2026 CVE Vulnerabilities

51,820 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-41604HIGH8.2Out-of-bounds Read vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.23.0. Users are recommen...
CVE-2026-41602HIGH7.5Integer Overflow or Wraparound vulnerability in Apache Thrift TFramedTransport Go language implementation This issue af...
CVE-2026-7247HIGH7.3A vulnerability has been found in D-Link DI-8100 16.07.26A1. Affected by this issue is the function file_exten_asp of th...
CVE-2026-40978HIGH8.8SQL injection vulnerability in Spring AI's `CosmosDBVectorStore` allows attackers to execute arbitrary SQL queries via c...
CVE-2026-7237HIGH7.3A vulnerability was detected in AgiFlow scaffold-mcp up to 1.0.27. Affected by this issue is some unknown functionality ...
CVE-2026-41526HIGH7.8In KDE KCoreAddons before 6.25, KShell::quoteArgs is intended to safely quote arguments so that they can be passed to a ...
CVE-2026-7234HIGH7.3A weakness has been identified in BrowserOperator browser-operator-core up to 0.6.0. Affected is the function startsWith...
CVE-2026-40967HIGH8.6In Spring AI, various FilterExpressionConverter implementations accept a filter expression object and translate them to ...
CVE-2026-40356HIGH7.5In MIT Kerberos 5 (aka krb5) before 1.22.3, there is an integer underflow and resultant out-of-bounds read if an applica...
CVE-2026-7228HIGH7.3A flaw has been found in SourceCodester Pizzafy Ecommerce System 1.0. The affected element is the function get_cart_coun...
CVE-2026-7227HIGH7.3A vulnerability was detected in SourceCodester Pizzafy Ecommerce System 1.0. Impacted is the function Login of the file ...
CVE-2026-7226HIGH7.3A security vulnerability has been detected in SourceCodester Pizzafy Ecommerce System 1.0. This issue affects the functi...
CVE-2026-7225HIGH7.3A weakness has been identified in SourceCodester Pizzafy Ecommerce System 1.0. This vulnerability affects the function d...
CVE-2026-7224HIGH7.3A security flaw has been discovered in SourceCodester Pizzafy Ecommerce System 1.0. This affects the function delete_car...
CVE-2026-42510HIGH7.2OpenStack Ironic before 35.0.1 allows ipmitool execution in a non-default configuration that has a console interface.
CVE-2026-40355HIGH7.5In MIT Kerberos 5 (aka krb5) before 1.22.3, there is a NULL pointer dereference if an application calls gss_accept_sec_c...
CVE-2026-7223HIGH7.3A vulnerability was identified in BigSweetPotatoStudio HyperChat up to 2.0.0-alpha.63. Affected by this issue is the fun...
CVE-2026-7221HIGH7.3A vulnerability was found in TencentCloudBase CloudBase-MCP up to 2.17.0. Affected is the function openUrl of the file m...
CVE-2026-7220HIGH7.3A vulnerability has been found in jackwrichards FastlyMCP up to 6f3d0b0e654fc51076badc7fa16c03c461f95620. This impacts a...
CVE-2026-7219HIGH7.3A flaw has been found in Totolink N300RT 3.4.0-B20250430. This affects an unknown function of the file /boafrm/formIpQoS...
CVE-2026-7218HIGH7.3A vulnerability was detected in Totolink N300RT 3.4.0-B20250430. The impacted element is the function is_cmd_string_vali...
CVE-2026-7216HIGH7.3A weakness has been identified in donchelo processing-claude-mcp-bridge up to e017b20a4b592a45531a6392f494007f04e661bd. ...
CVE-2026-7215HIGH7.3A security flaw has been discovered in egtai gmx-vmd-mcp up to 0.1.0. This issue affects the function launch_vmd_gui_too...
CVE-2026-1460HIGH7.2A post-authentication command injection vulnerability in the “DomainName” parameter of the DHCP configuration file in Zy...
CVE-2026-7214HIGH7.3A vulnerability was identified in eghuzefa engineer-your-data up to 0.1.3. This vulnerability affects the function read_...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now