2026 CVE Vulnerabilities

44,021 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-46388MEDIUM4.4osquery is a SQL powered operating system instrumentation, monitoring, and analytics framework. Prior to 5.23.1, an unpr...
CVE-2026-15375MEDIUM4.3A vulnerability has been found in Eleveo Call Recording Software 9.7.0. This impacts an unknown function of the file /ca...
CVE-2026-15374MEDIUM6.3A flaw has been found in Eleveo Call Recording Software 9.7.0. This affects an unknown function of the file /callrec/rol...
CVE-2026-15373MEDIUM6.3A vulnerability was detected in Eleveo Call Recording Software 9.7.0. The impacted element is an unknown function of the...
CVE-2026-61492MEDIUM6.1In JetBrains YouTrack before 2026.2.17394 stored XSS via article titles in digest emails was possible
CVE-2026-61456MEDIUM5.1The Grav API plugin (getgrav/grav-plugin-api) before 1.0.3 fails to sanitize SVG files uploaded through the POST /api/v1...
CVE-2026-61432MEDIUM6.9PraisonAI (praisonaiagents) before 1.6.78 contains a path traversal vulnerability in the FastContext feature (praisonaia...
CVE-2026-61431MEDIUM6.8PraisonAI before 4.6.78 contains a path traversal vulnerability in ContextGatherer that fails to validate include paths ...
CVE-2026-60089MEDIUM6.9PraisonAI (pip package praisonaiagents) before 1.6.78 automatically loads defaults from a project-local .praisonai/confi...
CVE-2026-60086MEDIUM6.9PraisonAI before 4.6.78 contains a prompt injection defense bypass vulnerability where the injection defense only blocks...
CVE-2026-59795MEDIUM6.1In JetBrains TeamCity before 2026.1.2 stored XSS via unauthenticated agent registration was possible
CVE-2026-59794MEDIUM5.4In JetBrains TeamCity before 2026.1.2 stored XSS on the cloud profile page was possible via agent-reported data
CVE-2026-58661MEDIUM4.3n8n before 2.28.0 (and before 1.123.58 on the 1.x branch) contains a disk space exhaustion vulnerability in the data-tab...
CVE-2026-57994MEDIUM6.9phpMyFAQ before 4.1.5 applies inconsistent active=yes and publication-date filtering across its public FAQ API endpoints...
CVE-2026-57961MEDIUM5.1phpMyFAQ before 4.1.5 contains a potential authenticated path traversal vulnerability in the concatenatePaths() function...
CVE-2026-56373MEDIUM5.3ImageMagick before 7.1.2-15 contains a use-after-free vulnerability in the PDB decoder that uses a stale pointer when me...
CVE-2026-56366MEDIUM6.5ImageMagick before 7.1.2-18 contains a memory leak vulnerability in the META reader when processing APP1JPEG input paths...
CVE-2026-56354MEDIUM5.4n8n before 1.123.24, 2.10.4, and 2.12.0 (across its 1.x and 2.x branches) contains cross-site scripting and open redirec...
CVE-2026-56329MEDIUM6.4Capgo before 12.128.2 contains a cross-tenant preview namespace collision vulnerability caused by non-bijective decoding...
CVE-2026-56312MEDIUM6.9Capgo before 12.128.2 contains an improper validation vulnerability in the accept_invitation endpoint that creates user ...
CVE-2026-56309MEDIUM5.4Capgo before 12.128.2 fails to enforce plan/quota restrictions on the /files/upload/attachments endpoint, allowing plan-...
CVE-2026-54470MEDIUM5.3Dell Unisphere for PowerMax, version(s) 10.3.0.5 and prior contain(s) an Improper Restriction of XML External Entity Ref...
CVE-2026-56814MEDIUM6.9Plug.Parsers.MULTIPART, the multipart request-body parser used to handle file uploads and multipart forms, does not enfo...
CVE-2026-54468MEDIUM6.5Dell Unisphere for PowerMax, version(s) 10.3.0.5 and prior, contain(s) a path traversal vulnerability. A low privileged ...
CVE-2026-14461MEDIUM5.1mtr is vulnerable to Out-of-bound read vulnerability in ipinfo_lookup() function. An attacker who can influence the TXT ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now