2026 CVE Vulnerabilities

45,107 CVEs published in 2026.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2026-34935CRITICAL9.8PraisonAI is a multi-agent teams system. From version 4.5.15 to before version 4.5.69, the --mcp CLI argument is passed ...
CVE-2026-34934CRITICAL9.8PraisonAI is a multi-agent teams system. Prior to version 4.5.90, the get_all_user_threads function constructs raw SQL q...
CVE-2026-34612CRITICAL9Kestra is an open-source, event-driven orchestration platform. Prior to version 1.3.7, Kestra (default docker-compose de...
CVE-2026-27634CRITICAL9.8Piwigo is an open source photo gallery application for the web. Prior to version 16.3.0, the four date filter parameters...
CVE-2026-35561CRITICAL9.8Insufficient authentication security controls in the browser-based authentication components in Amazon Athena ODBC drive...
CVE-2026-28798CRITICAL10ZimaOS is a fork of CasaOS, an operating system for Zima devices and x86-64 systems with UEFI. Prior to version 1.5.3, a...
CVE-2026-25726CRITICAL9.8Cloudreve is a self-hosted file management and sharing system. Prior to version 4.13.0, the application uses the weak ps...
CVE-2026-32186CRITICAL9.8Server-side request forgery (ssrf) in Microsoft Bing allows an unauthorized attacker to elevate privileges over a networ...
CVE-2026-0545CRITICAL9.8In mlflow/mlflow, the FastAPI job endpoints under `/ajax-api/3.0/jobs/*` are not protected by authentication or authoriz...
CVE-2026-28373CRITICAL9.6The Stackfield Desktop App before 1.10.2 for macOS and Windows contains a path traversal vulnerability in certain decryp...
CVE-2026-35216CRITICAL9Budibase is an open-source low-code platform. Prior to version 3.33.4, an unauthenticated attacker can achieve Remote Co...
CVE-2026-31818CRITICAL9.9Budibase is an open-source low-code platform. Prior to version 3.33.4, a server-side request forgery (SSRF) vulnerabilit...
CVE-2026-31402CRITICAL9.8In the Linux kernel, the following vulnerability has been resolved: nfsd: fix heap overflow in NFSv4.0 LOCK replay cach...
CVE-2026-23455CRITICAL9.1In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conntrack_h323: check for zero length...
CVE-2026-23450CRITICAL9.8In the Linux kernel, the following vulnerability has been resolved: net/smc: fix NULL dereference and UAF in smc_tcp_sy...
CVE-2026-5463CRITICAL9.8Command injection vulnerability in console.run_module_with_output() in pymetasploit3 through version 1.0.6 allows attack...
CVE-2026-33107CRITICAL9.8Server-side request forgery (ssrf) in Azure Databricks allows an unauthorized attacker to elevate privileges over a netw...
CVE-2026-33105CRITICAL9.8Improper authorization in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elevate privileges over ...
CVE-2026-32213CRITICAL9.8Improper authorization in Azure AI Foundry allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-35053CRITICAL9.8OneUptime is an open-source monitoring and observability platform. Prior to version 10.0.42, the Worker service's Manual...
CVE-2026-34932CRITICAL9.3hoppscotch is an open source API development ecosystem. Prior to version 2026.3.0, there is a stored XSS vulnerability t...
CVE-2026-34931CRITICAL9.6hoppscotch is an open source API development ecosystem. Prior to version 2026.3.0, there is an open redirect vulnerabili...
CVE-2026-34838CRITICAL9.9Group-Office is an enterprise customer relationship management and groupware tool. Prior to versions 6.8.156, 25.0.90, a...
CVE-2026-34758CRITICAL9.1OneUptime is an open-source monitoring and observability platform. Prior to version 10.0.42, unauthenticated access to N...
CVE-2026-34745CRITICAL9.1Fireshare facilitates self-hosted media and link sharing. Prior to version 1.5.3, the fix for CVE-2026-33645 was applied...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now