2026 CVE Vulnerabilities
64,775 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-31238 | CRITICAL | 9.8 | 0.5% | May 12, 2026 | The Ludwig framework thru 0.10.4 is vulnerable to insecure deserialization (CWE-502) in its model serving component. Whe... |
| CVE-2026-31237 | CRITICAL | 9.8 | 0.6% | May 12, 2026 | The Ludwig framework thru 0.10.4 is vulnerable to insecure deserialization (CWE-502) through its predict() method. When ... |
| CVE-2026-31236 | CRITICAL | 9.8 | 0.3% | May 12, 2026 | The llm CLI tool thru 0.27.1 contains a critical code injection vulnerability via its --functions command-line argument.... |
| CVE-2026-31235 | CRITICAL | 9.8 | 0.5% | May 12, 2026 | The imgaug library thru 0.4.0 contains an insecure deserialization vulnerability in its BackgroundAugmenter class within... |
| CVE-2026-31234 | CRITICAL | 9.8 | 0.7% | May 12, 2026 | Horovod thru 0.28.1 contains an insecure deserialization vulnerability (CWE-502) in its KVStore HTTP server component. T... |
| CVE-2026-31233 | CRITICAL | 9.8 | 0.6% | May 12, 2026 | Guardrails AI thru 0.6.7 contains a code injection vulnerability (CWE-94) in its Hub package installation mechanism. Whe... |
| CVE-2026-31232 | HIGH | 8.8 | 0.5% | May 12, 2026 | The CosyVoice project thru commit 6e01309e01bc93bbeb83bdd996b1182a81aaf11e (2025-30-21) contains an insecure deserializa... |
| CVE-2026-31231 | CRITICAL | 9.8 | 0.6% | May 12, 2026 | Cognee thru v0.4.0 contains a critical remote code execution vulnerability in its notebook cell execution API endpoint. ... |
| CVE-2026-31230 | CRITICAL | 9.8 | 0.6% | May 12, 2026 | The Adversarial Robustness Toolbox (ART) thru 1.20.1 contains a command-line argument injection vulnerability in its Kub... |
| CVE-2026-31229 | CRITICAL | 9.8 | 0.6% | May 12, 2026 | The Adversarial Robustness Toolbox (ART) thru 1.20.1 contains an insecure deserialization vulnerability (CWE-502) in its... |
| CVE-2026-29204 | CRITICAL | 9.1 | 0.3% | May 12, 2026 | Insufficient ownership check in `clientarea.php` allows an authenticated client area user to submit requests using anoth... |
| CVE-2026-26083 | CRITICAL | 9.8 | 0.7% | May 12, 2026 | A missing authorization vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.1, FortiSandbox 4.4.0 through 4.4.8, Fo... |
| CVE-2026-25690 | MEDIUM | 6.5 | 0.2% | May 12, 2026 | An improper neutralization of argument delimiters in a command ('argument injection') vulnerability in Fortinet FortiDec... |
| CVE-2026-25088 | HIGH | 8.8 | 0.3% | May 12, 2026 | An improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiN... |
| CVE-2026-21530 | MEDIUM | 6.7 | 0.3% | May 12, 2026 | Double free in Windows Rich Text Edit allows an authorized attacker to elevate privileges locally. |
| CVE-2026-20767 | HIGH | 7.8 | 0.1% | May 12, 2026 | Improper input validation for some Intel(R) QAT software drivers for Windows before version 1.13 within Ring 3: User App... |
| CVE-2026-20714 | HIGH | 7.8 | 0.1% | May 12, 2026 | Out-of-bounds write for some Intel(R) QAT software drivers for Windows before version 1.13 within Ring 3: User Applicati... |
| CVE-2026-8407 | MEDIUM | 4.3 | 0.2% | May 12, 2026 | Missing authorization in the PAM module in Devolutions Server allows an authenticated user with a PAM license but no add... |
| CVE-2026-8278 | — | — | — | May 12, 2026 | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error and is not a ... |
| CVE-2026-5089 | HIGH | 7.3 | 0.3% | May 12, 2026 | YAML::Syck versions before 1.38 for Perl has an out-of-bounds read. The base60 (sexagesimal) parsing code in perl_syck... |
| CVE-2026-43993 | HIGH | 8.2 | 0.2% | May 12, 2026 | JunoClaw is an agentic AI platform built on Juno Network. Prior to 0.x.y-security-1, the WAVS bridge's computeDataVerify... |
| CVE-2026-43992 | CRITICAL | 9.8 | 0.2% | May 12, 2026 | JunoClaw is an agentic AI platform built on Juno Network. Prior to 0.x.y-security-1, every MCP write tool (send_tokens, ... |
| CVE-2026-43991 | HIGH | 8.4 | 0.2% | May 12, 2026 | JunoClaw is an agentic AI platform built on Juno Network. Prior to 0.x.y-security-1, substring-based blocklist in plugin... |
| CVE-2026-43990 | HIGH | 8.4 | 0.2% | May 12, 2026 | JunoClaw is an agentic AI platform built on Juno Network. Prior to 0.x.y-security-1, plugin-shell's run_command wrapped ... |
| CVE-2026-43989 | HIGH | 8.5 | 0.1% | May 12, 2026 | JunoClaw is an agentic AI platform built on Juno Network. Prior to 0.x.y-security-1, the upload_wasm MCP tool accepted a... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now