2026 CVE Vulnerabilities

64,775 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-31238CRITICAL9.8The Ludwig framework thru 0.10.4 is vulnerable to insecure deserialization (CWE-502) in its model serving component. Whe...
CVE-2026-31237CRITICAL9.8The Ludwig framework thru 0.10.4 is vulnerable to insecure deserialization (CWE-502) through its predict() method. When ...
CVE-2026-31236CRITICAL9.8The llm CLI tool thru 0.27.1 contains a critical code injection vulnerability via its --functions command-line argument....
CVE-2026-31235CRITICAL9.8The imgaug library thru 0.4.0 contains an insecure deserialization vulnerability in its BackgroundAugmenter class within...
CVE-2026-31234CRITICAL9.8Horovod thru 0.28.1 contains an insecure deserialization vulnerability (CWE-502) in its KVStore HTTP server component. T...
CVE-2026-31233CRITICAL9.8Guardrails AI thru 0.6.7 contains a code injection vulnerability (CWE-94) in its Hub package installation mechanism. Whe...
CVE-2026-31232HIGH8.8The CosyVoice project thru commit 6e01309e01bc93bbeb83bdd996b1182a81aaf11e (2025-30-21) contains an insecure deserializa...
CVE-2026-31231CRITICAL9.8Cognee thru v0.4.0 contains a critical remote code execution vulnerability in its notebook cell execution API endpoint. ...
CVE-2026-31230CRITICAL9.8The Adversarial Robustness Toolbox (ART) thru 1.20.1 contains a command-line argument injection vulnerability in its Kub...
CVE-2026-31229CRITICAL9.8The Adversarial Robustness Toolbox (ART) thru 1.20.1 contains an insecure deserialization vulnerability (CWE-502) in its...
CVE-2026-29204CRITICAL9.1Insufficient ownership check in `clientarea.php` allows an authenticated client area user to submit requests using anoth...
CVE-2026-26083CRITICAL9.8A missing authorization vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.1, FortiSandbox 4.4.0 through 4.4.8, Fo...
CVE-2026-25690MEDIUM6.5An improper neutralization of argument delimiters in a command ('argument injection') vulnerability in Fortinet FortiDec...
CVE-2026-25088HIGH8.8An improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiN...
CVE-2026-21530MEDIUM6.7Double free in Windows Rich Text Edit allows an authorized attacker to elevate privileges locally.
CVE-2026-20767HIGH7.8Improper input validation for some Intel(R) QAT software drivers for Windows before version 1.13 within Ring 3: User App...
CVE-2026-20714HIGH7.8Out-of-bounds write for some Intel(R) QAT software drivers for Windows before version 1.13 within Ring 3: User Applicati...
CVE-2026-8407MEDIUM4.3Missing authorization in the PAM module in Devolutions Server allows an authenticated user with a PAM license but no add...
CVE-2026-8278——Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error and is not a ...
CVE-2026-5089HIGH7.3YAML::Syck versions before 1.38 for Perl has an out-of-bounds read. The base60 (sexagesimal) parsing code in perl_syck...
CVE-2026-43993HIGH8.2JunoClaw is an agentic AI platform built on Juno Network. Prior to 0.x.y-security-1, the WAVS bridge's computeDataVerify...
CVE-2026-43992CRITICAL9.8JunoClaw is an agentic AI platform built on Juno Network. Prior to 0.x.y-security-1, every MCP write tool (send_tokens, ...
CVE-2026-43991HIGH8.4JunoClaw is an agentic AI platform built on Juno Network. Prior to 0.x.y-security-1, substring-based blocklist in plugin...
CVE-2026-43990HIGH8.4JunoClaw is an agentic AI platform built on Juno Network. Prior to 0.x.y-security-1, plugin-shell's run_command wrapped ...
CVE-2026-43989HIGH8.5JunoClaw is an agentic AI platform built on Juno Network. Prior to 0.x.y-security-1, the upload_wasm MCP tool accepted a...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now