2026 CVE Vulnerabilities

65,619 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-40037HIGH7.1OpenClaw before 2026.3.31 (patched in 2026.4.8) contains a request body replay vulnerability in fetchWithSsrFGuard that ...
CVE-2026-40036HIGH8.7Unfurl before 2026.04 contains an unbounded zlib decompression vulnerability in parse_compressed.py that allows remote a...
CVE-2026-40035CRITICAL9.3Unfurl through 2025.08 contains an improper input validation vulnerability in config parsing that enables Flask debug mo...
CVE-2026-40032HIGH8.5UAC (Unix-like Artifacts Collector) before 3.3.0-rc1 contains a command injection vulnerability in the placeholder subst...
CVE-2026-40031HIGH8.5MemProcFS before 5.17 contains multiple unsafe library-loading patterns that enable DLL and shared-library hijacking acr...
CVE-2026-40030HIGH8.4parseusbs before 1.9 contains an OS command injection vulnerability where the volume listing path argument (-v flag) is ...
CVE-2026-40029HIGH7.8parseusbs before 1.9 contains an OS command injection vulnerability in parseUSBs.py where LNK file paths are passed unsa...
CVE-2026-40028MEDIUM5.4Hayabusa versions prior to 3.8.0 contain a cross-site scripting (XSS) vulnerability in its HTML report output that allow...
CVE-2026-40027HIGH8.4ALEAPP (Android Logs Events And Protobuf Parser) through 3.4.0 contains a path traversal vulnerability in the NQ_Vault.p...
CVE-2026-40026HIGH7.1The Sleuth Kit through 4.14.0 contains an out-of-bounds read vulnerability in the ISO9660 filesystem parser where the pa...
CVE-2026-40025MEDIUM6.1The Sleuth Kit through 4.14.0 contains an out-of-bounds read vulnerability in the APFS filesystem keybag parser where th...
CVE-2026-40024HIGH7.1The Sleuth Kit through 4.14.0 contains a path traversal vulnerability in tsk_recover that allows an attacker to write fi...
CVE-2026-39901MEDIUM5.7monetr is a budgeting application focused on planning for recurring expenses. Prior to 1.12.3, a transaction integrity f...
CVE-2026-5805HIGH7.3A weakness has been identified in code-projects Easy Blog Site up to 1.0. The impacted element is an unknown function of...
CVE-2026-5803MEDIUM6.3A security flaw has been discovered in bigsk1 openai-realtime-ui up to 188ccde27fdf3d8fab8da81f3893468f53b2797c. The aff...
CVE-2026-5451MEDIUM6.4The Extensions for Leaflet Map plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'elevation-trac...
CVE-2026-5436HIGH8.1The MW WP Form plugin for WordPress is vulnerable to Arbitrary File Move/Read in all versions up to and including 5.1.1....
CVE-2026-39892CRITICAL9.8cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. From 45.0.0 to b...
CVE-2026-39891HIGH8.8PraisonAI is a multi-agent teams system. Prior to 4.5.115, the create_agent_centric_tools() function returns tools (like...
CVE-2026-39890CRITICAL9.8PraisonAI is a multi-agent teams system. Prior to 4.5.115, the AgentService.loadAgentFromFile method uses the js-yaml li...
CVE-2026-39889HIGH7.5PraisonAI is a multi-agent teams system. Prior to 4.5.115, the A2U (Agent-to-User) event stream server in PraisonAI expo...
CVE-2026-39888CRITICAL9.9PraisonAI is a multi-agent teams system. Prior to 1.5.115, execute_code() in praisonaiagents.tools.python_tools defaults...
CVE-2026-39885HIGH7.5FrontMCP is a TypeScript-first framework for the Model Context Protocol (MCP). Prior to 2.3.0, the mcp-from-openapi libr...
CVE-2026-39883HIGH7OpenTelemetry-Go is the Go implementation of OpenTelemetry. From 1.15.0 to 1.42.0, the fix for CVE-2026-24051 changed th...
CVE-2026-39882MEDIUM5.3OpenTelemetry-Go is the Go implementation of OpenTelemetry. Prior to 1.43.0, the otlp HTTP exporters (traces/metrics/log...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now