2026 CVE Vulnerabilities
45,004 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-54560 | HIGH | 7.6 | — | Jul 15, 2026 | Cloudreve is a self-hosted file management and sharing system. From 4.12.0 until 4.16.1, Cloudreve's OAuth access tokens... |
| CVE-2026-52865 | HIGH | 7.1 | 0.3% | Jul 15, 2026 | When NGINX Ingress Controller processes Ingress or TransportServer resources, an authenticated, remote attacker with per... |
| CVE-2026-58558 | HIGH | 7.8 | — | Jul 15, 2026 | Permission control vulnerability in the file system. Impact: Successful exploitation of this vulnerability may affect se... |
| CVE-2026-46458 | HIGH | 7.1 | — | Jul 15, 2026 | ICU Scandinavia Boomerang is vulnerable to an information disclosure flaw where sensitive credential files are exposed v... |
| CVE-2026-15809 | HIGH | 7.8 | — | Jul 15, 2026 | A flaw was found in CRI-O. The fix for a previous vulnerability (CVE-2022-4318) was incorrect, allowing it to be bypasse... |
| CVE-2026-61873 | HIGH | 8.1 | — | Jul 15, 2026 | Grav before 9.1.8 contains an arbitrary file write vulnerability in the Form plugin's process.save.filename parameter, w... |
| CVE-2026-61866 | HIGH | 7.5 | — | Jul 15, 2026 | ImageMagick before 7.1.2-26 contains a memory leak vulnerability in the JNG encoder when a blob cannot be opened. Attack... |
| CVE-2026-61863 | HIGH | 7.5 | 0.1% | Jul 15, 2026 | ImageMagick before 7.1.2-26 (and 6.x before 6.9.13-51) contains a memory leak in the TIFF encoder that occurs when a tem... |
| CVE-2026-61457 | HIGH | 8.8 | — | Jul 15, 2026 | The Grav API plugin (getgrav/grav-plugin-api) before 1.0.3 contains a file upload extension bypass in the API media cont... |
| CVE-2026-61449 | HIGH | 7.1 | — | Jul 15, 2026 | Grav 2.0.1 contains a decompression-bomb size-cap bypass in ZipArchiver and GPM\Installer. The size bound introduced in ... |
| CVE-2026-61446 | HIGH | 8.6 | — | Jul 15, 2026 | PraisonAI (praisonaiagents) before 1.6.78 contains a remote code execution vulnerability in the plugin manager, which lo... |
| CVE-2026-61443 | HIGH | 8.6 | — | Jul 15, 2026 | PraisonAI before 1.6.78 contains a remote code execution vulnerability in SkillTools.run_skill_script() that executes sc... |
| CVE-2026-61440 | HIGH | 7.1 | 0.2% | Jul 15, 2026 | PraisonAI Platform before 0.1.9 fails to properly authorize label and issue-label mutations, allowing workspace members ... |
| CVE-2026-61438 | HIGH | 7.3 | — | Jul 15, 2026 | PraisonAI before 4.6.78 contains a remote code execution vulnerability in JobWorkflowExecutor._exec_inline_python() due ... |
| CVE-2026-61436 | HIGH | 8.8 | — | Jul 15, 2026 | PraisonAI before 4.6.78 fails to verify Svix webhook signatures in AgentMail webhook mode, allowing unauthenticated atta... |
| CVE-2026-61435 | HIGH | 8.8 | — | Jul 15, 2026 | PraisonAI before 4.6.78 contains an authentication bypass in the Call API agent invocation endpoints (src/praisonai/prai... |
| CVE-2026-61433 | HIGH | 8.5 | — | Jul 15, 2026 | PraisonAI before 4.6.78 fails to safely encode deployment configuration values when generating Python source code for AP... |
| CVE-2026-61430 | HIGH | 8.5 | — | Jul 15, 2026 | PraisonAI before 1.6.78 contains a server-side request forgery vulnerability in the web_crawl tool that validates hostna... |
| CVE-2026-61427 | HIGH | 7.3 | 0.3% | Jul 15, 2026 | PraisonAI before 4.6.78 exposes the MCP HTTP-stream transport without authentication by default: the CLI --api-key optio... |
| CVE-2026-60085 | HIGH | 8.7 | — | Jul 15, 2026 | PraisonAI before 4.6.78 contains an unenforced security policy vulnerability in the default Subprocess Sandbox backend w... |
| CVE-2026-58655 | HIGH | 8.8 | — | Jul 15, 2026 | The bundled Grav Flex Objects plugin (getgrav/grav-plugin-flex-objects) before 1.4.0 contains a stored server-side templ... |
| CVE-2026-57996 | HIGH | 8.8 | 0.2% | Jul 15, 2026 | phpMyFAQ before 4.1.5 contains a privilege escalation vulnerability in the user/add API endpoint that allows non-SuperAd... |
| CVE-2026-56339 | HIGH | 8.7 | — | Jul 15, 2026 | Capgo (Cap-go/capgo) before 12.128.2 contains an information disclosure vulnerability in the Supabase PostgREST SECURITY... |
| CVE-2026-59235 | HIGH | 8.7 | — | Jul 15, 2026 | Missing Authorization (CWE-862) in BankAccountListController (app/Http/Controllers/Api/BankAccount/BankAccountListContro... |
| CVE-2026-58077 | HIGH | 8.7 | 0.4% | Jul 15, 2026 | Joomla Extension - weeblr.com - Unauthenticated stored XSS in 4Analytics < 5.0.2 - The Joomla extension 4Analytics is vu... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now