2026 CVE Vulnerabilities

61,049 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-50034HIGH7.1An attacker within BLE communication range can passively intercept wireless traffic and obtain sensitive health-related...
CVE-2026-40624CRITICAL9.8Improper input validation in AVer PTC500S, PTC115, PTC500+, and PTC115+ cameras may allow a remote, unauthenticated att...
CVE-2026-12050HIGH8.8SQL injection in pgAdmin 4's named restore point endpoint (POST /browser/server/restore_point/{gid}/{sid}). The user-sup...
CVE-2026-12049MEDIUM6.1Open redirect in pgAdmin 4's multi-factor authentication flow. The MFA validate and register endpoints honoured the user...
CVE-2026-12048MEDIUM5.4Stored cross-site scripting in pgAdmin 4's error-rendering and plan-node-rendering paths. Text returned by a PostgreSQL ...
CVE-2026-12047MEDIUM5.4HTML injection in pgAdmin 4's cloud deployment module. The verify_credentials, deploy, regions, and update-server endpoi...
CVE-2026-12046CRITICAL9.5Two state-mutating endpoints in pgAdmin 4's SQL Editor blueprint -- DELETE /sqleditor/close/<trans_id> and POST /sqledit...
CVE-2026-12045HIGH8.8Read-only transaction bypass in the pgAdmin 4 AI Assistant allows an attacker who can influence database content that th...
CVE-2026-12044HIGH8.8SQL injection in pgAdmin 4 across every dialog template that renders ``COMMENT ON ... IS '<description>'`` for a user-su...
CVE-2026-6716Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-56078HIGH8.8PraisonAI before 1.5.115 contains a path traversal vulnerability in MultiAgentMonitor that fails to sanitize agent IDs w...
CVE-2026-56077HIGH7.1PraisonAI before 1.5.115 contains an information disclosure vulnerability in the MultiAgentLedger component that allows ...
CVE-2026-56076HIGH8.6PraisonAI before 1.5.128 contains a cross-origin agent execution vulnerability in the AGUI endpoint that allows remote a...
CVE-2026-56075HIGH8.8PraisonAI before 4.5.128 contains an arbitrary shell command execution vulnerability where the UI modules hardcode appro...
CVE-2026-56074MEDIUM6.8PraisonAI before 1.5.128 caches tool approval decisions by tool name only, not by invocation arguments, allowing subsequ...
CVE-2026-10746Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-8668LOW2.3A static credential embedded in Chef 360 prior to v1.7.0 permitted unauthenticated access to internal message queues.  Q...
CVE-2026-8100HIGH8.6Impact A security issue has been identified in Chef 360 that could allow unauthorized access to protected API endpoints...
CVE-2026-54130HIGH7.5Missing authentication for critical function in M365 Copilot allows an unauthorized attacker to disclose information ove...
CVE-2026-54017HIGH7.7Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.6, the t...
CVE-2026-49205MEDIUM6.5phpMyFAQ is an open source FAQ web application. Versions prior to 4.1.4 have Missing Authorization in the API CategoryC...
CVE-2026-47647CRITICAL9.9Improper access control in Microsoft Dynamics 365 allows an authorized attacker to elevate privileges over a network.
CVE-2026-47633HIGH7.5Exposure of sensitive information to an unauthorized actor in Cost Management Interactive Experiences allows an unauthor...
CVE-2026-32174HIGH8.8Improper authentication in Azure Bot Service allows an authorized attacker to elevate privileges over a network.
CVE-2026-22674MEDIUM4.8Hashgraph Guardian through 3.6.0, fixed in commit ba8c566, contains a stored cross-site scripting vulnerability that all...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now