2026 CVE Vulnerabilities

61,214 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-53840HIGH7.1OpenClaw before 2026.5.12 contains an information disclosure vulnerability in streamable-http MCP servers that forwards ...
CVE-2026-50656HIGH7Microsoft is aware of an elevation of privilege in the Microsoft Malware Protection Engine in Microsoft Defender publicl...
CVE-2026-4367MEDIUM5.5A flaw was found in libXpm. A local user with low privileges could exploit an Out-of-Bounds Read vulnerability in the `x...
CVE-2026-48775MEDIUM6.8LangGraph SQLite Checkpoint is an implementation of LangGraph CheckpointSaver that uses SQLite DB (both sync and async, ...
CVE-2026-47964HIGH7.8DNG SDK versions 1.7.1 2536 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in ...
CVE-2026-47963MEDIUM5.5DNG SDK versions 1.7.1 2536 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosur...
CVE-2026-47934MEDIUM5.5DNG SDK versions 1.7.1 2536 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosur...
CVE-2026-47927MEDIUM5.5DNG SDK versions 1.7.1 2536 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosur...
CVE-2026-47749HIGH7.8stable-diffusion.cpp is a pure C/C++ library for running diffusion model (Stable Diffusion, Flux, Wan, Qwen Image, Z-Ima...
CVE-2026-47748MEDIUM5.5stable-diffusion.cpp is a pure C/C++ library for running diffusion model (Stable Diffusion, Flux, Wan, Qwen Image, Z-Ima...
CVE-2026-10748HIGH8.6An authenticated user with the nx-licensing-create privilege can upload a specially crafted license file to execute arbi...
CVE-2026-53776CRITICAL9.3Perry before 0.5.1166 contains a JWT validation vulnerability that allows remote attackers to bypass token expiration by...
CVE-2026-44932HIGH8.8Passing of unsanitized strings from DHCP replies into the wicked dhcp client before wicked 0.6.79 could be used by attac...
CVE-2026-42089HIGH8.6Yeoman Environment provides an API to discover, create, and run generators, and to configure where and how a generator i...
CVE-2026-39927Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-39926Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-24228HIGH7.8NVIDIA NeMo Framework for Linux contains a vulnerability where an attacker may cause deserialization of untrusted data. ...
CVE-2026-24155HIGH7.8NVIDIA NeMo Framework for all platforms contains a code injection vulnerability. A successful exploit of this vulnerabil...
CVE-2026-12412Rejected reason: loading template...
CVE-2026-12003MEDIUM5.3To allow builds of Python to be run from an in-tree layout (rather than an installed file layout), the VPATH variable is...
CVE-2026-10649HIGH8.6A flaw was found in Pacemaker. An unauthenticated remote attacker can exploit an integer overflow vulnerability in the r...
CVE-2026-9307MEDIUM6.3A sensitive information disclosure security issue exists within the affected CompactLogix controllers. The controller's ...
CVE-2026-48780HIGH8.2Forem is open source software for building communities. Prior to commit a2ab6d4, a maliciously crafted email address cou...
CVE-2026-47684HIGH7.7Sync-in Server is a secure, open-source platform for file storage, sharing, collaboration, and syncing. Prior to version...
CVE-2026-12398HIGH7.5A command injection vulnerability was found in galaxy_ng. The do_git_checkout() function in the legacy role import API (...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now