 | sealed-env is a cross-stack, zero-trust secret management library for Node.js and Java/Spring Boot. In sealed-env enterp... |
| CVE-2026-27851 | CRITICAL | 9.1 | 0.4% | May 12, 2026 | When safe filter is used with variable expansion, all following pipelines on the same string are incorrectly interpreted... |
| CVE-2026-8072 | CRITICAL | 9.2 | 0.2% | May 12, 2026 | Insecure generation of credentials in the local SAT (Technical Support) access functionality of the Ingecon Sun EMS Boar... |
| CVE-2026-7428 | CRITICAL | 9.2 | 0.2% | May 12, 2026 | Prior to 2025-11-03, well-intended users of Terraform or REST API for Google Cloud AlloyDB for PostgreSQL could have cre... |
| CVE-2026-41551 | CRITICAL | 9.3 | 0.5% | May 12, 2026 | A vulnerability has been identified in ROS# (All versions < V2.2.2). Affected versions contain a path traversal vulnerab... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now