2026 CVE Vulnerabilities

65,702 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-39305CRITICAL10PraisonAI is a multi-agent teams system. Prior to 1.5.113, the Action Orchestrator feature contains a Path Traversal vul...
CVE-2026-35615HIGH7.5PraisonAI is a multi-agent teams system. Prior to 1.5.113, _validate_path() calls os.path.normpath() first, which collap...
CVE-2026-35614CRITICAL9.8Frappe is a full-stack web application framework. Prior to 16.14.0 and 15.104.0, Frappe has a SQL injection in bulk_upda...
CVE-2026-35613MEDIUM4.7coursevault-preview is a utility for previewing course material files from a configured directory. coursevault-preview v...
CVE-2026-35611HIGH7.5Addressable is an alternative implementation to the URI implementation that is part of Ruby's standard library. From 2.3...
CVE-2026-35610HIGH8.8PolarLearn is a free and open-source learning program. In 0-PRERELEASE-14 and earlier, setCustomPassword(userId, passwor...
CVE-2026-35608MEDIUM6.1QuickDrop is an easy-to-use file sharing application. Prior to 1.5.3, a stored XSS vulnerability exists in the file prev...
CVE-2026-35607HIGH8.8File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a spec...
CVE-2026-35606HIGH7.5File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a spec...
CVE-2026-35605HIGH7.5File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a spec...
CVE-2026-35604HIGH8.1File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a spec...
CVE-2026-35592MEDIUM6.5pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev97, the _safe_extractall() func...
CVE-2026-35586MEDIUM6.8pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev97, the ADMIN_ONLY_CORE_OPTIONS...
CVE-2026-35585HIGH7.2File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a spec...
CVE-2026-35584MEDIUM6.5FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to 1.8.212, the endpoint GET /t...
CVE-2026-35583MEDIUM5.3Emissary is a P2P based data-driven workflow engine. Prior to 8.39.0, the configuration API endpoint (/api/configuration...
CVE-2026-35581HIGH7.2Emissary is a P2P based data-driven workflow engine. Prior to 8.39.0, the Executrix utility class constructed shell comm...
CVE-2026-35580CRITICAL9.1Emissary is a P2P based data-driven workflow engine. Prior to 8.39.0, GitHub Actions workflow files contained shell inje...
CVE-2026-35578——Rejected reason: This CVE is a duplicate of another CVE.** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE...
CVE-2026-35574HIGH8.7ChurchCRM is an open-source church management system. Prior to 6.5.3, a stored Cross-Site Scripting (XSS) vulnerability ...
CVE-2026-35523HIGH7.5Strawberry GraphQL is a library for creating GraphQL APIs. Strawberry up until version 0.312.3 is vulnerable to an authe...
CVE-2026-32588MEDIUM6.5Authenticated DoS over CQL in Apache Cassandra 4.0, 4.1, 5.0 allows authenticated user to raise query latencies via repe...
CVE-2026-27315MEDIUM5.5Sensitive Information Leak in cqlsh in Apache Cassandra 4.0 allows access to sensitive information, like passwords, from...
CVE-2026-27314HIGH8.8Privilege escalation in Apache Cassandra 5.0 on an mTLS environment using MutualTlsAuthenticator allows a user with only...
CVE-2026-23696CRITICAL9.9Windmill CE and EE versions 1.276.0 through 1.603.2 contain an SQL injection vulnerability in the folder ownership manag...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now