2026 CVE Vulnerabilities
45,107 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-34935 | CRITICAL | 9.8 | 0.8% | Apr 3, 2026 | PraisonAI is a multi-agent teams system. From version 4.5.15 to before version 4.5.69, the --mcp CLI argument is passed ... |
| CVE-2026-34934 | CRITICAL | 9.8 | 0.5% | Apr 3, 2026 | PraisonAI is a multi-agent teams system. Prior to version 4.5.90, the get_all_user_threads function constructs raw SQL q... |
| CVE-2026-34612 | CRITICAL | 9 | 0.7% | Apr 3, 2026 | Kestra is an open-source, event-driven orchestration platform. Prior to version 1.3.7, Kestra (default docker-compose de... |
| CVE-2026-27634 | CRITICAL | 9.8 | 0.7% | Apr 3, 2026 | Piwigo is an open source photo gallery application for the web. Prior to version 16.3.0, the four date filter parameters... |
| CVE-2026-35561 | CRITICAL | 9.8 | 0.5% | Apr 3, 2026 | Insufficient authentication security controls in the browser-based authentication components in Amazon Athena ODBC drive... |
| CVE-2026-28798 | CRITICAL | 10 | 0.4% | Apr 3, 2026 | ZimaOS is a fork of CasaOS, an operating system for Zima devices and x86-64 systems with UEFI. Prior to version 1.5.3, a... |
| CVE-2026-25726 | CRITICAL | 9.8 | 0.4% | Apr 3, 2026 | Cloudreve is a self-hosted file management and sharing system. Prior to version 4.13.0, the application uses the weak ps... |
| CVE-2026-32186 | CRITICAL | 9.8 | 0.7% | Apr 3, 2026 | Server-side request forgery (ssrf) in Microsoft Bing allows an unauthorized attacker to elevate privileges over a networ... |
| CVE-2026-0545 | CRITICAL | 9.8 | 4.4% | Apr 3, 2026 | In mlflow/mlflow, the FastAPI job endpoints under `/ajax-api/3.0/jobs/*` are not protected by authentication or authoriz... |
| CVE-2026-28373 | CRITICAL | 9.6 | 0.4% | Apr 3, 2026 | The Stackfield Desktop App before 1.10.2 for macOS and Windows contains a path traversal vulnerability in certain decryp... |
| CVE-2026-35216 | CRITICAL | 9 | 12.0% | Apr 3, 2026 | Budibase is an open-source low-code platform. Prior to version 3.33.4, an unauthenticated attacker can achieve Remote Co... |
| CVE-2026-31818 | CRITICAL | 9.9 | 0.4% | Apr 3, 2026 | Budibase is an open-source low-code platform. Prior to version 3.33.4, a server-side request forgery (SSRF) vulnerabilit... |
| CVE-2026-31402 | CRITICAL | 9.8 | 0.5% | Apr 3, 2026 | In the Linux kernel, the following vulnerability has been resolved: nfsd: fix heap overflow in NFSv4.0 LOCK replay cach... |
| CVE-2026-23455 | CRITICAL | 9.1 | 1.3% | Apr 3, 2026 | In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conntrack_h323: check for zero length... |
| CVE-2026-23450 | CRITICAL | 9.8 | 0.6% | Apr 3, 2026 | In the Linux kernel, the following vulnerability has been resolved: net/smc: fix NULL dereference and UAF in smc_tcp_sy... |
| CVE-2026-5463 | CRITICAL | 9.8 | 1.9% | Apr 3, 2026 | Command injection vulnerability in console.run_module_with_output() in pymetasploit3 through version 1.0.6 allows attack... |
| CVE-2026-33107 | CRITICAL | 9.8 | 0.7% | Apr 3, 2026 | Server-side request forgery (ssrf) in Azure Databricks allows an unauthorized attacker to elevate privileges over a netw... |
| CVE-2026-33105 | CRITICAL | 9.8 | 0.7% | Apr 3, 2026 | Improper authorization in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elevate privileges over ... |
| CVE-2026-32213 | CRITICAL | 9.8 | 0.9% | Apr 3, 2026 | Improper authorization in Azure AI Foundry allows an unauthorized attacker to elevate privileges over a network. |
| CVE-2026-35053 | CRITICAL | 9.8 | 0.5% | Apr 2, 2026 | OneUptime is an open-source monitoring and observability platform. Prior to version 10.0.42, the Worker service's Manual... |
| CVE-2026-34932 | CRITICAL | 9.3 | 0.3% | Apr 2, 2026 | hoppscotch is an open source API development ecosystem. Prior to version 2026.3.0, there is a stored XSS vulnerability t... |
| CVE-2026-34931 | CRITICAL | 9.6 | 0.4% | Apr 2, 2026 | hoppscotch is an open source API development ecosystem. Prior to version 2026.3.0, there is an open redirect vulnerabili... |
| CVE-2026-34838 | CRITICAL | 9.9 | 1.0% | Apr 2, 2026 | Group-Office is an enterprise customer relationship management and groupware tool. Prior to versions 6.8.156, 25.0.90, a... |
| CVE-2026-34758 | CRITICAL | 9.1 | 0.3% | Apr 2, 2026 | OneUptime is an open-source monitoring and observability platform. Prior to version 10.0.42, unauthenticated access to N... |
| CVE-2026-34745 | CRITICAL | 9.1 | 0.6% | Apr 2, 2026 | Fireshare facilitates self-hosted media and link sharing. Prior to version 1.5.3, the fix for CVE-2026-33645 was applied... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now