2026 CVE Vulnerabilities

45,004 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-54560HIGH7.6Cloudreve is a self-hosted file management and sharing system. From 4.12.0 until 4.16.1, Cloudreve's OAuth access tokens...
CVE-2026-52865HIGH7.1When NGINX Ingress Controller processes Ingress or TransportServer resources, an authenticated, remote attacker with per...
CVE-2026-58558HIGH7.8Permission control vulnerability in the file system. Impact: Successful exploitation of this vulnerability may affect se...
CVE-2026-46458HIGH7.1ICU Scandinavia Boomerang is vulnerable to an information disclosure flaw where sensitive credential files are exposed v...
CVE-2026-15809HIGH7.8A flaw was found in CRI-O. The fix for a previous vulnerability (CVE-2022-4318) was incorrect, allowing it to be bypasse...
CVE-2026-61873HIGH8.1Grav before 9.1.8 contains an arbitrary file write vulnerability in the Form plugin's process.save.filename parameter, w...
CVE-2026-61866HIGH7.5ImageMagick before 7.1.2-26 contains a memory leak vulnerability in the JNG encoder when a blob cannot be opened. Attack...
CVE-2026-61863HIGH7.5ImageMagick before 7.1.2-26 (and 6.x before 6.9.13-51) contains a memory leak in the TIFF encoder that occurs when a tem...
CVE-2026-61457HIGH8.8The Grav API plugin (getgrav/grav-plugin-api) before 1.0.3 contains a file upload extension bypass in the API media cont...
CVE-2026-61449HIGH7.1Grav 2.0.1 contains a decompression-bomb size-cap bypass in ZipArchiver and GPM\Installer. The size bound introduced in ...
CVE-2026-61446HIGH8.6PraisonAI (praisonaiagents) before 1.6.78 contains a remote code execution vulnerability in the plugin manager, which lo...
CVE-2026-61443HIGH8.6PraisonAI before 1.6.78 contains a remote code execution vulnerability in SkillTools.run_skill_script() that executes sc...
CVE-2026-61440HIGH7.1PraisonAI Platform before 0.1.9 fails to properly authorize label and issue-label mutations, allowing workspace members ...
CVE-2026-61438HIGH7.3PraisonAI before 4.6.78 contains a remote code execution vulnerability in JobWorkflowExecutor._exec_inline_python() due ...
CVE-2026-61436HIGH8.8PraisonAI before 4.6.78 fails to verify Svix webhook signatures in AgentMail webhook mode, allowing unauthenticated atta...
CVE-2026-61435HIGH8.8PraisonAI before 4.6.78 contains an authentication bypass in the Call API agent invocation endpoints (src/praisonai/prai...
CVE-2026-61433HIGH8.5PraisonAI before 4.6.78 fails to safely encode deployment configuration values when generating Python source code for AP...
CVE-2026-61430HIGH8.5PraisonAI before 1.6.78 contains a server-side request forgery vulnerability in the web_crawl tool that validates hostna...
CVE-2026-61427HIGH7.3PraisonAI before 4.6.78 exposes the MCP HTTP-stream transport without authentication by default: the CLI --api-key optio...
CVE-2026-60085HIGH8.7PraisonAI before 4.6.78 contains an unenforced security policy vulnerability in the default Subprocess Sandbox backend w...
CVE-2026-58655HIGH8.8The bundled Grav Flex Objects plugin (getgrav/grav-plugin-flex-objects) before 1.4.0 contains a stored server-side templ...
CVE-2026-57996HIGH8.8phpMyFAQ before 4.1.5 contains a privilege escalation vulnerability in the user/add API endpoint that allows non-SuperAd...
CVE-2026-56339HIGH8.7Capgo (Cap-go/capgo) before 12.128.2 contains an information disclosure vulnerability in the Supabase PostgREST SECURITY...
CVE-2026-59235HIGH8.7Missing Authorization (CWE-862) in BankAccountListController (app/Http/Controllers/Api/BankAccount/BankAccountListContro...
CVE-2026-58077HIGH8.7Joomla Extension - weeblr.com - Unauthenticated stored XSS in 4Analytics < 5.0.2 - The Joomla extension 4Analytics is vu...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now