2026 CVE Vulnerabilities
44,973 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-19331 | MEDIUM | 5.3 | 0.1% | Aug 9, 2026 | A vulnerability was identified in bazylhorsey obsidian-mcp-server 1.0.0. This affects the function readCanvas/writeCanva... |
| CVE-2026-19330 | MEDIUM | 5.3 | 0.1% | Aug 9, 2026 | A vulnerability was determined in angrysky56 advanced-reasoning-mcp 1.0.0. The impacted element is the function create_s... |
| CVE-2026-19329 | MEDIUM | 5.3 | 0.6% | Aug 9, 2026 | A vulnerability was found in andreahaku codex_mcp up to 1ff521cc6cc57cfe56ddef946c644b8534771390. The affected element i... |
| CVE-2026-10595 | HIGH | 7.5 | 0.5% | Aug 9, 2026 | A path traversal vulnerability exists in parisneo/lollms version 2.1.0, specifically in the SPA catch-all route implemen... |
| CVE-2026-19328 | MEDIUM | 5.3 | 0.1% | Aug 9, 2026 | A vulnerability has been found in aktsmm skill-ninja-mcp-server 0.1.0. Impacted is the function getInstalledSkills/insta... |
| CVE-2026-19327 | MEDIUM | 5.3 | 0.1% | Aug 9, 2026 | A flaw has been found in abracadabra50 claude-sesh 1.0.0. This issue affects the function getEnrichedData/enrichSession ... |
| CVE-2026-19326 | MEDIUM | 4.4 | 0.1% | Aug 9, 2026 | A vulnerability was detected in Jevon-Zhong Ai-doctor 0.0.1. This vulnerability affects the function deleteImage of the ... |
| CVE-2026-19325 | MEDIUM | 5.3 | 0.1% | Aug 9, 2026 | A security vulnerability has been detected in IncomeStreamSurfer roo-code-memory-bank-mcp-server up to 9dcb2fb5e6b65a35a... |
| CVE-2026-19324 | LOW | 3.3 | 0.1% | Aug 9, 2026 | A weakness has been identified in HelloGGX shadcn-vue-mcp up to e170e277b94235cde627803277fc8c41103a4d38. Affected by th... |
| CVE-2026-17510 | HIGH | 7.5 | 0.2% | Aug 9, 2026 | Crypt::OpenSSL::PKCS12 versions before 1.98 for Perl allow a NULL pointer dereference in print_attribute via a zero leng... |
| CVE-2026-71993 | CRITICAL | 9.8 | 1.4% | Aug 9, 2026 | MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the openvpn function tha... |
| CVE-2026-71992 | CRITICAL | 9.8 | 1.4% | Aug 9, 2026 | MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the macfilter function t... |
| CVE-2026-71991 | CRITICAL | 9.8 | — | Aug 9, 2026 | MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the TelnetSSH function u... |
| CVE-2026-71990 | CRITICAL | 9.8 | 1.4% | Aug 9, 2026 | MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the TelnetSSH function u... |
| CVE-2026-71989 | CRITICAL | 9.8 | 1.4% | Aug 9, 2026 | MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the porTrigger function ... |
| CVE-2026-71988 | CRITICAL | 9.8 | 1.4% | Aug 9, 2026 | MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the portFw function that... |
| CVE-2026-71987 | CRITICAL | 9.8 | 1.4% | Aug 9, 2026 | MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the alg function that al... |
| CVE-2026-71986 | CRITICAL | 9.8 | — | Aug 9, 2026 | MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the dmz function that al... |
| CVE-2026-71985 | CRITICAL | 9.8 | 1.4% | Aug 9, 2026 | MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the accesscontrol functi... |
| CVE-2026-71984 | CRITICAL | 9.8 | 1.4% | Aug 9, 2026 | MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the urlfilter function t... |
| CVE-2026-19323 | MEDIUM | 5.3 | 0.1% | Aug 9, 2026 | A security flaw has been discovered in azer react-analyzer-mcp up to 335f2a3585f265e2e88352b59b10d3b478d678b0. Affected ... |
| CVE-2026-71983 | CRITICAL | 9.8 | 1.6% | Aug 8, 2026 | MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the wps.cgi interface th... |
| CVE-2026-11612 | — | — | — | Aug 8, 2026 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2026-71502 | MEDIUM | 5.1 | 0.6% | Aug 8, 2026 | CTI-Transmute contains a stored cross-site scripting vulnerability caused by insufficient neutralization of Vue template... |
| CVE-2026-71958 | CRITICAL | 9.8 | 0.6% | Aug 8, 2026 | D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_202602110044 contain a buffer overflow vu... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now