2026 CVE Vulnerabilities

51,812 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-38651HIGH8.2Authentication Bypass vulnerability exists in Netmaker versions prior to 1.5.0. The VerifyHostToken function in logic/jw...
CVE-2026-7324HIGH7.3Memory safety bugs present in Thunderbird 150.0.0. Some of these bugs showed evidence of memory corruption and we presum...
CVE-2026-7323HIGH7.3Memory safety bugs present in Thunderbird ESR 140.10.0 and Thunderbird 150.0.0. Some of these bugs showed evidence of me...
CVE-2026-7322HIGH7.3Memory safety bugs present in Thunderbird ESR 140.10.0 and Thunderbird 150.0.0. Some of these bugs showed evidence of me...
CVE-2026-7320HIGH7.5Information disclosure due to incorrect boundary conditions in the Audio/Video component. This vulnerability was fixed i...
CVE-2026-7289HIGH8.8A vulnerability was found in D-Link DIR-825M 1.1.12. This issue affects the function sub_414BA8 of the file /boafrm/form...
CVE-2026-7288HIGH8.8A vulnerability has been found in D-Link DIR-825M 1.1.12. This vulnerability affects the function sub_4151FC of the file...
CVE-2026-40968HIGH8.8When an authenticated user is denied access to a gRPC method, their authenticated identity remains bound to the gRPC wor...
CVE-2026-7272HIGH7.3A flaw has been found in WilliamCloudQi matlab-mcp-server up to ab88f6b9bf5f36f725e8628029f7f6dd0d9913ca. The affected e...
CVE-2026-5944HIGH8.2An improper access control vulnerability exists in the Cisco Intersight Device Connector for Nutanix Prism Central. The ...
CVE-2026-40551HIGH8.4mpGabinet performs client-side authentication. An attacker with access to any application instance connected to the back...
CVE-2026-5781HIGH8.8An authorization vulnerability in MphRx's Minerva V3.6.0, specifically in the '/minerva/moUser/update' endpoint, could a...
CVE-2026-5780HIGH8.1An insecure direct object reference (IDOR) vulnerability in MphRx's Minerva V3.6.0, specifically in the endpoint '/miner...
CVE-2026-5779HIGH8.8An insecure direct object reference (IDOR) vulnerability in MphRx's Minerva V3.6.0, specifically in the '/minerva/user/u...
CVE-2026-5435HIGH7.3The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.2 and newer fail to enforc...
CVE-2026-3323HIGH7.5An unsecured configuration interface on affected devices allows unauthenticated remote attackers to access sensitive inf...
CVE-2026-7280HIGH8.4AVACAST developed by eMPIA Technology has a Unquoted Service Path vulnerability, allowing privileged local attackers to ...
CVE-2026-7279HIGH8.5AVACAST developed by eMPIA Technology, has a DLL Hijacking vulnerability, allowing authenticated local attackers to plac...
CVE-2026-41636HIGH7.5Uncontrolled Recursion vulnerability in Apache Thrift Node.js bindings This issue affects Apache Thrift: before 0.23.0....
CVE-2026-41605HIGH7.3Integer Overflow or Wraparound vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.23.0. Users ...
CVE-2026-41604HIGH8.2Out-of-bounds Read vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.23.0. Users are recommen...
CVE-2026-41602HIGH7.5Integer Overflow or Wraparound vulnerability in Apache Thrift TFramedTransport Go language implementation This issue af...
CVE-2026-7247HIGH7.3A vulnerability has been found in D-Link DI-8100 16.07.26A1. Affected by this issue is the function file_exten_asp of th...
CVE-2026-40978HIGH8.8SQL injection vulnerability in Spring AI's `CosmosDBVectorStore` allows attackers to execute arbitrary SQL queries via c...
CVE-2026-7237HIGH7.3A vulnerability was detected in AgiFlow scaffold-mcp up to 1.0.27. Affected by this issue is some unknown functionality ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now