2026 CVE Vulnerabilities
64,775 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-34187 | CRITICAL | 9.8 | 0.3% | May 12, 2026 | Improper Neutralization of Special Elements used in an SQL Command vulnerability allows SQL Injection via graph containe... |
| CVE-2026-31228 | CRITICAL | 9.8 | 0.6% | May 12, 2026 | The Adversarial Robustness Toolbox (ART) thru 1.20.1 contains a remote code execution vulnerability in its Kubeflow comp... |
| CVE-2026-31226 | CRITICAL | 9.8 | 1.2% | May 12, 2026 | The TinyZero project thru commit 6652a63c57fa7e5ccde3fc9c598c7176ff15b839 (2025-58-24) contains a critical command injec... |
| CVE-2026-31225 | HIGH | 8.8 | 0.4% | May 12, 2026 | The superduper project thru v0.10.0 contains a critical remote code execution vulnerability in its query parsing compone... |
| CVE-2026-31224 | HIGH | 8.8 | 0.4% | May 12, 2026 | The snorkel library thru v0.10.0 contains an insecure deserialization vulnerability (CWE-502) in the MultitaskClassifier... |
| CVE-2026-31223 | HIGH | 8.8 | 0.4% | May 12, 2026 | The snorkel library thru v0.10.0 contains a critical insecure deserialization vulnerability (CWE-502) in the BaseLabeler... |
| CVE-2026-31222 | HIGH | 8.8 | 0.4% | May 12, 2026 | The snorkel library thru v0.10.0 contains an insecure deserialization vulnerability (CWE-502) in the Trainer.load() meth... |
| CVE-2026-31221 | HIGH | 7.8 | 0.4% | May 12, 2026 | PyTorch-Lightning versions 2.6.0 and earlier contain an insecure deserialization vulnerability (CWE-502) in the checkpoi... |
| CVE-2026-31220 | CRITICAL | 9.8 | 0.6% | May 12, 2026 | PySyft (Syft Datasite/Server) versions 0.9.5 and earlier are vulnerable to remote code execution due to insufficient val... |
| CVE-2026-31219 | HIGH | 8.8 | 0.6% | May 12, 2026 | The _load_model() function in the neural_magic_training.py script of the optimate project in commit a6d302f912b481c94370... |
| CVE-2026-31218 | HIGH | 8.8 | 0.6% | May 12, 2026 | The _load_model() function in the neural_magic_training.py script of the optimate project in commit a6d302f912b481c94370... |
| CVE-2026-31217 | CRITICAL | 9.8 | 0.4% | May 12, 2026 | The _load_model() function in the neural_magic_training.py script of the optimate project in commit a6d302f912b481c94370... |
| CVE-2026-31216 | CRITICAL | 9.1 | 0.4% | May 12, 2026 | The nexent v1.7.5.2 backend service contains an unauthorized arbitrary storage file deletion vulnerability in its file m... |
| CVE-2026-31215 | CRITICAL | 9.1 | 0.4% | May 12, 2026 | The nexent v1.7.5.2 backend service contains an unauthorized arbitrary file deletion vulnerability in its ElasticSearch ... |
| CVE-2026-31214 | CRITICAL | 9.8 | 0.5% | May 12, 2026 | The torch-checkpoint-shrink.py script in the ml-engineering project in commit 0099885db36a8f06556efe1faf552518852cb1e0 (... |
| CVE-2026-30810 | HIGH | 8.8 | 0.3% | May 12, 2026 | Server-Side Request Forgery vulnerability allows Privilege Escalation via API Checker extension. This issue affects Pand... |
| CVE-2026-30808 | HIGH | 8.1 | 0.3% | May 12, 2026 | Session Fixation vulnerability allows Session Hijacking via crafted session ID. This issue affects Pandora FMS: from 777... |
| CVE-2026-30807 | HIGH | 8.8 | 0.1% | May 12, 2026 | Cross-Site Request Forgery vulnerability allows an attacker to perform unauthorized actions via crafted web page. This i... |
| CVE-2026-30805 | CRITICAL | 9.1 | 0.3% | May 12, 2026 | Insecure Default Initialization of Resource vulnerability allows Authentication Bypass via API access. This issue affect... |
| CVE-2026-8401 | CRITICAL | 9.8 | 0.3% | May 12, 2026 | Sandbox escape in the Profile Backup component. This vulnerability was fixed in Firefox 150.0.3, Firefox ESR 115.36, Fir... |
| CVE-2026-8368 | MEDIUM | 6.5 | 0.3% | May 12, 2026 | LWP::UserAgent versions before 6.83 for Perl leak Authorization and Proxy-Authorization headers on cross-origin redirect... |
| CVE-2026-8111 | HIGH | 8.8 | 0.9% | May 12, 2026 | SQL injection in the web console of Ivanti Endpoint Manager before version 2024 SU6 allows a remote authenticated attack... |
| CVE-2026-8110 | HIGH | 7.8 | 0.2% | May 12, 2026 | Incorrect permissions assignment in the agent of Ivanti Endpoint Manager before version 2024 SU6 allows a local authenti... |
| CVE-2026-8109 | MEDIUM | 6.5 | 0.7% | May 12, 2026 | An exposed dangerous method on the Core Server of Ivanti Endpoint Manager before version 2024 SU6 allows a remote authen... |
| CVE-2026-8051 | HIGH | 7.2 | 1.9% | May 12, 2026 | OS command injection in Ivanti Virtual Traffic Manager before version 22.9r4 allows a remote authenticated attacker with... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now