2026 CVE Vulnerabilities
51,054 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-43990 | HIGH | 8.4 | 0.2% | May 12, 2026 | JunoClaw is an agentic AI platform built on Juno Network. Prior to 0.x.y-security-1, plugin-shell's run_command wrapped ... |
| CVE-2026-43989 | HIGH | 8.5 | 0.1% | May 12, 2026 | JunoClaw is an agentic AI platform built on Juno Network. Prior to 0.x.y-security-1, the upload_wasm MCP tool accepted a... |
| CVE-2026-20887 | HIGH | 8.8 | 0.5% | May 12, 2026 | Improper access control for some Intel Vision software for all versions within Ring 3: User Applications may allow a den... |
| CVE-2026-20879 | HIGH | 8.3 | 0.1% | May 12, 2026 | Out-of-bounds write for the Intel(R) Data Center Graphics Driver for VMware ESXi software before version 2.0.2 within Ri... |
| CVE-2026-20753 | HIGH | 8.7 | 0.1% | May 12, 2026 | Integer overflow in the UEFI firmware for the Slim Bootloader may allow an escalation of privilege. System software adve... |
| CVE-2026-20751 | HIGH | 8.3 | 0.1% | May 12, 2026 | Out-of-bounds read for the Intel(R) Data Center Graphics Driver for VMware ESXi software before version 2.0.2 within Rin... |
| CVE-2026-20738 | HIGH | 8.5 | 0.1% | May 12, 2026 | Untrusted pointer dereference for some Intel(R) QuickAssist Adapter 8960 software before version 1.13 within Ring 3: Use... |
| CVE-2026-43513 | HIGH | 7.5 | 0.5% | May 12, 2026 | Improper Handling of Case Sensitivity vulnerability in LockOutRealm in Apache Tomcat. This issue affects Apache Tomcat:... |
| CVE-2026-42498 | HIGH | 7.3 | 0.5% | May 12, 2026 | Exposure of HTTP Authentication Header to unexpected hosts during WebSocket authentication vulnerability in Apache Tomca... |
| CVE-2026-41284 | HIGH | 7.5 | 0.8% | May 12, 2026 | Allocation of Resources Without Limits or Throttling vulnerability in Apache Tomcat. This issue affects Apache Tomcat: ... |
| CVE-2026-31225 | HIGH | 8.8 | 0.4% | May 12, 2026 | The superduper project thru v0.10.0 contains a critical remote code execution vulnerability in its query parsing compone... |
| CVE-2026-31224 | HIGH | 8.8 | 0.4% | May 12, 2026 | The snorkel library thru v0.10.0 contains an insecure deserialization vulnerability (CWE-502) in the MultitaskClassifier... |
| CVE-2026-31223 | HIGH | 8.8 | 0.4% | May 12, 2026 | The snorkel library thru v0.10.0 contains a critical insecure deserialization vulnerability (CWE-502) in the BaseLabeler... |
| CVE-2026-31222 | HIGH | 8.8 | 0.4% | May 12, 2026 | The snorkel library thru v0.10.0 contains an insecure deserialization vulnerability (CWE-502) in the Trainer.load() meth... |
| CVE-2026-31221 | HIGH | 7.8 | 0.4% | May 12, 2026 | PyTorch-Lightning versions 2.6.0 and earlier contain an insecure deserialization vulnerability (CWE-502) in the checkpoi... |
| CVE-2026-31219 | HIGH | 8.8 | 0.6% | May 12, 2026 | The _load_model() function in the neural_magic_training.py script of the optimate project in commit a6d302f912b481c94370... |
| CVE-2026-31218 | HIGH | 8.8 | 0.6% | May 12, 2026 | The _load_model() function in the neural_magic_training.py script of the optimate project in commit a6d302f912b481c94370... |
| CVE-2026-30810 | HIGH | 8.8 | 0.3% | May 12, 2026 | Server-Side Request Forgery vulnerability allows Privilege Escalation via API Checker extension. This issue affects Pand... |
| CVE-2026-30808 | HIGH | 8.1 | 0.3% | May 12, 2026 | Session Fixation vulnerability allows Session Hijacking via crafted session ID. This issue affects Pandora FMS: from 777... |
| CVE-2026-30807 | HIGH | 8.8 | 0.1% | May 12, 2026 | Cross-Site Request Forgery vulnerability allows an attacker to perform unauthorized actions via crafted web page. This i... |
| CVE-2026-8111 | HIGH | 8.8 | 0.9% | May 12, 2026 | SQL injection in the web console of Ivanti Endpoint Manager before version 2024 SU6 allows a remote authenticated attack... |
| CVE-2026-8110 | HIGH | 7.8 | 0.2% | May 12, 2026 | Incorrect permissions assignment in the agent of Ivanti Endpoint Manager before version 2024 SU6 allows a local authenti... |
| CVE-2026-8051 | HIGH | 7.2 | 1.9% | May 12, 2026 | OS command injection in Ivanti Virtual Traffic Manager before version 22.9r4 allows a remote authenticated attacker with... |
| CVE-2026-7432 | HIGH | 7 | 0.3% | May 12, 2026 | A race condition in Ivanti Secure Access Client before 22.8R6 allows a locally authenticated user to escalate privileges... |
| CVE-2026-6866 | HIGH | 7.5 | 0.3% | May 12, 2026 | CWE-1188 Initialization of a Resource with an Insecure Default vulnerability exists that could cause unauthorized disclo... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now