2026 CVE Vulnerabilities

45,092 CVEs published in 2026.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2026-40154CRITICAL9.6PraisonAI is a multi-agent teams system. Prior to 4.5.128, PraisonAI treats remotely fetched template files as trusted e...
CVE-2026-40114CRITICAL10PraisonAI is a multi-agent teams system. Prior to 4.5.128, the /api/v1/runs endpoint accepts an arbitrary webhook_url in...
CVE-2026-33784CRITICAL9.8A Use of Default Password vulnerability in the Juniper Networks Support Insights (JSI) Virtual Lightweight Collector...
CVE-2026-5978CRITICAL9.8A security vulnerability has been detected in Totolink A7100RU 7.4cu.2313_b20191024. Affected is the function setWiFiAcl...
CVE-2026-5977CRITICAL9.8A weakness has been identified in Totolink A7100RU 7.4cu.2313_b20191024. This impacts the function setWiFiBasicCfg of th...
CVE-2026-5976CRITICAL9.8A security flaw has been discovered in Totolink A7100RU 7.4cu.2313_b20191024. This affects the function setStorageCfg of...
CVE-2026-5975CRITICAL9.8A vulnerability was identified in Totolink A7100RU 7.4cu.2313_b20191024. The impacted element is the function setDmzCfg ...
CVE-2026-5974CRITICAL9.8A vulnerability was determined in FoundationAgents MetaGPT up to 0.8.1. The affected element is the function Bash.run in...
CVE-2026-5973CRITICAL9.8A vulnerability was found in FoundationAgents MetaGPT up to 0.8.1. Impacted is the function get_mime_type of the file me...
CVE-2026-5972CRITICAL9.8A vulnerability has been found in FoundationAgents MetaGPT up to 0.8.1. This issue affects the function Terminal.run_com...
CVE-2026-5194CRITICAL9.1Missing hash/digest size and OID checks allow digests smaller than allowed when verifying ECDSA certificates, or smaller...
CVE-2026-5187CRITICAL9.8Two potential heap out-of-bounds write locations existed in DecodeObjectId() in wolfcrypt/src/asn.c. First, a bounds che...
CVE-2026-40089CRITICAL9.9Sonicverse is a Self-hosted Docker Compose stack for live radio streaming. The Sonicverse Radio Audio Streaming Stack da...
CVE-2026-40088CRITICAL9.6PraisonAI is a multi-agent teams system. Prior to 4.5.121, the execute_command function and workflow shell execution are...
CVE-2026-29145CRITICAL9.1CLIENT_CERT authentication does not fail as expected for some scenarios when soft fail is disabled vulnerability in Apac...
CVE-2026-39912CRITICAL9.1V2Board 1.6.1 through 1.7.4 and Xboard through 0.1.9 expose authentication tokens in HTTP response bodies of the loginWi...
CVE-2026-34987CRITICAL9.9Wasmtime is a runtime for WebAssembly. From 25.0.0 to before 36.0.7, 42.0.2, and 43.0.1, Wasmtime with its Winch (baseli...
CVE-2026-34971CRITICAL9Wasmtime is a runtime for WebAssembly. From 32.0.0 to before 36.0.7, 42.0.2, and 43.0.1, Wasmtime's Cranelift compilatio...
CVE-2026-31170CRITICAL9.8An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary comm...
CVE-2026-28205CRITICAL9.8OpenPLC_V3 is vulnerable to an Initialization of a Resource with an Insecure Default vulnerability which could allow an ...
CVE-2026-5971CRITICAL9.8A flaw has been found in FoundationAgents MetaGPT up to 0.8.1. This vulnerability affects the function ActionNode.xml_fi...
CVE-2026-5970CRITICAL9.8A vulnerability was detected in FoundationAgents MetaGPT up to 0.8.1. This affects the function check_solution of the co...
CVE-2026-39987CRITICAL9.8marimo is a reactive Python notebook. Prior to 0.23.0, Marimo has a Pre-Auth RCE vulnerability. The terminal WebSocket e...
CVE-2026-5962CRITICAL9.8A vulnerability was detected in Tenda CH22 1.0.0.6(468). This issue affects the function R7WebsSecurityHandlerfunction o...
CVE-2026-39962CRITICAL9.6MISP is an open source threat intelligence and sharing platform. Prior to 2.5.36, improper neutralization of special ele...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now