2026 CVE Vulnerabilities
61,049 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-50034 | HIGH | 7.1 | 0.1% | Jun 19, 2026 | An attacker within BLE communication range can passively intercept wireless traffic and obtain sensitive health-related... |
| CVE-2026-40624 | CRITICAL | 9.8 | 0.6% | Jun 19, 2026 | Improper input validation in AVer PTC500S, PTC115, PTC500+, and PTC115+ cameras may allow a remote, unauthenticated att... |
| CVE-2026-12050 | HIGH | 8.8 | 0.2% | Jun 19, 2026 | SQL injection in pgAdmin 4's named restore point endpoint (POST /browser/server/restore_point/{gid}/{sid}). The user-sup... |
| CVE-2026-12049 | MEDIUM | 6.1 | 0.3% | Jun 19, 2026 | Open redirect in pgAdmin 4's multi-factor authentication flow. The MFA validate and register endpoints honoured the user... |
| CVE-2026-12048 | MEDIUM | 5.4 | 0.3% | Jun 19, 2026 | Stored cross-site scripting in pgAdmin 4's error-rendering and plan-node-rendering paths. Text returned by a PostgreSQL ... |
| CVE-2026-12047 | MEDIUM | 5.4 | 0.2% | Jun 19, 2026 | HTML injection in pgAdmin 4's cloud deployment module. The verify_credentials, deploy, regions, and update-server endpoi... |
| CVE-2026-12046 | CRITICAL | 9.5 | 0.7% | Jun 19, 2026 | Two state-mutating endpoints in pgAdmin 4's SQL Editor blueprint -- DELETE /sqleditor/close/<trans_id> and POST /sqledit... |
| CVE-2026-12045 | HIGH | 8.8 | 0.5% | Jun 19, 2026 | Read-only transaction bypass in the pgAdmin 4 AI Assistant allows an attacker who can influence database content that th... |
| CVE-2026-12044 | HIGH | 8.8 | 0.5% | Jun 19, 2026 | SQL injection in pgAdmin 4 across every dialog template that renders ``COMMENT ON ... IS '<description>'`` for a user-su... |
| CVE-2026-6716 | — | — | — | Jun 18, 2026 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2026-56078 | HIGH | 8.8 | 0.7% | Jun 18, 2026 | PraisonAI before 1.5.115 contains a path traversal vulnerability in MultiAgentMonitor that fails to sanitize agent IDs w... |
| CVE-2026-56077 | HIGH | 7.1 | 0.3% | Jun 18, 2026 | PraisonAI before 1.5.115 contains an information disclosure vulnerability in the MultiAgentLedger component that allows ... |
| CVE-2026-56076 | HIGH | 8.6 | 0.5% | Jun 18, 2026 | PraisonAI before 1.5.128 contains a cross-origin agent execution vulnerability in the AGUI endpoint that allows remote a... |
| CVE-2026-56075 | HIGH | 8.8 | 0.5% | Jun 18, 2026 | PraisonAI before 4.5.128 contains an arbitrary shell command execution vulnerability where the UI modules hardcode appro... |
| CVE-2026-56074 | MEDIUM | 6.8 | 0.1% | Jun 18, 2026 | PraisonAI before 1.5.128 caches tool approval decisions by tool name only, not by invocation arguments, allowing subsequ... |
| CVE-2026-10746 | — | — | — | Jun 18, 2026 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2026-8668 | LOW | 2.3 | 0.2% | Jun 18, 2026 | A static credential embedded in Chef 360 prior to v1.7.0 permitted unauthenticated access to internal message queues. Q... |
| CVE-2026-8100 | HIGH | 8.6 | 0.4% | Jun 18, 2026 | Impact A security issue has been identified in Chef 360 that could allow unauthorized access to protected API endpoints... |
| CVE-2026-54130 | HIGH | 7.5 | 0.6% | Jun 18, 2026 | Missing authentication for critical function in M365 Copilot allows an unauthorized attacker to disclose information ove... |
| CVE-2026-54017 | HIGH | 7.7 | 0.3% | Jun 18, 2026 | Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.6, the t... |
| CVE-2026-49205 | MEDIUM | 6.5 | 0.2% | Jun 18, 2026 | phpMyFAQ is an open source FAQ web application. Versions prior to 4.1.4 have Missing Authorization in the API CategoryC... |
| CVE-2026-47647 | CRITICAL | 9.9 | 0.4% | Jun 18, 2026 | Improper access control in Microsoft Dynamics 365 allows an authorized attacker to elevate privileges over a network. |
| CVE-2026-47633 | HIGH | 7.5 | 0.6% | Jun 18, 2026 | Exposure of sensitive information to an unauthorized actor in Cost Management Interactive Experiences allows an unauthor... |
| CVE-2026-32174 | HIGH | 8.8 | 0.4% | Jun 18, 2026 | Improper authentication in Azure Bot Service allows an authorized attacker to elevate privileges over a network. |
| CVE-2026-22674 | MEDIUM | 4.8 | 0.2% | Jun 18, 2026 | Hashgraph Guardian through 3.6.0, fixed in commit ba8c566, contains a stored cross-site scripting vulnerability that all... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now