2026 CVE Vulnerabilities

57,035 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-61441HIGH7.1PraisonAI Platform (praisonai-platform) before 0.1.9 improperly authorizes deletion of issue dependencies. The DELETE de...
CVE-2026-61437HIGH8.5PraisonAI (pip package praisonaiagents) before 1.6.78 contains an unsafe dynamic module loading vulnerability in AgentFl...
CVE-2026-61434HIGH8.8PraisonAI versions before 4.6.78 contain an allowlist bypass vulnerability in shell command execution that allows attack...
CVE-2026-61432MEDIUM6.9PraisonAI (praisonaiagents) before 1.6.78 contains a path traversal vulnerability in the FastContext feature (praisonaia...
CVE-2026-61431MEDIUM6.8PraisonAI before 4.6.78 contains a path traversal vulnerability in ContextGatherer that fails to validate include paths ...
CVE-2026-60091HIGH7.2PraisonAI before 4.6.78 contains an unauthenticated server-side request forgery vulnerability in the Jobs API /api/v1/ru...
CVE-2026-60089MEDIUM6.9PraisonAI (pip package praisonaiagents) before 1.6.78 automatically loads defaults from a project-local .praisonai/confi...
CVE-2026-60086MEDIUM6.9PraisonAI before 4.6.78 contains a prompt injection defense bypass vulnerability where the injection defense only blocks...
CVE-2026-59796HIGH8.1In JetBrains TeamCity before 2026.1.2 pipeline modification was possible due to improper permission checks
CVE-2026-59795MEDIUM6.1In JetBrains TeamCity before 2026.1.2 stored XSS via unauthenticated agent registration was possible
CVE-2026-59794MEDIUM5.4In JetBrains TeamCity before 2026.1.2 stored XSS on the cloud profile page was possible via agent-reported data
CVE-2026-59793HIGH8.8In JetBrains TeamCity before 2026.1.2 arbitrary file access was possible via the Perforce VCS integration
CVE-2026-59792CRITICAL9.8In JetBrains IntelliJ IDEA before 2026.1.4, 2026.2 code execution via path traversal in project workspace ID handling w...
CVE-2026-59791LOW3.5In JetBrains YouTrack before 2026.2.17012 cSS injection via Mermaid diagram rendering was possible
CVE-2026-58661MEDIUM4.3n8n before 2.28.0 (and before 1.123.58 on the 1.x branch) contains a disk space exhaustion vulnerability in the data-tab...
CVE-2026-57994MEDIUM6.9phpMyFAQ before 4.1.5 applies inconsistent active=yes and publication-date filtering across its public FAQ API endpoints...
CVE-2026-57961MEDIUM5.1phpMyFAQ before 4.1.5 contains a potential authenticated path traversal vulnerability in the concatenatePaths() function...
CVE-2026-56765CRITICAL9.8Vikunja before 2.2.1 contains an authorization flaw where the LinkSharing.ReadAll endpoint exposes share hashes to users...
CVE-2026-56373MEDIUM5.3ImageMagick before 7.1.2-15 contains a use-after-free vulnerability in the PDB decoder that uses a stale pointer when me...
CVE-2026-56366MEDIUM6.5ImageMagick before 7.1.2-18 contains a memory leak vulnerability in the META reader when processing APP1JPEG input paths...
CVE-2026-56354MEDIUM5.4n8n before 1.123.24, 2.10.4, and 2.12.0 (across its 1.x and 2.x branches) contains cross-site scripting and open redirec...
CVE-2026-56335HIGH7.1Capgo before 12.128.2 contains an authorization bypass vulnerability where write-scoped API keys can directly mutate pro...
CVE-2026-56329MEDIUM6.4Capgo before 12.128.2 contains a cross-tenant preview namespace collision vulnerability caused by non-bijective decoding...
CVE-2026-56312MEDIUM6.9Capgo before 12.128.2 contains an improper validation vulnerability in the accept_invitation endpoint that creates user ...
CVE-2026-56309MEDIUM5.4Capgo before 12.128.2 fails to enforce plan/quota restrictions on the /files/upload/attachments endpoint, allowing plan-...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now