2026 CVE Vulnerabilities
64,868 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-91925 | HIGH | 8.8 | 0.8% | Sep 15, 2026 | Polyaxon through 2.16.4 renders operation specification fields with an unsandboxed Jinja2 environment during server-side... |
| CVE-2026-91924 | HIGH | 8.5 | 0.3% | Sep 15, 2026 | pgweb through 0.17.0 leaves the POST /api/connect endpoint unguarded when connect-backend authorization is configured, a... |
| CVE-2026-91923 | HIGH | 7.7 | 0.5% | Sep 15, 2026 | KubeSphere through 4.1.3 contains a server-side request forgery vulnerability in the git credential verification endpoin... |
| CVE-2026-57137 | HIGH | 8.8 | 0.4% | Sep 15, 2026 | PraisonAI is a multi-agent teams system. From 1.4.0 until 1.7.2, createAgentLoop() in src/praisonai-ts/src/ai/agent-loop... |
| CVE-2026-57136 | HIGH | 8.8 | 0.8% | Sep 15, 2026 | PraisonAI is a multi-agent teams system. From 1.2.3 until 1.7.2, CommandValidator in src/praisonai-ts/src/cli/features/s... |
| CVE-2026-57135 | HIGH | 7.6 | 0.4% | Sep 15, 2026 | PraisonAI is a multi-agent teams system. From 1.2.3 until 1.7.2, SandboxExecutor network-isolated mode in src/praisonai-... |
| CVE-2026-57134 | HIGH | 8.2 | 0.4% | Sep 15, 2026 | PraisonAI is a multi-agent teams system. From 1.5.1 until 1.7.2, MCPSecurity.evaluatePolicy() in src/praisonai-ts/src/mc... |
| CVE-2026-57133 | HIGH | 8.8 | 0.4% | Sep 15, 2026 | PraisonAI is a multi-agent teams system. From 1.5.1 until 1.7.2, the shell() helper exported from src/praisonai-ts/src/t... |
| CVE-2026-57112 | HIGH | 8.3 | 0.2% | Sep 15, 2026 | PraisonAI is a multi-agent teams system. From praisonaiagents 0.6.0 until 1.6.59 and PraisonAI 3.10.0 until 4.6.59, Tool... |
| CVE-2026-52827 | HIGH | 7.1 | 0.4% | Sep 15, 2026 | Kimai is an open-source time tracking application. Prior to 2.59.0, the KIMAI_SESSION cookie issued after password verif... |
| CVE-2026-1758 | HIGH | 8.3 | 0.2% | Sep 15, 2026 | Session fixation vulnerability in Secomea GateManager (webserver module) allows Session Fixation. This issue affects Ga... |
| CVE-2026-53660 | HIGH | 7.4 | 0.3% | Sep 15, 2026 | Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, the default configuration initializes... |
| CVE-2026-47426 | HIGH | 7.6 | 0.4% | Sep 15, 2026 | Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, the private_key_jwt client authentica... |
| CVE-2026-47424 | HIGH | 7.5 | 0.4% | Sep 15, 2026 | Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, GroovySandboxValueFilter permits an a... |
| CVE-2026-46623 | HIGH | 7.4 | 0.5% | Sep 15, 2026 | Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, the OAuth2 authentication module upda... |
| CVE-2026-46498 | HIGH | 7.6 | 0.3% | Sep 15, 2026 | Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, OAuthTokenStore reads caller-supplied... |
| CVE-2026-45794 | HIGH | 7.7 | 0.5% | Sep 15, 2026 | Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, the anonymous Push Notification SNS c... |
| CVE-2026-45048 | HIGH | 8.5 | 0.3% | Sep 15, 2026 | Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, SessionRequestHandler in the session ... |
| CVE-2026-44793 | HIGH | 7 | 0.4% | Sep 15, 2026 | Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, certain federation endpoints in a non... |
| CVE-2026-44203 | HIGH | 8.3 | 0.5% | Sep 15, 2026 | Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, the OAuth 2.0 and OpenID Connect auth... |
| CVE-2026-41573 | HIGH | 7.1 | 0.4% | Sep 15, 2026 | Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, IdentityResourceV1.queryCollection() ... |
| CVE-2026-19515 | HIGH | 7 | 0.1% | Sep 15, 2026 | The WSO2 Integrator MI VS Code extension fails to properly sanitize or validate user-supplied input when processing Micr... |
| CVE-2026-91846 | HIGH | 7.1 | 0.2% | Sep 15, 2026 | Affected versions of MISP allow a collection element to be created from a bare UUID without consistently checking whethe... |
| CVE-2026-91825 | HIGH | 7.1 | 0.2% | Sep 15, 2026 | Affected versions of MISP fail to authorize a submitted sharing group in a specific event-edit path. The vulnerable lo... |
| CVE-2026-80217 | HIGH | 8.7 | 0.3% | Sep 15, 2026 | Hidden functionality issue exists in FF-RFI079I4 and FF-RFI078I4, which may allow a user who can log in via SSH and acce... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now