2026 CVE Vulnerabilities
51,872 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-41605 | HIGH | 7.3 | 0.9% | Apr 28, 2026 | Integer Overflow or Wraparound vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.23.0. Users ... |
| CVE-2026-41604 | HIGH | 8.2 | 0.9% | Apr 28, 2026 | Out-of-bounds Read vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.23.0. Users are recommen... |
| CVE-2026-41602 | HIGH | 7.5 | 1.2% | Apr 28, 2026 | Integer Overflow or Wraparound vulnerability in Apache Thrift TFramedTransport Go language implementation This issue af... |
| CVE-2026-7247 | HIGH | 7.3 | 0.7% | Apr 28, 2026 | A vulnerability has been found in D-Link DI-8100 16.07.26A1. Affected by this issue is the function file_exten_asp of th... |
| CVE-2026-40978 | HIGH | 8.8 | 0.3% | Apr 28, 2026 | SQL injection vulnerability in Spring AI's `CosmosDBVectorStore` allows attackers to execute arbitrary SQL queries via c... |
| CVE-2026-7237 | HIGH | 7.3 | 0.4% | Apr 28, 2026 | A vulnerability was detected in AgiFlow scaffold-mcp up to 1.0.27. Affected by this issue is some unknown functionality ... |
| CVE-2026-41526 | HIGH | 7.8 | 0.2% | Apr 28, 2026 | In KDE KCoreAddons before 6.25, KShell::quoteArgs is intended to safely quote arguments so that they can be passed to a ... |
| CVE-2026-7234 | HIGH | 7.3 | 0.4% | Apr 28, 2026 | A weakness has been identified in BrowserOperator browser-operator-core up to 0.6.0. Affected is the function startsWith... |
| CVE-2026-40967 | HIGH | 8.6 | 0.4% | Apr 28, 2026 | In Spring AI, various FilterExpressionConverter implementations accept a filter expression object and translate them to ... |
| CVE-2026-40356 | HIGH | 7.5 | 0.5% | Apr 28, 2026 | In MIT Kerberos 5 (aka krb5) before 1.22.3, there is an integer underflow and resultant out-of-bounds read if an applica... |
| CVE-2026-7228 | HIGH | 7.3 | 0.3% | Apr 28, 2026 | A flaw has been found in SourceCodester Pizzafy Ecommerce System 1.0. The affected element is the function get_cart_coun... |
| CVE-2026-7227 | HIGH | 7.3 | 0.3% | Apr 28, 2026 | A vulnerability was detected in SourceCodester Pizzafy Ecommerce System 1.0. Impacted is the function Login of the file ... |
| CVE-2026-7226 | HIGH | 7.3 | 0.3% | Apr 28, 2026 | A security vulnerability has been detected in SourceCodester Pizzafy Ecommerce System 1.0. This issue affects the functi... |
| CVE-2026-7225 | HIGH | 7.3 | 0.3% | Apr 28, 2026 | A weakness has been identified in SourceCodester Pizzafy Ecommerce System 1.0. This vulnerability affects the function d... |
| CVE-2026-7224 | HIGH | 7.3 | 0.3% | Apr 28, 2026 | A security flaw has been discovered in SourceCodester Pizzafy Ecommerce System 1.0. This affects the function delete_car... |
| CVE-2026-42510 | HIGH | 7.2 | 0.6% | Apr 28, 2026 | OpenStack Ironic before 35.0.1 allows ipmitool execution in a non-default configuration that has a console interface. |
| CVE-2026-40355 | HIGH | 7.5 | 0.5% | Apr 28, 2026 | In MIT Kerberos 5 (aka krb5) before 1.22.3, there is a NULL pointer dereference if an application calls gss_accept_sec_c... |
| CVE-2026-7223 | HIGH | 7.3 | 0.3% | Apr 28, 2026 | A vulnerability was identified in BigSweetPotatoStudio HyperChat up to 2.0.0-alpha.63. Affected by this issue is the fun... |
| CVE-2026-7221 | HIGH | 7.3 | 0.3% | Apr 28, 2026 | A vulnerability was found in TencentCloudBase CloudBase-MCP up to 2.17.0. Affected is the function openUrl of the file m... |
| CVE-2026-7220 | HIGH | 7.3 | 1.3% | Apr 28, 2026 | A vulnerability has been found in jackwrichards FastlyMCP up to 6f3d0b0e654fc51076badc7fa16c03c461f95620. This impacts a... |
| CVE-2026-7219 | HIGH | 7.3 | 0.6% | Apr 28, 2026 | A flaw has been found in Totolink N300RT 3.4.0-B20250430. This affects an unknown function of the file /boafrm/formIpQoS... |
| CVE-2026-7218 | HIGH | 7.3 | 0.5% | Apr 28, 2026 | A vulnerability was detected in Totolink N300RT 3.4.0-B20250430. The impacted element is the function is_cmd_string_vali... |
| CVE-2026-7216 | HIGH | 7.3 | 0.4% | Apr 28, 2026 | A weakness has been identified in donchelo processing-claude-mcp-bridge up to e017b20a4b592a45531a6392f494007f04e661bd. ... |
| CVE-2026-7215 | HIGH | 7.3 | 1.3% | Apr 28, 2026 | A security flaw has been discovered in egtai gmx-vmd-mcp up to 0.1.0. This issue affects the function launch_vmd_gui_too... |
| CVE-2026-1460 | HIGH | 7.2 | 1.2% | Apr 28, 2026 | A post-authentication command injection vulnerability in the “DomainName” parameter of the DHCP configuration file in Zy... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now