2026 CVE Vulnerabilities

45,029 CVEs published in 2026.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2026-41507CRITICAL9.8math-codegen generates code from mathematical expressions. Prior to version 0.4.3, string literal content passed to cg.p...
CVE-2026-41497CRITICAL9.8PraisonAI is a multi-agent teams system. Prior to version 4.6.9, the fix for PraisonAI's MCP command handling does not a...
CVE-2026-25199CRITICAL9.1Instances deployed via the Proxmox extension allow unauthorized access to instances belonging to other tenants. This...
CVE-2026-8153CRITICAL9.8OS command injection in Dashboard Server interface in Universal Robots PolyScope versions prior to 5.25.1 allows unauthe...
CVE-2026-8076CRITICAL9.3Weak credentials in the CashDro 3 web administration panel, version 24.01.00.26, where the platform allows the use of nu...
CVE-2026-6213CRITICAL10A vulnerability in Remote Spark SparkView before build 1122 allows an attacker to bypasses the local connection check an...
CVE-2026-43944CRITICAL9.6electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. From versions 3.0.6 to before ...
CVE-2026-43941CRITICAL9.6electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. In versions 3.8.15 and prior, ...
CVE-2026-42264CRITICAL9.1Axios is a promise based HTTP client for the browser and Node.js. From version 1.0.0 to before version 1.15.2, fFive con...
CVE-2026-42208CRITICAL9.8LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. From version 1.81.16 to before ver...
CVE-2026-41900CRITICAL10OpenLearnX is an open-source, decentralized learning and assessment platform. Prior to version 2.0.3, a remote code exec...
CVE-2026-41501CRITICAL9.8electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to version 3.3.8, a comm...
CVE-2026-41500CRITICAL9.8electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to version 3.3.8, a comm...
CVE-2026-42880CRITICAL9.6Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. From versions 3.2.0 to before 3.2.11 and 3.3.0...
CVE-2026-8034CRITICAL9.8A server-side request forgery (SSRF) vulnerability was identified in the GitHub Enterprise Server notebook viewer that a...
CVE-2026-7891CRITICAL9.1A vulnerability has been identified in Mendix Runtime (All versions). Mendix documentation for access rules does not ade...
CVE-2026-35435CRITICAL10Improper access control in Azure AI Foundry M365 published agents allows an unauthorized attacker to elevate privileges ...
CVE-2026-35428CRITICAL9.6Improper neutralization of special elements used in a command ('command injection') in Azure Cloud Shell allows an unaut...
CVE-2026-33844CRITICAL9Improper access control in Azure Managed Instance for Apache Cassandra allows an authorized attacker to execute code ove...
CVE-2026-33109CRITICAL9.9Improper access control in Azure Managed Instance for Apache Cassandra allows an authorized attacker to execute code ove...
CVE-2026-41691CRITICAL9.1Copilot said: i18nextify is a JavaScript library that adds i18nextify is a JavaScript library that adds website internat...
CVE-2026-42284CRITICAL9.8GitPython is a python library used to interact with Git repositories. Prior to version 3.1.47, _clone() validates multi_...
CVE-2026-41902CRITICAL9.1FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.217, the /user-s...
CVE-2026-37709CRITICAL9.8Insecure Permissions vulnerability in grokability snipe-it v.8.4.0 and before and fixed after 2026-03-10 commit 676a9958...
CVE-2026-7415CRITICAL9.8The MQTT broker embedded in Yarbo firmware v2.3.9 is configured to allow anonymous connections with no topic-level read ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now