2026 CVE Vulnerabilities

64,909 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-24231MEDIUM6.3NVIDIA NemoClaw contains a vulnerability in the validateEndpointUrl() SSRF protection component, where an attacker could...
CVE-2026-24222HIGH8.6NVIDIA NeMoClaw contains a vulnerability in the sandbox environment initialization component, where a remote attacker co...
CVE-2026-24204MEDIUM6.5NVIDIA Flare SDK contains a vulnerability where an Attacker may cause an Improper Input Validation by path traversing. A...
CVE-2026-24186HIGH8.8NVIDIA FLARE SDK contains a vulnerability in FOBS, where an attacker may cause deserialization of untrusted data by sen...
CVE-2026-24178CRITICAL9.8NVIDIA NVFlare Dashboard contains a vulnerability in the user management and authentication system where an unauthentica...
CVE-2026-41873CRITICAL9.8** UNSUPPORTED WHEN ASSIGNED ** Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnera...
CVE-2026-38948MEDIUM5.4Cross-Site Scripting (XSS) vulnerability exists in FUEL CMS v1.5.2 and before within the asset upload functionality. The...
CVE-2026-38651HIGH8.2Authentication Bypass vulnerability exists in Netmaker versions prior to 1.5.0. The VerifyHostToken function in logic/jw...
CVE-2026-7324HIGH7.3Memory safety bugs present in Thunderbird 150.0.0. Some of these bugs showed evidence of memory corruption and we presum...
CVE-2026-7323HIGH7.3Memory safety bugs present in Thunderbird ESR 140.10.0 and Thunderbird 150.0.0. Some of these bugs showed evidence of me...
CVE-2026-7322HIGH7.3Memory safety bugs present in Thunderbird ESR 140.10.0 and Thunderbird 150.0.0. Some of these bugs showed evidence of me...
CVE-2026-7321CRITICAL9.6Sandbox escape due to incorrect boundary conditions in the WebRTC: Networking component. This vulnerability was fixed in...
CVE-2026-7320HIGH7.5Information disclosure due to incorrect boundary conditions in the Audio/Video component. This vulnerability was fixed i...
CVE-2026-7289HIGH8.8A vulnerability was found in D-Link DIR-825M 1.1.12. This issue affects the function sub_414BA8 of the file /boafrm/form...
CVE-2026-7288HIGH8.8A vulnerability has been found in D-Link DIR-825M 1.1.12. This vulnerability affects the function sub_4151FC of the file...
CVE-2026-7283MEDIUM4.7A security flaw has been discovered in SourceCodester Pharmacy Sales and Inventory System 1.0. This impacts the function...
CVE-2026-7282MEDIUM4.7A vulnerability was identified in SourceCodester Pharmacy Sales and Inventory System 1.0. This affects the function dele...
CVE-2026-40969MEDIUM5.3The raw message of every server-side AuthenticationException is returned to the unauthenticated remote caller in the gRP...
CVE-2026-40968HIGH8.8When an authenticated user is denied access to a gRPC method, their authenticated identity remains bound to the gRPC wor...
CVE-2026-40556——Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-27760CRITICAL9.2OpenCATS prior to commit 3002a29 contains a PHP code injection vulnerability in the installer AJAX endpoint that allows ...
CVE-2026-7281LOW2.4A vulnerability was determined in SourceCodester Pharmacy Sales and Inventory System 1.0. The impacted element is the fu...
CVE-2026-7272HIGH7.3A flaw has been found in WilliamCloudQi matlab-mcp-server up to ab88f6b9bf5f36f725e8628029f7f6dd0d9913ca. The affected e...
CVE-2026-6706MEDIUM6.5Improper access control in the vault documentation feature in Devolutions Server allows an authenticated attacker to r...
CVE-2026-5944HIGH8.2An improper access control vulnerability exists in the Cisco Intersight Device Connector for Nutanix Prism Central. The ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now