2026 CVE Vulnerabilities
64,909 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-24231 | MEDIUM | 6.3 | 0.1% | Apr 28, 2026 | NVIDIA NemoClaw contains a vulnerability in the validateEndpointUrl() SSRF protection component, where an attacker could... |
| CVE-2026-24222 | HIGH | 8.6 | 0.4% | Apr 28, 2026 | NVIDIA NeMoClaw contains a vulnerability in the sandbox environment initialization component, where a remote attacker co... |
| CVE-2026-24204 | MEDIUM | 6.5 | 0.4% | Apr 28, 2026 | NVIDIA Flare SDK contains a vulnerability where an Attacker may cause an Improper Input Validation by path traversing. A... |
| CVE-2026-24186 | HIGH | 8.8 | 0.5% | Apr 28, 2026 | NVIDIA FLARE SDK contains a vulnerability in FOBS, where an attacker may cause deserialization of untrusted data by sen... |
| CVE-2026-24178 | CRITICAL | 9.8 | 0.6% | Apr 28, 2026 | NVIDIA NVFlare Dashboard contains a vulnerability in the user management and authentication system where an unauthentica... |
| CVE-2026-41873 | CRITICAL | 9.8 | 0.4% | Apr 28, 2026 | ** UNSUPPORTED WHEN ASSIGNED ** Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnera... |
| CVE-2026-38948 | MEDIUM | 5.4 | 0.2% | Apr 28, 2026 | Cross-Site Scripting (XSS) vulnerability exists in FUEL CMS v1.5.2 and before within the asset upload functionality. The... |
| CVE-2026-38651 | HIGH | 8.2 | 0.3% | Apr 28, 2026 | Authentication Bypass vulnerability exists in Netmaker versions prior to 1.5.0. The VerifyHostToken function in logic/jw... |
| CVE-2026-7324 | HIGH | 7.3 | 0.3% | Apr 28, 2026 | Memory safety bugs present in Thunderbird 150.0.0. Some of these bugs showed evidence of memory corruption and we presum... |
| CVE-2026-7323 | HIGH | 7.3 | 0.4% | Apr 28, 2026 | Memory safety bugs present in Thunderbird ESR 140.10.0 and Thunderbird 150.0.0. Some of these bugs showed evidence of me... |
| CVE-2026-7322 | HIGH | 7.3 | 0.3% | Apr 28, 2026 | Memory safety bugs present in Thunderbird ESR 140.10.0 and Thunderbird 150.0.0. Some of these bugs showed evidence of me... |
| CVE-2026-7321 | CRITICAL | 9.6 | 0.3% | Apr 28, 2026 | Sandbox escape due to incorrect boundary conditions in the WebRTC: Networking component. This vulnerability was fixed in... |
| CVE-2026-7320 | HIGH | 7.5 | 0.3% | Apr 28, 2026 | Information disclosure due to incorrect boundary conditions in the Audio/Video component. This vulnerability was fixed i... |
| CVE-2026-7289 | HIGH | 8.8 | 0.7% | Apr 28, 2026 | A vulnerability was found in D-Link DIR-825M 1.1.12. This issue affects the function sub_414BA8 of the file /boafrm/form... |
| CVE-2026-7288 | HIGH | 8.8 | 0.7% | Apr 28, 2026 | A vulnerability has been found in D-Link DIR-825M 1.1.12. This vulnerability affects the function sub_4151FC of the file... |
| CVE-2026-7283 | MEDIUM | 4.7 | 0.3% | Apr 28, 2026 | A security flaw has been discovered in SourceCodester Pharmacy Sales and Inventory System 1.0. This impacts the function... |
| CVE-2026-7282 | MEDIUM | 4.7 | 0.2% | Apr 28, 2026 | A vulnerability was identified in SourceCodester Pharmacy Sales and Inventory System 1.0. This affects the function dele... |
| CVE-2026-40969 | MEDIUM | 5.3 | 0.2% | Apr 28, 2026 | The raw message of every server-side AuthenticationException is returned to the unauthenticated remote caller in the gRP... |
| CVE-2026-40968 | HIGH | 8.8 | 0.2% | Apr 28, 2026 | When an authenticated user is denied access to a gRPC method, their authenticated identity remains bound to the gRPC wor... |
| CVE-2026-40556 | — | — | — | Apr 28, 2026 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2026-27760 | CRITICAL | 9.2 | 22.2% | Apr 28, 2026 | OpenCATS prior to commit 3002a29 contains a PHP code injection vulnerability in the installer AJAX endpoint that allows ... |
| CVE-2026-7281 | LOW | 2.4 | 0.2% | Apr 28, 2026 | A vulnerability was determined in SourceCodester Pharmacy Sales and Inventory System 1.0. The impacted element is the fu... |
| CVE-2026-7272 | HIGH | 7.3 | 0.4% | Apr 28, 2026 | A flaw has been found in WilliamCloudQi matlab-mcp-server up to ab88f6b9bf5f36f725e8628029f7f6dd0d9913ca. The affected e... |
| CVE-2026-6706 | MEDIUM | 6.5 | 0.2% | Apr 28, 2026 | Improper access control in the vault documentation feature in Devolutions Server allows an authenticated attacker to r... |
| CVE-2026-5944 | HIGH | 8.2 | 0.5% | Apr 28, 2026 | An improper access control vulnerability exists in the Cisco Intersight Device Connector for Nutanix Prism Central. The ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now