2026 CVE Vulnerabilities
65,702 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-39305 | CRITICAL | 10 | 0.3% | Apr 7, 2026 | PraisonAI is a multi-agent teams system. Prior to 1.5.113, the Action Orchestrator feature contains a Path Traversal vul... |
| CVE-2026-35615 | HIGH | 7.5 | 0.4% | Apr 7, 2026 | PraisonAI is a multi-agent teams system. Prior to 1.5.113, _validate_path() calls os.path.normpath() first, which collap... |
| CVE-2026-35614 | CRITICAL | 9.8 | 0.3% | Apr 7, 2026 | Frappe is a full-stack web application framework. Prior to 16.14.0 and 15.104.0, Frappe has a SQL injection in bulk_upda... |
| CVE-2026-35613 | MEDIUM | 4.7 | 0.1% | Apr 7, 2026 | coursevault-preview is a utility for previewing course material files from a configured directory. coursevault-preview v... |
| CVE-2026-35611 | HIGH | 7.5 | 0.4% | Apr 7, 2026 | Addressable is an alternative implementation to the URI implementation that is part of Ruby's standard library. From 2.3... |
| CVE-2026-35610 | HIGH | 8.8 | 0.3% | Apr 7, 2026 | PolarLearn is a free and open-source learning program. In 0-PRERELEASE-14 and earlier, setCustomPassword(userId, passwor... |
| CVE-2026-35608 | MEDIUM | 6.1 | 0.2% | Apr 7, 2026 | QuickDrop is an easy-to-use file sharing application. Prior to 1.5.3, a stored XSS vulnerability exists in the file prev... |
| CVE-2026-35607 | HIGH | 8.8 | 0.4% | Apr 7, 2026 | File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a spec... |
| CVE-2026-35606 | HIGH | 7.5 | 0.3% | Apr 7, 2026 | File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a spec... |
| CVE-2026-35605 | HIGH | 7.5 | 0.4% | Apr 7, 2026 | File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a spec... |
| CVE-2026-35604 | HIGH | 8.1 | 0.3% | Apr 7, 2026 | File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a spec... |
| CVE-2026-35592 | MEDIUM | 6.5 | 0.3% | Apr 7, 2026 | pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev97, the _safe_extractall() func... |
| CVE-2026-35586 | MEDIUM | 6.8 | 0.1% | Apr 7, 2026 | pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev97, the ADMIN_ONLY_CORE_OPTIONS... |
| CVE-2026-35585 | HIGH | 7.2 | 1.9% | Apr 7, 2026 | File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a spec... |
| CVE-2026-35584 | MEDIUM | 6.5 | 0.3% | Apr 7, 2026 | FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to 1.8.212, the endpoint GET /t... |
| CVE-2026-35583 | MEDIUM | 5.3 | 0.3% | Apr 7, 2026 | Emissary is a P2P based data-driven workflow engine. Prior to 8.39.0, the configuration API endpoint (/api/configuration... |
| CVE-2026-35581 | HIGH | 7.2 | 0.6% | Apr 7, 2026 | Emissary is a P2P based data-driven workflow engine. Prior to 8.39.0, the Executrix utility class constructed shell comm... |
| CVE-2026-35580 | CRITICAL | 9.1 | 0.6% | Apr 7, 2026 | Emissary is a P2P based data-driven workflow engine. Prior to 8.39.0, GitHub Actions workflow files contained shell inje... |
| CVE-2026-35578 | — | — | — | Apr 7, 2026 | Rejected reason: This CVE is a duplicate of another CVE.** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE... |
| CVE-2026-35574 | HIGH | 8.7 | 0.3% | Apr 7, 2026 | ChurchCRM is an open-source church management system. Prior to 6.5.3, a stored Cross-Site Scripting (XSS) vulnerability ... |
| CVE-2026-35523 | HIGH | 7.5 | 0.4% | Apr 7, 2026 | Strawberry GraphQL is a library for creating GraphQL APIs. Strawberry up until version 0.312.3 is vulnerable to an authe... |
| CVE-2026-32588 | MEDIUM | 6.5 | 0.5% | Apr 7, 2026 | Authenticated DoS over CQL in Apache Cassandra 4.0, 4.1, 5.0 allows authenticated user to raise query latencies via repe... |
| CVE-2026-27315 | MEDIUM | 5.5 | 0.2% | Apr 7, 2026 | Sensitive Information Leak in cqlsh in Apache Cassandra 4.0 allows access to sensitive information, like passwords, from... |
| CVE-2026-27314 | HIGH | 8.8 | 0.3% | Apr 7, 2026 | Privilege escalation in Apache Cassandra 5.0 on an mTLS environment using MutualTlsAuthenticator allows a user with only... |
| CVE-2026-23696 | CRITICAL | 9.9 | 5.1% | Apr 7, 2026 | Windmill CE and EE versions 1.276.0 through 1.603.2 contain an SQL injection vulnerability in the folder ownership manag... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now