2026 CVE Vulnerabilities

66,317 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-34935CRITICAL9.8PraisonAI is a multi-agent teams system. From version 4.5.15 to before version 4.5.69, the --mcp CLI argument is passed ...
CVE-2026-34934CRITICAL9.8PraisonAI is a multi-agent teams system. Prior to version 4.5.90, the get_all_user_threads function constructs raw SQL q...
CVE-2026-34933MEDIUM5.5Avahi is a system which facilitates service discovery on a local network via the mDNS/DNS-SD protocol suite. Prior to ve...
CVE-2026-34824HIGH7.5Mesop is a Python-based UI framework that allows users to build web applications. From version 1.2.3 to before version 1...
CVE-2026-34788MEDIUM6.5Emlog is an open source website building system. In versions 2.6.2 and prior, a SQL injection vulnerability exists in in...
CVE-2026-34787MEDIUM6.5Emlog is an open source website building system. In versions 2.6.2 and prior, a Local File Inclusion (LFI) vulnerability...
CVE-2026-34612CRITICAL9Kestra is an open-source, event-driven orchestration platform. Prior to version 1.3.7, Kestra (default docker-compose de...
CVE-2026-34607HIGH7.2Emlog is an open source website building system. In versions 2.6.2 and prior, a path traversal vulnerability exists in t...
CVE-2026-34229MEDIUM6.1Emlog is an open source website building system. Prior to version 2.6.8, there is a stored cross-site scripting (XSS) vu...
CVE-2026-34228MEDIUM6.5Emlog is an open source website building system. Prior to version 2.6.8, the backend upgrade interface accepts remote SQ...
CVE-2026-34061MEDIUM6.5nimiq/core-rs-albatross is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus a...
CVE-2026-34052MEDIUM5.9LTI JupyterHub Authenticator is a JupyterHub authenticator for LTI. Prior to version 1.6.3, the LTI 1.1 validator stores...
CVE-2026-33184HIGH7.5nimiq/core-rs-albatross is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus a...
CVE-2026-34990HIGH7.8OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. In versions 2.4.16 ...
CVE-2026-34980HIGH7.5OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. In versions 2.4.16 ...
CVE-2026-34979MEDIUM5.3OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. In versions 2.4.16 ...
CVE-2026-34978MEDIUM6.5OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. In versions 2.4.16 ...
CVE-2026-34947MEDIUM5.3Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.3, 2026.2.0-latest to be...
CVE-2026-33709MEDIUM6.1JupyterHub is software that allows one to create a multi-user server for Jupyter notebooks. Prior to version 5.4.4, an o...
CVE-2026-33175HIGH8.8OAuthenticator is software that allows OAuth2 identity providers to be plugged in and used with JupyterHub. Prior to ver...
CVE-2026-28797HIGH8.8RAGFlow is an open-source RAG (Retrieval-Augmented Generation) engine. In versions 0.24.0 and prior, a Server-Side Templ...
CVE-2026-27885HIGH7.2Piwigo is an open source photo gallery application for the web. Prior to version 16.3.0, a SQL Injection vulnerability w...
CVE-2026-27834HIGH7.2Piwigo is an open source photo gallery application for the web. Prior to version 16.3.0, a SQL Injection vulnerability e...
CVE-2026-27833HIGH7.5Piwigo is an open source photo gallery application for the web. Prior to version 16.3.0, the pwg.history.search API meth...
CVE-2026-27634CRITICAL9.8Piwigo is an open source photo gallery application for the web. Prior to version 16.3.0, the four date filter parameters...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now