2026 CVE Vulnerabilities

60,243 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-12046CRITICAL9.5Two state-mutating endpoints in pgAdmin 4's SQL Editor blueprint -- DELETE /sqleditor/close/<trans_id> and POST /sqledit...
CVE-2026-12045HIGH8.8Read-only transaction bypass in the pgAdmin 4 AI Assistant allows an attacker who can influence database content that th...
CVE-2026-12044HIGH8.8SQL injection in pgAdmin 4 across every dialog template that renders ``COMMENT ON ... IS '<description>'`` for a user-su...
CVE-2026-6716Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-56078HIGH8.8PraisonAI before 1.5.115 contains a path traversal vulnerability in MultiAgentMonitor that fails to sanitize agent IDs w...
CVE-2026-56077HIGH7.1PraisonAI before 1.5.115 contains an information disclosure vulnerability in the MultiAgentLedger component that allows ...
CVE-2026-56076HIGH8.6PraisonAI before 1.5.128 contains a cross-origin agent execution vulnerability in the AGUI endpoint that allows remote a...
CVE-2026-56075HIGH8.8PraisonAI before 4.5.128 contains an arbitrary shell command execution vulnerability where the UI modules hardcode appro...
CVE-2026-56074MEDIUM6.8PraisonAI before 1.5.128 caches tool approval decisions by tool name only, not by invocation arguments, allowing subsequ...
CVE-2026-10746Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-8668LOW2.3A static credential embedded in Chef 360 prior to v1.7.0 permitted unauthenticated access to internal message queues.  Q...
CVE-2026-8100HIGH8.6Impact A security issue has been identified in Chef 360 that could allow unauthorized access to protected API endpoints...
CVE-2026-54130HIGH7.5Missing authentication for critical function in M365 Copilot allows an unauthorized attacker to disclose information ove...
CVE-2026-54017HIGH7.7Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.6, the t...
CVE-2026-49205MEDIUM6.5phpMyFAQ is an open source FAQ web application. Versions prior to 4.1.4 have Missing Authorization in the API CategoryC...
CVE-2026-47647CRITICAL9.9Improper access control in Microsoft Dynamics 365 allows an authorized attacker to elevate privileges over a network.
CVE-2026-47633HIGH7.5Exposure of sensitive information to an unauthorized actor in Cost Management Interactive Experiences allows an unauthor...
CVE-2026-32174HIGH8.8Improper authentication in Azure Bot Service allows an authorized attacker to elevate privileges over a network.
CVE-2026-22674MEDIUM4.8Hashgraph Guardian through 3.6.0, fixed in commit ba8c566, contains a stored cross-site scripting vulnerability that all...
CVE-2026-49454CRITICAL9.1Relyra is a strict-by-default SAML 2.0 Service Provider library for Elixir and Phoenix. Versions 1.0.0 and 1.1.0 accept ...
CVE-2026-49257CRITICAL10mcp-pinot is a Python-based Model Context Protocol (MCP) server for interacting with Apache Pinot. In versions 3.0.1 and...
CVE-2026-49252CRITICAL9.9deepstream is a server that allows clients and backend services to sync data, send messages and make rpcs at scale. Vers...
CVE-2026-49248HIGH8.3OneDev is a Git server with CI/CD, kanban, and packages. In versions 15.0.6 and below, TarUtils.untar() creates symbolic...
CVE-2026-46699HIGH7.6conda-smithy is a tool for combining a conda recipe with configurations to build using freely hosted CI services into a ...
CVE-2026-45696MEDIUM6.5OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture in...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now