2026 CVE Vulnerabilities

64,763 CVEs published in 2026.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2026-92071CRITICAL9.6Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component. This vulnerability was fixed in Fire...
CVE-2026-92066CRITICAL9.8Sandbox escape in the Profile Backup component. This vulnerability was fixed in Firefox 156 and Thunderbird 156.
CVE-2026-92061CRITICAL9.8Incorrect boundary conditions in the Security: Process Sandboxing component. This vulnerability was fixed in Firefox 156...
CVE-2026-92059CRITICAL9.3Incorrect boundary conditions in the DOM: Editor component. This vulnerability was fixed in Firefox 156, Firefox ESR 153...
CVE-2026-92057CRITICAL9.1Mitigation bypass in the Enterprise Policies component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, ...
CVE-2026-92051CRITICAL9.1Spoofing issue due to invalid pointer in the Graphics component. This vulnerability was fixed in Firefox 156 and Thunder...
CVE-2026-92050CRITICAL9.1Sandbox escape due to race condition in the XPConnect component. This vulnerability was fixed in Firefox 156 and Thunder...
CVE-2026-92048CRITICAL9Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component. This vulnerability was fixed in Fire...
CVE-2026-92045CRITICAL9.6Sandbox escape due to incorrect boundary conditions in the WebRTC component. This vulnerability was fixed in Firefox 156...
CVE-2026-92041CRITICAL9.1Mitigation bypass in the DOM: Networking component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thun...
CVE-2026-92038CRITICAL9.1Mitigation bypass in the Remote Settings Client component. This vulnerability was fixed in Firefox 156, Firefox ESR 153....
CVE-2026-92037CRITICAL9.8Incorrect boundary conditions in the DOM: Animation component. This vulnerability was fixed in Firefox 156 and Thunderbi...
CVE-2026-92036CRITICAL9.8Incorrect boundary conditions in the Networking: HTTP component. This vulnerability was fixed in Firefox 156 and Thunder...
CVE-2026-92035CRITICAL9.6Sandbox escape due to incorrect boundary conditions in the Graphics component. This vulnerability was fixed in Firefox 1...
CVE-2026-92034CRITICAL9.1Site isolation issue in the Graphics component. This vulnerability was fixed in Firefox 156 and Thunderbird 156.
CVE-2026-92032CRITICAL9.6Sandbox escape due to invalid pointer in the Graphics component. This vulnerability was fixed in Firefox 156, Firefox ES...
CVE-2026-92018CRITICAL9.6Sandbox escape in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firef...
CVE-2026-91998CRITICAL9.9Casdoor through 4.4.0 contains an authorization bypass vulnerability in the /api/mcp endpoint that allows attackers with...
CVE-2026-91995CRITICAL9.1pig before 4.1.0 contains an authentication bypass vulnerability in the /register/password endpoint where password verif...
CVE-2026-89308CRITICAL9.3An unauthenticated OS command injection vulnerability exists in the ping.php endpoint, allowing remote attackers to exec...
CVE-2026-57148CRITICAL9.8PraisonAI is a multi-agent teams system. Prior to 0.1.6, praisonai_platform/services/auth_service.py falls back to the p...
CVE-2026-57147CRITICAL9.8PraisonAI is a multi-agent teams system. Prior to 0.1.6, praisonai_platform/services/auth_service.py assigns the public ...
CVE-2026-57141CRITICAL9.8PraisonAI is a multi-agent teams system. Prior to 1.7.2, the codeMode tool in src/praisonai-ts/src/tools/builtins/code-m...
CVE-2026-57140CRITICAL9.4PraisonAI is a multi-agent teams system. From 1.6.0 until 1.7.2, AgentOS in src/praisonai-ts/src/os/agentos.ts uses the ...
CVE-2026-57139CRITICAL9.8PraisonAI is a multi-agent teams system. From 1.5.0 until 1.7.2, MCPServer.startHttp() in src/praisonai-ts/src/mcp/serve...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now