2026 CVE Vulnerabilities
51,734 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-7322 | HIGH | 7.3 | 0.3% | Apr 28, 2026 | Memory safety bugs present in Thunderbird ESR 140.10.0 and Thunderbird 150.0.0. Some of these bugs showed evidence of me... |
| CVE-2026-7320 | HIGH | 7.5 | 0.3% | Apr 28, 2026 | Information disclosure due to incorrect boundary conditions in the Audio/Video component. This vulnerability was fixed i... |
| CVE-2026-7289 | HIGH | 8.8 | 0.7% | Apr 28, 2026 | A vulnerability was found in D-Link DIR-825M 1.1.12. This issue affects the function sub_414BA8 of the file /boafrm/form... |
| CVE-2026-7288 | HIGH | 8.8 | 0.7% | Apr 28, 2026 | A vulnerability has been found in D-Link DIR-825M 1.1.12. This vulnerability affects the function sub_4151FC of the file... |
| CVE-2026-40968 | HIGH | 8.8 | 0.2% | Apr 28, 2026 | When an authenticated user is denied access to a gRPC method, their authenticated identity remains bound to the gRPC wor... |
| CVE-2026-7272 | HIGH | 7.3 | 0.4% | Apr 28, 2026 | A flaw has been found in WilliamCloudQi matlab-mcp-server up to ab88f6b9bf5f36f725e8628029f7f6dd0d9913ca. The affected e... |
| CVE-2026-5944 | HIGH | 8.2 | 0.5% | Apr 28, 2026 | An improper access control vulnerability exists in the Cisco Intersight Device Connector for Nutanix Prism Central. The ... |
| CVE-2026-40551 | HIGH | 8.4 | 0.1% | Apr 28, 2026 | mpGabinet performs client-side authentication. An attacker with access to any application instance connected to the back... |
| CVE-2026-5781 | HIGH | 8.8 | 0.2% | Apr 28, 2026 | An authorization vulnerability in MphRx's Minerva V3.6.0, specifically in the '/minerva/moUser/update' endpoint, could a... |
| CVE-2026-5780 | HIGH | 8.1 | 0.2% | Apr 28, 2026 | An insecure direct object reference (IDOR) vulnerability in MphRx's Minerva V3.6.0, specifically in the endpoint '/miner... |
| CVE-2026-5779 | HIGH | 8.8 | 0.3% | Apr 28, 2026 | An insecure direct object reference (IDOR) vulnerability in MphRx's Minerva V3.6.0, specifically in the '/minerva/user/u... |
| CVE-2026-5435 | HIGH | 7.3 | 0.2% | Apr 28, 2026 | The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.2 and newer fail to enforc... |
| CVE-2026-3323 | HIGH | 7.5 | 0.4% | Apr 28, 2026 | An unsecured configuration interface on affected devices allows unauthenticated remote attackers to access sensitive inf... |
| CVE-2026-7280 | HIGH | 8.4 | 0.1% | Apr 28, 2026 | AVACAST developed by eMPIA Technology has a Unquoted Service Path vulnerability, allowing privileged local attackers to ... |
| CVE-2026-7279 | HIGH | 8.5 | 0.1% | Apr 28, 2026 | AVACAST developed by eMPIA Technology, has a DLL Hijacking vulnerability, allowing authenticated local attackers to plac... |
| CVE-2026-41636 | HIGH | 7.5 | 0.5% | Apr 28, 2026 | Uncontrolled Recursion vulnerability in Apache Thrift Node.js bindings This issue affects Apache Thrift: before 0.23.0.... |
| CVE-2026-41605 | HIGH | 7.3 | 0.9% | Apr 28, 2026 | Integer Overflow or Wraparound vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.23.0. Users ... |
| CVE-2026-41604 | HIGH | 8.2 | 0.9% | Apr 28, 2026 | Out-of-bounds Read vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.23.0. Users are recommen... |
| CVE-2026-41602 | HIGH | 7.5 | 1.2% | Apr 28, 2026 | Integer Overflow or Wraparound vulnerability in Apache Thrift TFramedTransport Go language implementation This issue af... |
| CVE-2026-7247 | HIGH | 7.3 | 0.7% | Apr 28, 2026 | A vulnerability has been found in D-Link DI-8100 16.07.26A1. Affected by this issue is the function file_exten_asp of th... |
| CVE-2026-40978 | HIGH | 8.8 | 0.3% | Apr 28, 2026 | SQL injection vulnerability in Spring AI's `CosmosDBVectorStore` allows attackers to execute arbitrary SQL queries via c... |
| CVE-2026-7237 | HIGH | 7.3 | 0.4% | Apr 28, 2026 | A vulnerability was detected in AgiFlow scaffold-mcp up to 1.0.27. Affected by this issue is some unknown functionality ... |
| CVE-2026-41526 | HIGH | 7.8 | 0.2% | Apr 28, 2026 | In KDE KCoreAddons before 6.25, KShell::quoteArgs is intended to safely quote arguments so that they can be passed to a ... |
| CVE-2026-7234 | HIGH | 7.3 | 0.4% | Apr 28, 2026 | A weakness has been identified in BrowserOperator browser-operator-core up to 0.6.0. Affected is the function startsWith... |
| CVE-2026-40967 | HIGH | 8.6 | 0.4% | Apr 28, 2026 | In Spring AI, various FilterExpressionConverter implementations accept a filter expression object and translate them to ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now