2026 CVE Vulnerabilities

51,872 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-41605HIGH7.3Integer Overflow or Wraparound vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.23.0. Users ...
CVE-2026-41604HIGH8.2Out-of-bounds Read vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.23.0. Users are recommen...
CVE-2026-41602HIGH7.5Integer Overflow or Wraparound vulnerability in Apache Thrift TFramedTransport Go language implementation This issue af...
CVE-2026-7247HIGH7.3A vulnerability has been found in D-Link DI-8100 16.07.26A1. Affected by this issue is the function file_exten_asp of th...
CVE-2026-40978HIGH8.8SQL injection vulnerability in Spring AI's `CosmosDBVectorStore` allows attackers to execute arbitrary SQL queries via c...
CVE-2026-7237HIGH7.3A vulnerability was detected in AgiFlow scaffold-mcp up to 1.0.27. Affected by this issue is some unknown functionality ...
CVE-2026-41526HIGH7.8In KDE KCoreAddons before 6.25, KShell::quoteArgs is intended to safely quote arguments so that they can be passed to a ...
CVE-2026-7234HIGH7.3A weakness has been identified in BrowserOperator browser-operator-core up to 0.6.0. Affected is the function startsWith...
CVE-2026-40967HIGH8.6In Spring AI, various FilterExpressionConverter implementations accept a filter expression object and translate them to ...
CVE-2026-40356HIGH7.5In MIT Kerberos 5 (aka krb5) before 1.22.3, there is an integer underflow and resultant out-of-bounds read if an applica...
CVE-2026-7228HIGH7.3A flaw has been found in SourceCodester Pizzafy Ecommerce System 1.0. The affected element is the function get_cart_coun...
CVE-2026-7227HIGH7.3A vulnerability was detected in SourceCodester Pizzafy Ecommerce System 1.0. Impacted is the function Login of the file ...
CVE-2026-7226HIGH7.3A security vulnerability has been detected in SourceCodester Pizzafy Ecommerce System 1.0. This issue affects the functi...
CVE-2026-7225HIGH7.3A weakness has been identified in SourceCodester Pizzafy Ecommerce System 1.0. This vulnerability affects the function d...
CVE-2026-7224HIGH7.3A security flaw has been discovered in SourceCodester Pizzafy Ecommerce System 1.0. This affects the function delete_car...
CVE-2026-42510HIGH7.2OpenStack Ironic before 35.0.1 allows ipmitool execution in a non-default configuration that has a console interface.
CVE-2026-40355HIGH7.5In MIT Kerberos 5 (aka krb5) before 1.22.3, there is a NULL pointer dereference if an application calls gss_accept_sec_c...
CVE-2026-7223HIGH7.3A vulnerability was identified in BigSweetPotatoStudio HyperChat up to 2.0.0-alpha.63. Affected by this issue is the fun...
CVE-2026-7221HIGH7.3A vulnerability was found in TencentCloudBase CloudBase-MCP up to 2.17.0. Affected is the function openUrl of the file m...
CVE-2026-7220HIGH7.3A vulnerability has been found in jackwrichards FastlyMCP up to 6f3d0b0e654fc51076badc7fa16c03c461f95620. This impacts a...
CVE-2026-7219HIGH7.3A flaw has been found in Totolink N300RT 3.4.0-B20250430. This affects an unknown function of the file /boafrm/formIpQoS...
CVE-2026-7218HIGH7.3A vulnerability was detected in Totolink N300RT 3.4.0-B20250430. The impacted element is the function is_cmd_string_vali...
CVE-2026-7216HIGH7.3A weakness has been identified in donchelo processing-claude-mcp-bridge up to e017b20a4b592a45531a6392f494007f04e661bd. ...
CVE-2026-7215HIGH7.3A security flaw has been discovered in egtai gmx-vmd-mcp up to 0.1.0. This issue affects the function launch_vmd_gui_too...
CVE-2026-1460HIGH7.2A post-authentication command injection vulnerability in the “DomainName” parameter of the DHCP configuration file in Zy...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now