2026 CVE Vulnerabilities
57,021 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-46388 | MEDIUM | 4.4 | — | Jul 10, 2026 | osquery is a SQL powered operating system instrumentation, monitoring, and analytics framework. Prior to 5.23.1, an unpr... |
| CVE-2026-33382 | HIGH | 7.5 | 0.4% | Jul 10, 2026 | Several Grafana API endpoints, some of them unauthenticated, do not limit the size of the request body before processing... |
| CVE-2026-15375 | MEDIUM | 4.3 | 0.2% | Jul 10, 2026 | A vulnerability has been found in Eleveo Call Recording Software 9.7.0. This impacts an unknown function of the file /ca... |
| CVE-2026-15374 | MEDIUM | 6.3 | 0.3% | Jul 10, 2026 | A flaw has been found in Eleveo Call Recording Software 9.7.0. This affects an unknown function of the file /callrec/rol... |
| CVE-2026-15373 | MEDIUM | 6.3 | 0.3% | Jul 10, 2026 | A vulnerability was detected in Eleveo Call Recording Software 9.7.0. The impacted element is an unknown function of the... |
| CVE-2026-15143 | CRITICAL | 9.3 | 0.4% | Jul 10, 2026 | A flaw was found in the file_type content detector of guardrails-detectors. This vulnerability allows a remote attacker ... |
| CVE-2026-61492 | MEDIUM | 6.1 | — | Jul 10, 2026 | In JetBrains YouTrack before 2026.2.17394 stored XSS via article titles in digest emails was possible |
| CVE-2026-61456 | MEDIUM | 5.1 | — | Jul 10, 2026 | The Grav API plugin (getgrav/grav-plugin-api) before 1.0.3 fails to sanitize SVG files uploaded through the POST /api/v1... |
| CVE-2026-61455 | HIGH | 7.1 | — | Jul 10, 2026 | Grav before 2.0.1 contains a decompression bomb vulnerability in ZipArchiver::extract() that lacks limits on uncompresse... |
| CVE-2026-61450 | HIGH | 7.1 | — | Jul 10, 2026 | Grav before 2.0.2 contains a Twig sandbox bypass that allows a page author (any admin.pages user, or anyone able to writ... |
| CVE-2026-61444 | CRITICAL | 9.4 | — | Jul 10, 2026 | PraisonAI versions before 4.6.78 contain a code injection vulnerability in deploy/api.py where the agents_file parameter... |
| CVE-2026-61441 | HIGH | 7.1 | — | Jul 10, 2026 | PraisonAI Platform (praisonai-platform) before 0.1.9 improperly authorizes deletion of issue dependencies. The DELETE de... |
| CVE-2026-61437 | HIGH | 8.5 | 0.1% | Jul 10, 2026 | PraisonAI (pip package praisonaiagents) before 1.6.78 contains an unsafe dynamic module loading vulnerability in AgentFl... |
| CVE-2026-61434 | HIGH | 8.8 | — | Jul 10, 2026 | PraisonAI versions before 4.6.78 contain an allowlist bypass vulnerability in shell command execution that allows attack... |
| CVE-2026-61432 | MEDIUM | 6.9 | — | Jul 10, 2026 | PraisonAI (praisonaiagents) before 1.6.78 contains a path traversal vulnerability in the FastContext feature (praisonaia... |
| CVE-2026-61431 | MEDIUM | 6.8 | — | Jul 10, 2026 | PraisonAI before 4.6.78 contains a path traversal vulnerability in ContextGatherer that fails to validate include paths ... |
| CVE-2026-60091 | HIGH | 7.2 | — | Jul 10, 2026 | PraisonAI before 4.6.78 contains an unauthenticated server-side request forgery vulnerability in the Jobs API /api/v1/ru... |
| CVE-2026-60089 | MEDIUM | 6.9 | — | Jul 10, 2026 | PraisonAI (pip package praisonaiagents) before 1.6.78 automatically loads defaults from a project-local .praisonai/confi... |
| CVE-2026-60086 | MEDIUM | 6.9 | 0.2% | Jul 10, 2026 | PraisonAI before 4.6.78 contains a prompt injection defense bypass vulnerability where the injection defense only blocks... |
| CVE-2026-59796 | HIGH | 8.1 | 0.2% | Jul 10, 2026 | In JetBrains TeamCity before 2026.1.2 pipeline modification was possible due to improper permission checks |
| CVE-2026-59795 | MEDIUM | 6.1 | 0.3% | Jul 10, 2026 | In JetBrains TeamCity before 2026.1.2 stored XSS via unauthenticated agent registration was possible |
| CVE-2026-59794 | MEDIUM | 5.4 | — | Jul 10, 2026 | In JetBrains TeamCity before 2026.1.2 stored XSS on the cloud profile page was possible via agent-reported data |
| CVE-2026-59793 | HIGH | 8.8 | 0.3% | Jul 10, 2026 | In JetBrains TeamCity before 2026.1.2 arbitrary file access was possible via the Perforce VCS integration |
| CVE-2026-59792 | CRITICAL | 9.8 | 0.4% | Jul 10, 2026 | In JetBrains IntelliJ IDEA before 2026.1.4, 2026.2 code execution via path traversal in project workspace ID handling w... |
| CVE-2026-59791 | LOW | 3.5 | — | Jul 10, 2026 | In JetBrains YouTrack before 2026.2.17012 cSS injection via Mermaid diagram rendering was possible |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now