2026 CVE Vulnerabilities

64,775 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-34187CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command vulnerability allows SQL Injection via graph containe...
CVE-2026-31228CRITICAL9.8The Adversarial Robustness Toolbox (ART) thru 1.20.1 contains a remote code execution vulnerability in its Kubeflow comp...
CVE-2026-31226CRITICAL9.8The TinyZero project thru commit 6652a63c57fa7e5ccde3fc9c598c7176ff15b839 (2025-58-24) contains a critical command injec...
CVE-2026-31225HIGH8.8The superduper project thru v0.10.0 contains a critical remote code execution vulnerability in its query parsing compone...
CVE-2026-31224HIGH8.8The snorkel library thru v0.10.0 contains an insecure deserialization vulnerability (CWE-502) in the MultitaskClassifier...
CVE-2026-31223HIGH8.8The snorkel library thru v0.10.0 contains a critical insecure deserialization vulnerability (CWE-502) in the BaseLabeler...
CVE-2026-31222HIGH8.8The snorkel library thru v0.10.0 contains an insecure deserialization vulnerability (CWE-502) in the Trainer.load() meth...
CVE-2026-31221HIGH7.8PyTorch-Lightning versions 2.6.0 and earlier contain an insecure deserialization vulnerability (CWE-502) in the checkpoi...
CVE-2026-31220CRITICAL9.8PySyft (Syft Datasite/Server) versions 0.9.5 and earlier are vulnerable to remote code execution due to insufficient val...
CVE-2026-31219HIGH8.8The _load_model() function in the neural_magic_training.py script of the optimate project in commit a6d302f912b481c94370...
CVE-2026-31218HIGH8.8The _load_model() function in the neural_magic_training.py script of the optimate project in commit a6d302f912b481c94370...
CVE-2026-31217CRITICAL9.8The _load_model() function in the neural_magic_training.py script of the optimate project in commit a6d302f912b481c94370...
CVE-2026-31216CRITICAL9.1The nexent v1.7.5.2 backend service contains an unauthorized arbitrary storage file deletion vulnerability in its file m...
CVE-2026-31215CRITICAL9.1The nexent v1.7.5.2 backend service contains an unauthorized arbitrary file deletion vulnerability in its ElasticSearch ...
CVE-2026-31214CRITICAL9.8The torch-checkpoint-shrink.py script in the ml-engineering project in commit 0099885db36a8f06556efe1faf552518852cb1e0 (...
CVE-2026-30810HIGH8.8Server-Side Request Forgery vulnerability allows Privilege Escalation via API Checker extension. This issue affects Pand...
CVE-2026-30808HIGH8.1Session Fixation vulnerability allows Session Hijacking via crafted session ID. This issue affects Pandora FMS: from 777...
CVE-2026-30807HIGH8.8Cross-Site Request Forgery vulnerability allows an attacker to perform unauthorized actions via crafted web page. This i...
CVE-2026-30805CRITICAL9.1Insecure Default Initialization of Resource vulnerability allows Authentication Bypass via API access. This issue affect...
CVE-2026-8401CRITICAL9.8Sandbox escape in the Profile Backup component. This vulnerability was fixed in Firefox 150.0.3, Firefox ESR 115.36, Fir...
CVE-2026-8368MEDIUM6.5LWP::UserAgent versions before 6.83 for Perl leak Authorization and Proxy-Authorization headers on cross-origin redirect...
CVE-2026-8111HIGH8.8SQL injection in the web console of Ivanti Endpoint Manager before version 2024 SU6 allows a remote authenticated attack...
CVE-2026-8110HIGH7.8Incorrect permissions assignment in the agent of Ivanti Endpoint Manager before version 2024 SU6 allows a local authenti...
CVE-2026-8109MEDIUM6.5An exposed dangerous method on the Core Server of Ivanti Endpoint Manager before version 2024 SU6 allows a remote authen...
CVE-2026-8051HIGH7.2OS command injection in Ivanti Virtual Traffic Manager before version 22.9r4 allows a remote authenticated attacker with...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now