2026 CVE Vulnerabilities
57,035 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-61441 | HIGH | 7.1 | — | Jul 10, 2026 | PraisonAI Platform (praisonai-platform) before 0.1.9 improperly authorizes deletion of issue dependencies. The DELETE de... |
| CVE-2026-61437 | HIGH | 8.5 | 0.1% | Jul 10, 2026 | PraisonAI (pip package praisonaiagents) before 1.6.78 contains an unsafe dynamic module loading vulnerability in AgentFl... |
| CVE-2026-61434 | HIGH | 8.8 | — | Jul 10, 2026 | PraisonAI versions before 4.6.78 contain an allowlist bypass vulnerability in shell command execution that allows attack... |
| CVE-2026-61432 | MEDIUM | 6.9 | — | Jul 10, 2026 | PraisonAI (praisonaiagents) before 1.6.78 contains a path traversal vulnerability in the FastContext feature (praisonaia... |
| CVE-2026-61431 | MEDIUM | 6.8 | — | Jul 10, 2026 | PraisonAI before 4.6.78 contains a path traversal vulnerability in ContextGatherer that fails to validate include paths ... |
| CVE-2026-60091 | HIGH | 7.2 | — | Jul 10, 2026 | PraisonAI before 4.6.78 contains an unauthenticated server-side request forgery vulnerability in the Jobs API /api/v1/ru... |
| CVE-2026-60089 | MEDIUM | 6.9 | — | Jul 10, 2026 | PraisonAI (pip package praisonaiagents) before 1.6.78 automatically loads defaults from a project-local .praisonai/confi... |
| CVE-2026-60086 | MEDIUM | 6.9 | 0.2% | Jul 10, 2026 | PraisonAI before 4.6.78 contains a prompt injection defense bypass vulnerability where the injection defense only blocks... |
| CVE-2026-59796 | HIGH | 8.1 | 0.2% | Jul 10, 2026 | In JetBrains TeamCity before 2026.1.2 pipeline modification was possible due to improper permission checks |
| CVE-2026-59795 | MEDIUM | 6.1 | 0.3% | Jul 10, 2026 | In JetBrains TeamCity before 2026.1.2 stored XSS via unauthenticated agent registration was possible |
| CVE-2026-59794 | MEDIUM | 5.4 | — | Jul 10, 2026 | In JetBrains TeamCity before 2026.1.2 stored XSS on the cloud profile page was possible via agent-reported data |
| CVE-2026-59793 | HIGH | 8.8 | 0.3% | Jul 10, 2026 | In JetBrains TeamCity before 2026.1.2 arbitrary file access was possible via the Perforce VCS integration |
| CVE-2026-59792 | CRITICAL | 9.8 | 0.4% | Jul 10, 2026 | In JetBrains IntelliJ IDEA before 2026.1.4, 2026.2 code execution via path traversal in project workspace ID handling w... |
| CVE-2026-59791 | LOW | 3.5 | — | Jul 10, 2026 | In JetBrains YouTrack before 2026.2.17012 cSS injection via Mermaid diagram rendering was possible |
| CVE-2026-58661 | MEDIUM | 4.3 | 0.2% | Jul 10, 2026 | n8n before 2.28.0 (and before 1.123.58 on the 1.x branch) contains a disk space exhaustion vulnerability in the data-tab... |
| CVE-2026-57994 | MEDIUM | 6.9 | — | Jul 10, 2026 | phpMyFAQ before 4.1.5 applies inconsistent active=yes and publication-date filtering across its public FAQ API endpoints... |
| CVE-2026-57961 | MEDIUM | 5.1 | — | Jul 10, 2026 | phpMyFAQ before 4.1.5 contains a potential authenticated path traversal vulnerability in the concatenatePaths() function... |
| CVE-2026-56765 | CRITICAL | 9.8 | — | Jul 10, 2026 | Vikunja before 2.2.1 contains an authorization flaw where the LinkSharing.ReadAll endpoint exposes share hashes to users... |
| CVE-2026-56373 | MEDIUM | 5.3 | 0.2% | Jul 10, 2026 | ImageMagick before 7.1.2-15 contains a use-after-free vulnerability in the PDB decoder that uses a stale pointer when me... |
| CVE-2026-56366 | MEDIUM | 6.5 | 0.1% | Jul 10, 2026 | ImageMagick before 7.1.2-18 contains a memory leak vulnerability in the META reader when processing APP1JPEG input paths... |
| CVE-2026-56354 | MEDIUM | 5.4 | 0.2% | Jul 10, 2026 | n8n before 1.123.24, 2.10.4, and 2.12.0 (across its 1.x and 2.x branches) contains cross-site scripting and open redirec... |
| CVE-2026-56335 | HIGH | 7.1 | — | Jul 10, 2026 | Capgo before 12.128.2 contains an authorization bypass vulnerability where write-scoped API keys can directly mutate pro... |
| CVE-2026-56329 | MEDIUM | 6.4 | — | Jul 10, 2026 | Capgo before 12.128.2 contains a cross-tenant preview namespace collision vulnerability caused by non-bijective decoding... |
| CVE-2026-56312 | MEDIUM | 6.9 | — | Jul 10, 2026 | Capgo before 12.128.2 contains an improper validation vulnerability in the accept_invitation endpoint that creates user ... |
| CVE-2026-56309 | MEDIUM | 5.4 | — | Jul 10, 2026 | Capgo before 12.128.2 fails to enforce plan/quota restrictions on the /files/upload/attachments endpoint, allowing plan-... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now