2026 CVE Vulnerabilities
44,021 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-46388 | MEDIUM | 4.4 | — | Jul 10, 2026 | osquery is a SQL powered operating system instrumentation, monitoring, and analytics framework. Prior to 5.23.1, an unpr... |
| CVE-2026-15375 | MEDIUM | 4.3 | 0.2% | Jul 10, 2026 | A vulnerability has been found in Eleveo Call Recording Software 9.7.0. This impacts an unknown function of the file /ca... |
| CVE-2026-15374 | MEDIUM | 6.3 | 0.3% | Jul 10, 2026 | A flaw has been found in Eleveo Call Recording Software 9.7.0. This affects an unknown function of the file /callrec/rol... |
| CVE-2026-15373 | MEDIUM | 6.3 | 0.3% | Jul 10, 2026 | A vulnerability was detected in Eleveo Call Recording Software 9.7.0. The impacted element is an unknown function of the... |
| CVE-2026-61492 | MEDIUM | 6.1 | — | Jul 10, 2026 | In JetBrains YouTrack before 2026.2.17394 stored XSS via article titles in digest emails was possible |
| CVE-2026-61456 | MEDIUM | 5.1 | — | Jul 10, 2026 | The Grav API plugin (getgrav/grav-plugin-api) before 1.0.3 fails to sanitize SVG files uploaded through the POST /api/v1... |
| CVE-2026-61432 | MEDIUM | 6.9 | — | Jul 10, 2026 | PraisonAI (praisonaiagents) before 1.6.78 contains a path traversal vulnerability in the FastContext feature (praisonaia... |
| CVE-2026-61431 | MEDIUM | 6.8 | — | Jul 10, 2026 | PraisonAI before 4.6.78 contains a path traversal vulnerability in ContextGatherer that fails to validate include paths ... |
| CVE-2026-60089 | MEDIUM | 6.9 | — | Jul 10, 2026 | PraisonAI (pip package praisonaiagents) before 1.6.78 automatically loads defaults from a project-local .praisonai/confi... |
| CVE-2026-60086 | MEDIUM | 6.9 | 0.2% | Jul 10, 2026 | PraisonAI before 4.6.78 contains a prompt injection defense bypass vulnerability where the injection defense only blocks... |
| CVE-2026-59795 | MEDIUM | 6.1 | 0.3% | Jul 10, 2026 | In JetBrains TeamCity before 2026.1.2 stored XSS via unauthenticated agent registration was possible |
| CVE-2026-59794 | MEDIUM | 5.4 | — | Jul 10, 2026 | In JetBrains TeamCity before 2026.1.2 stored XSS on the cloud profile page was possible via agent-reported data |
| CVE-2026-58661 | MEDIUM | 4.3 | 0.2% | Jul 10, 2026 | n8n before 2.28.0 (and before 1.123.58 on the 1.x branch) contains a disk space exhaustion vulnerability in the data-tab... |
| CVE-2026-57994 | MEDIUM | 6.9 | — | Jul 10, 2026 | phpMyFAQ before 4.1.5 applies inconsistent active=yes and publication-date filtering across its public FAQ API endpoints... |
| CVE-2026-57961 | MEDIUM | 5.1 | — | Jul 10, 2026 | phpMyFAQ before 4.1.5 contains a potential authenticated path traversal vulnerability in the concatenatePaths() function... |
| CVE-2026-56373 | MEDIUM | 5.3 | 0.2% | Jul 10, 2026 | ImageMagick before 7.1.2-15 contains a use-after-free vulnerability in the PDB decoder that uses a stale pointer when me... |
| CVE-2026-56366 | MEDIUM | 6.5 | 0.1% | Jul 10, 2026 | ImageMagick before 7.1.2-18 contains a memory leak vulnerability in the META reader when processing APP1JPEG input paths... |
| CVE-2026-56354 | MEDIUM | 5.4 | 0.2% | Jul 10, 2026 | n8n before 1.123.24, 2.10.4, and 2.12.0 (across its 1.x and 2.x branches) contains cross-site scripting and open redirec... |
| CVE-2026-56329 | MEDIUM | 6.4 | — | Jul 10, 2026 | Capgo before 12.128.2 contains a cross-tenant preview namespace collision vulnerability caused by non-bijective decoding... |
| CVE-2026-56312 | MEDIUM | 6.9 | — | Jul 10, 2026 | Capgo before 12.128.2 contains an improper validation vulnerability in the accept_invitation endpoint that creates user ... |
| CVE-2026-56309 | MEDIUM | 5.4 | — | Jul 10, 2026 | Capgo before 12.128.2 fails to enforce plan/quota restrictions on the /files/upload/attachments endpoint, allowing plan-... |
| CVE-2026-54470 | MEDIUM | 5.3 | 0.2% | Jul 10, 2026 | Dell Unisphere for PowerMax, version(s) 10.3.0.5 and prior contain(s) an Improper Restriction of XML External Entity Ref... |
| CVE-2026-56814 | MEDIUM | 6.9 | — | Jul 10, 2026 | Plug.Parsers.MULTIPART, the multipart request-body parser used to handle file uploads and multipart forms, does not enfo... |
| CVE-2026-54468 | MEDIUM | 6.5 | 0.3% | Jul 10, 2026 | Dell Unisphere for PowerMax, version(s) 10.3.0.5 and prior, contain(s) a path traversal vulnerability. A low privileged ... |
| CVE-2026-14461 | MEDIUM | 5.1 | — | Jul 10, 2026 | mtr is vulnerable to Out-of-bound read vulnerability in ipinfo_lookup() function. An attacker who can influence the TXT ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now