2026 CVE Vulnerabilities

64,868 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-91925HIGH8.8Polyaxon through 2.16.4 renders operation specification fields with an unsandboxed Jinja2 environment during server-side...
CVE-2026-91924HIGH8.5pgweb through 0.17.0 leaves the POST /api/connect endpoint unguarded when connect-backend authorization is configured, a...
CVE-2026-91923HIGH7.7KubeSphere through 4.1.3 contains a server-side request forgery vulnerability in the git credential verification endpoin...
CVE-2026-57137HIGH8.8PraisonAI is a multi-agent teams system. From 1.4.0 until 1.7.2, createAgentLoop() in src/praisonai-ts/src/ai/agent-loop...
CVE-2026-57136HIGH8.8PraisonAI is a multi-agent teams system. From 1.2.3 until 1.7.2, CommandValidator in src/praisonai-ts/src/cli/features/s...
CVE-2026-57135HIGH7.6PraisonAI is a multi-agent teams system. From 1.2.3 until 1.7.2, SandboxExecutor network-isolated mode in src/praisonai-...
CVE-2026-57134HIGH8.2PraisonAI is a multi-agent teams system. From 1.5.1 until 1.7.2, MCPSecurity.evaluatePolicy() in src/praisonai-ts/src/mc...
CVE-2026-57133HIGH8.8PraisonAI is a multi-agent teams system. From 1.5.1 until 1.7.2, the shell() helper exported from src/praisonai-ts/src/t...
CVE-2026-57112HIGH8.3PraisonAI is a multi-agent teams system. From praisonaiagents 0.6.0 until 1.6.59 and PraisonAI 3.10.0 until 4.6.59, Tool...
CVE-2026-52827HIGH7.1Kimai is an open-source time tracking application. Prior to 2.59.0, the KIMAI_SESSION cookie issued after password verif...
CVE-2026-1758HIGH8.3Session fixation vulnerability in Secomea GateManager (webserver module) allows Session Fixation. This issue affects Ga...
CVE-2026-53660HIGH7.4Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, the default configuration initializes...
CVE-2026-47426HIGH7.6Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, the private_key_jwt client authentica...
CVE-2026-47424HIGH7.5Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, GroovySandboxValueFilter permits an a...
CVE-2026-46623HIGH7.4Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, the OAuth2 authentication module upda...
CVE-2026-46498HIGH7.6Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, OAuthTokenStore reads caller-supplied...
CVE-2026-45794HIGH7.7Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, the anonymous Push Notification SNS c...
CVE-2026-45048HIGH8.5Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, SessionRequestHandler in the session ...
CVE-2026-44793HIGH7Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, certain federation endpoints in a non...
CVE-2026-44203HIGH8.3Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, the OAuth 2.0 and OpenID Connect auth...
CVE-2026-41573HIGH7.1Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, IdentityResourceV1.queryCollection() ...
CVE-2026-19515HIGH7The WSO2 Integrator MI VS Code extension fails to properly sanitize or validate user-supplied input when processing Micr...
CVE-2026-91846HIGH7.1Affected versions of MISP allow a collection element to be created from a bare UUID without consistently checking whethe...
CVE-2026-91825HIGH7.1Affected versions of MISP fail to authorize a submitted sharing group in a specific event-edit path. The vulnerable lo...
CVE-2026-80217HIGH8.7Hidden functionality issue exists in FF-RFI079I4 and FF-RFI078I4, which may allow a user who can log in via SSH and acce...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now