2026 CVE Vulnerabilities

51,054 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-43990HIGH8.4JunoClaw is an agentic AI platform built on Juno Network. Prior to 0.x.y-security-1, plugin-shell's run_command wrapped ...
CVE-2026-43989HIGH8.5JunoClaw is an agentic AI platform built on Juno Network. Prior to 0.x.y-security-1, the upload_wasm MCP tool accepted a...
CVE-2026-20887HIGH8.8Improper access control for some Intel Vision software for all versions within Ring 3: User Applications may allow a den...
CVE-2026-20879HIGH8.3Out-of-bounds write for the Intel(R) Data Center Graphics Driver for VMware ESXi software before version 2.0.2 within Ri...
CVE-2026-20753HIGH8.7Integer overflow in the UEFI firmware for the Slim Bootloader may allow an escalation of privilege. System software adve...
CVE-2026-20751HIGH8.3Out-of-bounds read for the Intel(R) Data Center Graphics Driver for VMware ESXi software before version 2.0.2 within Rin...
CVE-2026-20738HIGH8.5Untrusted pointer dereference for some Intel(R) QuickAssist Adapter 8960 software before version 1.13 within Ring 3: Use...
CVE-2026-43513HIGH7.5Improper Handling of Case Sensitivity vulnerability in LockOutRealm in Apache Tomcat. This issue affects Apache Tomcat:...
CVE-2026-42498HIGH7.3Exposure of HTTP Authentication Header to unexpected hosts during WebSocket authentication vulnerability in Apache Tomca...
CVE-2026-41284HIGH7.5Allocation of Resources Without Limits or Throttling vulnerability in Apache Tomcat. This issue affects Apache Tomcat: ...
CVE-2026-31225HIGH8.8The superduper project thru v0.10.0 contains a critical remote code execution vulnerability in its query parsing compone...
CVE-2026-31224HIGH8.8The snorkel library thru v0.10.0 contains an insecure deserialization vulnerability (CWE-502) in the MultitaskClassifier...
CVE-2026-31223HIGH8.8The snorkel library thru v0.10.0 contains a critical insecure deserialization vulnerability (CWE-502) in the BaseLabeler...
CVE-2026-31222HIGH8.8The snorkel library thru v0.10.0 contains an insecure deserialization vulnerability (CWE-502) in the Trainer.load() meth...
CVE-2026-31221HIGH7.8PyTorch-Lightning versions 2.6.0 and earlier contain an insecure deserialization vulnerability (CWE-502) in the checkpoi...
CVE-2026-31219HIGH8.8The _load_model() function in the neural_magic_training.py script of the optimate project in commit a6d302f912b481c94370...
CVE-2026-31218HIGH8.8The _load_model() function in the neural_magic_training.py script of the optimate project in commit a6d302f912b481c94370...
CVE-2026-30810HIGH8.8Server-Side Request Forgery vulnerability allows Privilege Escalation via API Checker extension. This issue affects Pand...
CVE-2026-30808HIGH8.1Session Fixation vulnerability allows Session Hijacking via crafted session ID. This issue affects Pandora FMS: from 777...
CVE-2026-30807HIGH8.8Cross-Site Request Forgery vulnerability allows an attacker to perform unauthorized actions via crafted web page. This i...
CVE-2026-8111HIGH8.8SQL injection in the web console of Ivanti Endpoint Manager before version 2024 SU6 allows a remote authenticated attack...
CVE-2026-8110HIGH7.8Incorrect permissions assignment in the agent of Ivanti Endpoint Manager before version 2024 SU6 allows a local authenti...
CVE-2026-8051HIGH7.2OS command injection in Ivanti Virtual Traffic Manager before version 22.9r4 allows a remote authenticated attacker with...
CVE-2026-7432HIGH7A race condition in Ivanti Secure Access Client before 22.8R6 allows a locally authenticated user to escalate privileges...
CVE-2026-6866HIGH7.5CWE-1188 Initialization of a Resource with an Insecure Default vulnerability exists that could cause unauthorized disclo...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now