2026 CVE Vulnerabilities
45,091 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-34457 | CRITICAL | 9.1 | 0.5% | Apr 14, 2026 | OAuth2 Proxy is a reverse proxy that provides authentication using OAuth2 providers. Versions prior to 7.15.2 contain a ... |
| CVE-2026-39907 | CRITICAL | 10 | 0.6% | Apr 14, 2026 | Unisys WebPerfect Image Suite versions 3.0.3960.22810 and 3.0.3960.22604 expose an unauthenticated WCF SOAP endpoint on ... |
| CVE-2026-39906 | CRITICAL | 10 | 0.7% | Apr 14, 2026 | Unisys WebPerfect Image Suite versions 3.0.3960.22810 and 3.0.3960.22604 expose a deprecated .NET Remoting TCP channel t... |
| CVE-2026-27304 | CRITICAL | 9.3 | 4.0% | Apr 14, 2026 | ColdFusion versions 2023.18, 2025.6 and earlier are affected by an Improper Input Validation vulnerability that could re... |
| CVE-2026-5752 | CRITICAL | 9.3 | 0.2% | Apr 14, 2026 | Sandbox Escape Vulnerability in Terrarium allows arbitrary code execution with root privileges on a host process via Jav... |
| CVE-2026-34615 | CRITICAL | 9.3 | 0.6% | Apr 14, 2026 | Adobe Connect versions 2025.3, 12.10 and earlier are affected by a Deserialization of Untrusted Data vulnerability that ... |
| CVE-2026-33824 | CRITICAL | 9.8 | 55.9% | Apr 14, 2026 | Double free in Windows IKE Extension allows an unauthorized attacker to execute code over a network. |
| CVE-2026-27303 | CRITICAL | 9.6 | 0.6% | Apr 14, 2026 | Adobe Connect versions 2025.3, 12.10 and earlier are affected by a Deserialization of Untrusted Data vulnerability that ... |
| CVE-2026-27246 | CRITICAL | 9.3 | 0.3% | Apr 14, 2026 | Adobe Connect versions 2025.3, 12.10 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. A... |
| CVE-2026-27245 | CRITICAL | 9.3 | 0.3% | Apr 14, 2026 | Adobe Connect versions 2025.3, 12.10 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. A... |
| CVE-2026-27243 | CRITICAL | 9.3 | 0.3% | Apr 14, 2026 | Adobe Connect versions 2025.3, 12.10 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. A... |
| CVE-2026-26149 | CRITICAL | 9 | 0.6% | Apr 14, 2026 | Improper neutralization of escape, meta, or control sequences in Microsoft Power Apps allows an authorized attacker to p... |
| CVE-2026-39813 | CRITICAL | 9.8 | 16.7% | Apr 14, 2026 | A path traversal: '../filedir' vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.... |
| CVE-2026-39808 | CRITICAL | 9.8 | 48.7% | Apr 14, 2026 | A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet F... |
| CVE-2026-38526 | CRITICAL | 9.9 | 0.8% | Apr 14, 2026 | An authenticated arbitrary file upload vulnerability in the /admin/tinymce/upload endpoint of Webkul Krayin CRM v2.2.x a... |
| CVE-2026-31049 | CRITICAL | 9.8 | 0.7% | Apr 14, 2026 | An issue in Hostbill v.2025-11-24 and 2025-12-01 allows a remote attacker to execute arbitrary code and escalate privile... |
| CVE-2026-2449 | CRITICAL | 9 | 0.3% | Apr 14, 2026 | Improper neutralization of argument delimiters in a command ('argument injection') vulnerability in upKeeper Solutions u... |
| CVE-2026-2332 | CRITICAL | 9.1 | 1.2% | Apr 14, 2026 | In Eclipse Jetty, the HTTP/1.1 parser is vulnerable to request smuggling when chunk extensions are used, similar to the ... |
| CVE-2026-31908 | CRITICAL | 9.1 | 0.5% | Apr 14, 2026 | Header injection vulnerability in Apache APISIX. The attacker can take advantage of certain configuration in forward-au... |
| CVE-2026-40315 | CRITICAL | 9.8 | 0.3% | Apr 14, 2026 | PraisonAI is a multi-agent teams system. Prior to 4.5.133, there is an SQL identifier injection vulnerability in SQLiteC... |
| CVE-2026-40313 | CRITICAL | 9.1 | 0.3% | Apr 14, 2026 | PraisonAI is a multi-agent teams system. In versions 4.5.139 and below, the GitHub Actions workflows are vulnerable to A... |
| CVE-2026-40289 | CRITICAL | 9.1 | 0.4% | Apr 14, 2026 | PraisonAI is a multi-agent teams system. In versions below 4.5.139 of PraisonAI and 1.5.140 of praisonaiagents, the brow... |
| CVE-2026-40288 | CRITICAL | 9.8 | 0.6% | Apr 14, 2026 | PraisonAI is a multi-agent teams system. In versions below 4.5.139 of PraisonAI and 1.5.140 of praisonaiagents, the work... |
| CVE-2026-6264 | CRITICAL | 9.8 | 0.7% | Apr 14, 2026 | A critical vulnerability in the Talend JobServer and Talend Runtime allows unauthenticated remote code execution via the... |
| CVE-2026-4365 | CRITICAL | 9.1 | 0.9% | Apr 14, 2026 | The LearnPress plugin for WordPress is vulnerable to unauthorized data deletion due to a missing capability check on the... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now