2026 CVE Vulnerabilities
60,243 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-12046 | CRITICAL | 9.5 | 0.7% | Jun 19, 2026 | Two state-mutating endpoints in pgAdmin 4's SQL Editor blueprint -- DELETE /sqleditor/close/<trans_id> and POST /sqledit... |
| CVE-2026-12045 | HIGH | 8.8 | 0.5% | Jun 19, 2026 | Read-only transaction bypass in the pgAdmin 4 AI Assistant allows an attacker who can influence database content that th... |
| CVE-2026-12044 | HIGH | 8.8 | 0.5% | Jun 19, 2026 | SQL injection in pgAdmin 4 across every dialog template that renders ``COMMENT ON ... IS '<description>'`` for a user-su... |
| CVE-2026-6716 | — | — | — | Jun 18, 2026 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2026-56078 | HIGH | 8.8 | 0.7% | Jun 18, 2026 | PraisonAI before 1.5.115 contains a path traversal vulnerability in MultiAgentMonitor that fails to sanitize agent IDs w... |
| CVE-2026-56077 | HIGH | 7.1 | 0.3% | Jun 18, 2026 | PraisonAI before 1.5.115 contains an information disclosure vulnerability in the MultiAgentLedger component that allows ... |
| CVE-2026-56076 | HIGH | 8.6 | 0.5% | Jun 18, 2026 | PraisonAI before 1.5.128 contains a cross-origin agent execution vulnerability in the AGUI endpoint that allows remote a... |
| CVE-2026-56075 | HIGH | 8.8 | 0.5% | Jun 18, 2026 | PraisonAI before 4.5.128 contains an arbitrary shell command execution vulnerability where the UI modules hardcode appro... |
| CVE-2026-56074 | MEDIUM | 6.8 | 0.1% | Jun 18, 2026 | PraisonAI before 1.5.128 caches tool approval decisions by tool name only, not by invocation arguments, allowing subsequ... |
| CVE-2026-10746 | — | — | — | Jun 18, 2026 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2026-8668 | LOW | 2.3 | 0.2% | Jun 18, 2026 | A static credential embedded in Chef 360 prior to v1.7.0 permitted unauthenticated access to internal message queues. Q... |
| CVE-2026-8100 | HIGH | 8.6 | 0.4% | Jun 18, 2026 | Impact A security issue has been identified in Chef 360 that could allow unauthorized access to protected API endpoints... |
| CVE-2026-54130 | HIGH | 7.5 | 0.6% | Jun 18, 2026 | Missing authentication for critical function in M365 Copilot allows an unauthorized attacker to disclose information ove... |
| CVE-2026-54017 | HIGH | 7.7 | 0.3% | Jun 18, 2026 | Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.6, the t... |
| CVE-2026-49205 | MEDIUM | 6.5 | 0.2% | Jun 18, 2026 | phpMyFAQ is an open source FAQ web application. Versions prior to 4.1.4 have Missing Authorization in the API CategoryC... |
| CVE-2026-47647 | CRITICAL | 9.9 | 0.4% | Jun 18, 2026 | Improper access control in Microsoft Dynamics 365 allows an authorized attacker to elevate privileges over a network. |
| CVE-2026-47633 | HIGH | 7.5 | 0.6% | Jun 18, 2026 | Exposure of sensitive information to an unauthorized actor in Cost Management Interactive Experiences allows an unauthor... |
| CVE-2026-32174 | HIGH | 8.8 | 0.4% | Jun 18, 2026 | Improper authentication in Azure Bot Service allows an authorized attacker to elevate privileges over a network. |
| CVE-2026-22674 | MEDIUM | 4.8 | 0.2% | Jun 18, 2026 | Hashgraph Guardian through 3.6.0, fixed in commit ba8c566, contains a stored cross-site scripting vulnerability that all... |
| CVE-2026-49454 | CRITICAL | 9.1 | 0.1% | Jun 18, 2026 | Relyra is a strict-by-default SAML 2.0 Service Provider library for Elixir and Phoenix. Versions 1.0.0 and 1.1.0 accept ... |
| CVE-2026-49257 | CRITICAL | 10 | 0.5% | Jun 18, 2026 | mcp-pinot is a Python-based Model Context Protocol (MCP) server for interacting with Apache Pinot. In versions 3.0.1 and... |
| CVE-2026-49252 | CRITICAL | 9.9 | 0.3% | Jun 18, 2026 | deepstream is a server that allows clients and backend services to sync data, send messages and make rpcs at scale. Vers... |
| CVE-2026-49248 | HIGH | 8.3 | 0.4% | Jun 18, 2026 | OneDev is a Git server with CI/CD, kanban, and packages. In versions 15.0.6 and below, TarUtils.untar() creates symbolic... |
| CVE-2026-46699 | HIGH | 7.6 | 0.2% | Jun 18, 2026 | conda-smithy is a tool for combining a conda recipe with configurations to build using freely hosted CI services into a ... |
| CVE-2026-45696 | MEDIUM | 6.5 | 0.3% | Jun 18, 2026 | OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture in... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now