2026 CVE Vulnerabilities

45,117 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-55641HIGH8.29Router is an AI router & token saver. Prior to 0.5.2, 9router determines whether a /v1 LLM proxy request is local by re...
CVE-2026-55638HIGH8.69Router is an AI router & token saver. Prior to 0.5.2, 9router protects /v1, /v1beta, /api/v1, and /api/v1beta in src/da...
CVE-2026-54919HIGH7.4cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. In affected Mbed TLS backend versions ...
CVE-2026-54063HIGH7.5Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets. Prior to 2.11.0, the checkSheet(...
CVE-2026-53657HIGH8.2Lima launches Linux virtual machines, typically on macOS, for running containerd. Prior to 2.1.3, on an instance of Lima...
CVE-2026-53653HIGH8.7Grav is a file-based Web platform. Prior to 1.7.53 and 2.0.0-rc.8, Grav allows an unauthenticated visitor to exhaust ser...
CVE-2026-39903HIGH7.1Simple Machines Forum 2.1 prior to commit 7d048f8 and 3.0 prior to commit a7875e8 contains an authorization bypass vulne...
CVE-2026-39244HIGH7.5adm-zip before 0.5.18 is vulnerable to denial of service via a crafted ZIP file with a manipulated uncompressed size hea...
CVE-2026-2398HIGH8.8Authorization bypass through User-Controlled key vulnerability in Adam Retail Automation Ltd. MobilMen 20T allows Privil...
CVE-2026-1667HIGH7.2The SEO Plugin by Squirrly SEO plugin for WordPress is vulnerable to Arbitrary Post Creation and Stored Cross-Site Scrip...
CVE-2026-8609HIGH7.5An unauthenticated attacker can repeatedly call Grafana's OAuth login route with unique values, causing unbounded memory...
CVE-2026-56676HIGH7.49Router is an AI router & token saver. Prior to 0.5.2, 9router validates image URLs by resolving the host before fetchin...
CVE-2026-55501HIGH7.39Router is an AI router & token saver. Prior to 0.4.80, the dashboard login rate limiter in src/lib/auth/loginLimiter.js...
CVE-2026-54149HIGH8.8MaxKB is an open-source AI assistant for enterprise. Prior to 2.10.0-lts, MaxKB tool import functionality in apps/tools/...
CVE-2026-54001HIGH7osquery is a SQL powered operating system instrumentation, monitoring, and analytics framework. Prior to 5.23.1, on Wind...
CVE-2026-54000HIGH7osquery is a SQL powered operating system instrumentation, monitoring, and analytics framework. Prior to 5.23.1, on Wind...
CVE-2026-33382HIGH7.5Several Grafana API endpoints, some of them unauthenticated, do not limit the size of the request body before processing...
CVE-2026-61455HIGH7.1Grav before 2.0.1 contains a decompression bomb vulnerability in ZipArchiver::extract() that lacks limits on uncompresse...
CVE-2026-61450HIGH7.1Grav before 2.0.2 contains a Twig sandbox bypass that allows a page author (any admin.pages user, or anyone able to writ...
CVE-2026-61441HIGH7.1PraisonAI Platform (praisonai-platform) before 0.1.9 improperly authorizes deletion of issue dependencies. The DELETE de...
CVE-2026-61437HIGH8.5PraisonAI (pip package praisonaiagents) before 1.6.78 contains an unsafe dynamic module loading vulnerability in AgentFl...
CVE-2026-61434HIGH8.8PraisonAI versions before 4.6.78 contain an allowlist bypass vulnerability in shell command execution that allows attack...
CVE-2026-60091HIGH7.2PraisonAI before 4.6.78 contains an unauthenticated server-side request forgery vulnerability in the Jobs API /api/v1/ru...
CVE-2026-59796HIGH8.1In JetBrains TeamCity before 2026.1.2 pipeline modification was possible due to improper permission checks
CVE-2026-59793HIGH8.8In JetBrains TeamCity before 2026.1.2 arbitrary file access was possible via the Perforce VCS integration

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now