2026 CVE Vulnerabilities

64,788 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-41584HIGH7.5ZEBRA is a Zcash node written entirely in Rust. Prior to zebrad version 4.3.1 and prior to zebra-chain version 6.0.2, Or...
CVE-2026-41583CRITICAL9.1ZEBRA is a Zcash node written entirely in Rust. Prior to zebrad version 4.3.1 and prior to zebra-script version 5.0.2, a...
CVE-2026-41576HIGH7.1Brave CMS is an open-source CMS. Prior to commit 6c56603, the contact form is publicly accessible (no authentication req...
CVE-2026-41575MEDIUM6.1In th30d4y/IP from version 1.0.1 to before version 2.0.1, a DOM-Based Cross-Site Scripting (XSS) vulnerability was ident...
CVE-2026-41574CRITICAL9.8Nhost is an open source Firebase alternative with GraphQL. Prior to version 0.49.1, Nhost automatically links an incomin...
CVE-2026-41570HIGH7.8PHPUnit is a testing framework for PHP. In versions 12.5.21 and 13.1.5, PHPUnit forwards PHP INI settings to child proce...
CVE-2026-41524HIGH8.7Brave CMS is an open-source CMS. Prior to commit 6c56603, page and article body content entered through the CKEditor ric...
CVE-2026-41487MEDIUM5.4Langfuse is an open source large language model engineering platform. From version 3.68.0 to before version 3.167.0, the...
CVE-2026-41308MEDIUM6.5Password Pusher is an open source application to communicate sensitive information over the web. Prior to versions 1.69....
CVE-2026-38361HIGH7.5Multiple unauthenticated denial-of-service (DoS) issues in fohrloop dash-uploader v0.1.0 through v0.7.0a2. The chunked-u...
CVE-2026-37431CRITICAL9.8Beauty Parlour Management System v1.1 was discovered to contain a SQL injection vulnerability via the aptnumber paramete...
CVE-2026-7864MEDIUM6.9SEPPmail Secure Email Gateway before version 15.0.4 exposes server environment variables through an unauthenticated endp...
CVE-2026-44340HIGH7.5PraisonAI is a multi-agent teams system. Prior to version 4.6.37, the _safe_extractall helper that all recipe pull, reci...
CVE-2026-44339HIGH8.6PraisonAI is a multi-agent teams system. Prior to praisonai version 4.6.37 and praisonaiagents version 1.6.37, praisonai...
CVE-2026-44338HIGH7.3PraisonAI is a multi-agent teams system. From version 2.5.6 to before version 4.6.34, PraisonAI ships a legacy Flask API...
CVE-2026-44337MEDIUM6.3PraisonAI is a multi-agent teams system. From version 2.4.1 to before version 4.6.34, PraisonAI exposes optional SQL/CQL...
CVE-2026-44336CRITICAL9.6PraisonAI is a multi-agent teams system. Prior to version 4.6.34, PraisonAI's MCP (Model Context Protocol) server (prais...
CVE-2026-44335CRITICAL9.8PraisonAI is a multi-agent teams system. Prior to version 1.6.32, the URL checking logic in PraisonAI has a logical flaw...
CVE-2026-44334HIGH8.4PraisonAI is a multi-agent teams system. From version 4.5.139 to before version 4.6.32, CVE-2026-40287's fix gated tools...
CVE-2026-44129HIGH8.3SEPPmail Secure Email Gateway before version 15.0.4 contains a server-side template injection vulnerability in the new G...
CVE-2026-44128CRITICAL9.3SEPPmail Secure Email Gateway before version 15.0.2.1 allows unauthenticated remote code execution in the new GINA UI be...
CVE-2026-44127HIGH8.8SEPPmail Secure Email Gateway before version 15.0.4 contains an unauthenticated path traversal vulnerability in the iden...
CVE-2026-44126CRITICAL9.2SEPPmail Secure Email Gateway before version 15.0.4 insecurely deserializes untrusted data, which can be reached from th...
CVE-2026-44125CRITICAL9.3SEPPmail Secure Email Gateway before version 15.0.4 fails to enforce authorization checks for multiple endpoints in the ...
CVE-2026-43350HIGH7.6In the Linux kernel, the following vulnerability has been resolved: smb: client: require a full NFS mode SID before rea...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now