2026 CVE Vulnerabilities

57,021 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-46388MEDIUM4.4osquery is a SQL powered operating system instrumentation, monitoring, and analytics framework. Prior to 5.23.1, an unpr...
CVE-2026-33382HIGH7.5Several Grafana API endpoints, some of them unauthenticated, do not limit the size of the request body before processing...
CVE-2026-15375MEDIUM4.3A vulnerability has been found in Eleveo Call Recording Software 9.7.0. This impacts an unknown function of the file /ca...
CVE-2026-15374MEDIUM6.3A flaw has been found in Eleveo Call Recording Software 9.7.0. This affects an unknown function of the file /callrec/rol...
CVE-2026-15373MEDIUM6.3A vulnerability was detected in Eleveo Call Recording Software 9.7.0. The impacted element is an unknown function of the...
CVE-2026-15143CRITICAL9.3A flaw was found in the file_type content detector of guardrails-detectors. This vulnerability allows a remote attacker ...
CVE-2026-61492MEDIUM6.1In JetBrains YouTrack before 2026.2.17394 stored XSS via article titles in digest emails was possible
CVE-2026-61456MEDIUM5.1The Grav API plugin (getgrav/grav-plugin-api) before 1.0.3 fails to sanitize SVG files uploaded through the POST /api/v1...
CVE-2026-61455HIGH7.1Grav before 2.0.1 contains a decompression bomb vulnerability in ZipArchiver::extract() that lacks limits on uncompresse...
CVE-2026-61450HIGH7.1Grav before 2.0.2 contains a Twig sandbox bypass that allows a page author (any admin.pages user, or anyone able to writ...
CVE-2026-61444CRITICAL9.4PraisonAI versions before 4.6.78 contain a code injection vulnerability in deploy/api.py where the agents_file parameter...
CVE-2026-61441HIGH7.1PraisonAI Platform (praisonai-platform) before 0.1.9 improperly authorizes deletion of issue dependencies. The DELETE de...
CVE-2026-61437HIGH8.5PraisonAI (pip package praisonaiagents) before 1.6.78 contains an unsafe dynamic module loading vulnerability in AgentFl...
CVE-2026-61434HIGH8.8PraisonAI versions before 4.6.78 contain an allowlist bypass vulnerability in shell command execution that allows attack...
CVE-2026-61432MEDIUM6.9PraisonAI (praisonaiagents) before 1.6.78 contains a path traversal vulnerability in the FastContext feature (praisonaia...
CVE-2026-61431MEDIUM6.8PraisonAI before 4.6.78 contains a path traversal vulnerability in ContextGatherer that fails to validate include paths ...
CVE-2026-60091HIGH7.2PraisonAI before 4.6.78 contains an unauthenticated server-side request forgery vulnerability in the Jobs API /api/v1/ru...
CVE-2026-60089MEDIUM6.9PraisonAI (pip package praisonaiagents) before 1.6.78 automatically loads defaults from a project-local .praisonai/confi...
CVE-2026-60086MEDIUM6.9PraisonAI before 4.6.78 contains a prompt injection defense bypass vulnerability where the injection defense only blocks...
CVE-2026-59796HIGH8.1In JetBrains TeamCity before 2026.1.2 pipeline modification was possible due to improper permission checks
CVE-2026-59795MEDIUM6.1In JetBrains TeamCity before 2026.1.2 stored XSS via unauthenticated agent registration was possible
CVE-2026-59794MEDIUM5.4In JetBrains TeamCity before 2026.1.2 stored XSS on the cloud profile page was possible via agent-reported data
CVE-2026-59793HIGH8.8In JetBrains TeamCity before 2026.1.2 arbitrary file access was possible via the Perforce VCS integration
CVE-2026-59792CRITICAL9.8In JetBrains IntelliJ IDEA before 2026.1.4, 2026.2 code execution via path traversal in project workspace ID handling w...
CVE-2026-59791LOW3.5In JetBrains YouTrack before 2026.2.17012 cSS injection via Mermaid diagram rendering was possible

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now