2026 CVE Vulnerabilities
51,889 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-7220 | HIGH | 7.3 | 1.3% | Apr 28, 2026 | A vulnerability has been found in jackwrichards FastlyMCP up to 6f3d0b0e654fc51076badc7fa16c03c461f95620. This impacts a... |
| CVE-2026-7219 | HIGH | 7.3 | 0.6% | Apr 28, 2026 | A flaw has been found in Totolink N300RT 3.4.0-B20250430. This affects an unknown function of the file /boafrm/formIpQoS... |
| CVE-2026-7218 | HIGH | 7.3 | 0.5% | Apr 28, 2026 | A vulnerability was detected in Totolink N300RT 3.4.0-B20250430. The impacted element is the function is_cmd_string_vali... |
| CVE-2026-7216 | HIGH | 7.3 | 0.4% | Apr 28, 2026 | A weakness has been identified in donchelo processing-claude-mcp-bridge up to e017b20a4b592a45531a6392f494007f04e661bd. ... |
| CVE-2026-7215 | HIGH | 7.3 | 1.3% | Apr 28, 2026 | A security flaw has been discovered in egtai gmx-vmd-mcp up to 0.1.0. This issue affects the function launch_vmd_gui_too... |
| CVE-2026-1460 | HIGH | 7.2 | 1.2% | Apr 28, 2026 | A post-authentication command injection vulnerability in the “DomainName” parameter of the DHCP configuration file in Zy... |
| CVE-2026-7214 | HIGH | 7.3 | 0.4% | Apr 28, 2026 | A vulnerability was identified in eghuzefa engineer-your-data up to 0.1.3. This vulnerability affects the function read_... |
| CVE-2026-7213 | HIGH | 7.3 | 0.4% | Apr 28, 2026 | A vulnerability was detected in ef10007 MLOps_MCP 1.0.0. This impacts an unknown function of the file fastmcp_server.py ... |
| CVE-2026-7212 | HIGH | 7.3 | 0.4% | Apr 28, 2026 | A security vulnerability has been detected in edvardlindelof notes-mcp up to 0.1.4. This affects an unknown function of ... |
| CVE-2026-7211 | HIGH | 7.3 | 1.3% | Apr 28, 2026 | A weakness has been identified in dvladimirov MCP up to 0.1.0. The impacted element is the function GitSearchRequest of ... |
| CVE-2026-7206 | HIGH | 7.3 | 0.3% | Apr 28, 2026 | A security flaw has been discovered in dubydu sqlite-mcp up to 0.1.0. The affected element is the function extract_to_js... |
| CVE-2026-7205 | HIGH | 7.3 | 0.4% | Apr 28, 2026 | A vulnerability was identified in duartium papers-mcp-server 9ceb3812a6458ba7922ca24a7406f8807bc55598. Impacted is the f... |
| CVE-2026-32649 | HIGH | 7.3 | 0.9% | Apr 28, 2026 | A command injection vulnerability exists in the web server of specific firmware versions of Milesight cameras. |
| CVE-2026-20766 | HIGH | 8.8 | 0.3% | Apr 28, 2026 | An out-of-bounds memory access vulnerability exists in specific firmware versions of Milesight AIOT cameras. |
| CVE-2026-7199 | HIGH | 7.3 | 0.3% | Apr 28, 2026 | A vulnerability was detected in SourceCodester Pharmacy Sales and Inventory System 1.0. Affected by this vulnerability i... |
| CVE-2026-41371 | HIGH | 8.5 | 0.3% | Apr 28, 2026 | OpenClaw before 2026.3.28 contains a privilege escalation vulnerability in chat.send that allows write-scoped gateway ca... |
| CVE-2026-41370 | HIGH | 7.1 | 0.4% | Apr 28, 2026 | OpenClaw before 2026.3.31 contains a path traversal vulnerability in ACP dispatch that allows attackers to read arbitrar... |
| CVE-2026-41369 | HIGH | 7.1 | 0.3% | Apr 28, 2026 | OpenClaw before 2026.3.31 contains insufficient environment variable sanitization in host exec operations, failing to fi... |
| CVE-2026-41368 | HIGH | 7.1 | 0.2% | Apr 28, 2026 | OpenClaw before 2026.3.28 contains an environment variable disclosure vulnerability in the jq safe-bin policy that fails... |
| CVE-2026-41364 | HIGH | 8.1 | 0.5% | Apr 28, 2026 | OpenClaw before 2026.3.31 contains a symlink following vulnerability in SSH sandbox tar upload that allows remote attack... |
| CVE-2026-40975 | HIGH | 7.5 | 0.3% | Apr 28, 2026 | Values produced by ${random.value} are not suitable for use as secrets. ${random.uuid} is not affected. ${random.int} an... |
| CVE-2026-40973 | HIGH | 7 | 0.1% | Apr 28, 2026 | A local attacker on the same host as the application may be able to take control of the directory used by `ApplicationTe... |
| CVE-2026-40972 | HIGH | 7.5 | 0.3% | Apr 28, 2026 | An attacker on the same network as the remote application may be able to utilize a timing attack to discover information... |
| CVE-2026-27785 | HIGH | 8.8 | 0.2% | Apr 28, 2026 | Specific firmware versions of Milesight AIOT camera firmware contain hard-coded credentials. |
| CVE-2026-7194 | HIGH | 7.3 | 0.3% | Apr 27, 2026 | A weakness has been identified in SourceCodester Pharmacy Sales and Inventory System 1.0. This impacts an unknown functi... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now