2026 CVE Vulnerabilities

51,899 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-40975HIGH7.5Values produced by ${random.value} are not suitable for use as secrets. ${random.uuid} is not affected. ${random.int} an...
CVE-2026-40973HIGH7A local attacker on the same host as the application may be able to take control of the directory used by `ApplicationTe...
CVE-2026-40972HIGH7.5An attacker on the same network as the remote application may be able to utilize a timing attack to discover information...
CVE-2026-27785HIGH8.8Specific firmware versions of Milesight AIOT camera firmware contain hard-coded credentials.
CVE-2026-7194HIGH7.3A weakness has been identified in SourceCodester Pharmacy Sales and Inventory System 1.0. This impacts an unknown functi...
CVE-2026-28747HIGH7.3A weak key generation vulnerability exists in specific firmware versions of Milesight AIOT cameras allows authorization ...
CVE-2026-7178HIGH7.3A weakness has been identified in ChatGPTNextWeb NextChat up to 2.16.1. This affects the function storeUrl of the file a...
CVE-2026-7177HIGH7.3A security flaw has been discovered in ChatGPTNextWeb NextChat up to 2.16.1. Affected by this issue is the function prox...
CVE-2026-7160HIGH8.8A vulnerability was determined in Tenda HG3 2.0. This vulnerability affects the function formTracert of the file /boafor...
CVE-2026-7159HIGH7.3A vulnerability was found in douinc mkdocs-mcp-plugin up to 0.4.1. This affects the function read_document/list_document...
CVE-2026-7191HIGH8.6Improper use of the static-eval npm package in the open source solution qnabot-on-aws versions 7.2.4 and earlier may all...
CVE-2026-7158HIGH7.3A vulnerability has been found in dmitryglhf mcp-url-downloader up to 4b8cf2de55f6e8864a77d108e8a94a5b8e4394c6. Affected...
CVE-2026-7157HIGH7.3A flaw has been found in disler aider-mcp-server up to b2516fa466d0d851932da92ee6d0e66946db9efc. Affected by this vulner...
CVE-2026-3087HIGH7.5If `shutil.unpack_archive()` is given a ZIP archive with an absolute Windows path containing a drive (`C:\\...`) then th...
CVE-2026-7151HIGH8.8A vulnerability was determined in Tenda HG3 2.0. Impacted is the function formUploadConfig of the file /boaform/formIPv6...
CVE-2026-6741HIGH8.8The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Privilege Esca...
CVE-2026-5394HIGH7An authenticated administrative user who can import or save DataObject class definitions can inject attacker-controlled ...
CVE-2026-7149HIGH7.3A vulnerability has been found in dexhunter kaggle-mcp up to 406127ffcb2b91b8c10e20e6c2ca787fbc1dc92d. This vulnerabilit...
CVE-2026-7147HIGH7.3A vulnerability was detected in JoeCastrom mcp-chat-studio up to 1.5.0. Affected by this issue is some unknown functiona...
CVE-2026-32655HIGH7.8Dell Alienware Command Center (AWCC), versions prior to 6.13.8.0, contain a Least Privilege Violation vulnerability. A l...
CVE-2026-31256HIGH7.5A null pointer dereference vulnerability exists in the RTSP service of the MERCURY MIPC252W 1.0.5 Build 230306 Rel.79931...
CVE-2026-7146HIGH7.3A security vulnerability has been detected in AlejandroArciniegas mcp-data-vis up to de5a51525a69822290eaee569a1ab447b49...
CVE-2026-31690HIGH7.8In the Linux kernel, the following vulnerability has been resolved: firmware: thead: Fix buffer overflow and use standa...
CVE-2026-31686HIGH7.8In the Linux kernel, the following vulnerability has been resolved: mm/kasan: fix double free for kasan pXds kasan_fre...
CVE-2026-25908HIGH7.8Dell Alienware Command Center (AWCC), versions prior to 6.13.8.0, contain an Execution with Unnecessary Privileges vulne...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now