2026 CVE Vulnerabilities

46,825 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-8609HIGH7.5An unauthenticated attacker can repeatedly call Grafana's OAuth login route with unique values, causing unbounded memory...
CVE-2026-56676HIGH7.49Router is an AI router & token saver. Prior to 0.5.2, 9router validates image URLs by resolving the host before fetchin...
CVE-2026-55501HIGH7.39Router is an AI router & token saver. Prior to 0.4.80, the dashboard login rate limiter in src/lib/auth/loginLimiter.js...
CVE-2026-54149HIGH8.8MaxKB is an open-source AI assistant for enterprise. Prior to 2.10.0-lts, MaxKB tool import functionality in apps/tools/...
CVE-2026-54001HIGH7osquery is a SQL powered operating system instrumentation, monitoring, and analytics framework. Prior to 5.23.1, on Wind...
CVE-2026-54000HIGH7osquery is a SQL powered operating system instrumentation, monitoring, and analytics framework. Prior to 5.23.1, on Wind...
CVE-2026-33382HIGH7.5Several Grafana API endpoints, some of them unauthenticated, do not limit the size of the request body before processing...
CVE-2026-61455HIGH7.1Grav before 2.0.1 contains a decompression bomb vulnerability in ZipArchiver::extract() that lacks limits on uncompresse...
CVE-2026-61450HIGH7.1Grav before 2.0.2 contains a Twig sandbox bypass that allows a page author (any admin.pages user, or anyone able to writ...
CVE-2026-61441HIGH7.1PraisonAI Platform (praisonai-platform) before 0.1.9 improperly authorizes deletion of issue dependencies. The DELETE de...
CVE-2026-61437HIGH8.5PraisonAI (pip package praisonaiagents) before 1.6.78 contains an unsafe dynamic module loading vulnerability in AgentFl...
CVE-2026-61434HIGH8.8PraisonAI versions before 4.6.78 contain an allowlist bypass vulnerability in shell command execution that allows attack...
CVE-2026-60091HIGH7.2PraisonAI before 4.6.78 contains an unauthenticated server-side request forgery vulnerability in the Jobs API /api/v1/ru...
CVE-2026-59796HIGH8.1In JetBrains TeamCity before 2026.1.2 pipeline modification was possible due to improper permission checks
CVE-2026-59793HIGH8.8In JetBrains TeamCity before 2026.1.2 arbitrary file access was possible via the Perforce VCS integration
CVE-2026-56335HIGH7.1Capgo before 12.128.2 contains an authorization bypass vulnerability where write-scoped API keys can directly mutate pro...
CVE-2026-56305HIGH8.7Capgo before 12.128.2 contains an authentication bypass vulnerability in the password change endpoint that allows attack...
CVE-2026-56279HIGH8.7Capgo before 12.128.2 contains an information disclosure vulnerability in the get_orgs_v7(userid) RPC function that rema...
CVE-2026-56261HIGH7.5Crawl4AI before 0.8.7 contains a server-side request forgery (SSRF) vulnerability in the Docker API server's /crawl/job ...
CVE-2026-56254HIGH8.3In @capgo/capacitor-updater (Cap-go/capgo) before 12.128.2, the end-to-end encryption scheme distributes the private key...
CVE-2026-38059HIGH8.7The iDirect iQ200 exposes the /api/identity and /api/ REST API endpoints without authentication. An unauthenticated atta...
CVE-2026-38057HIGH8.1The iDirect iQ200 does not validate CSRF tokens on state-changing API endpoints after authentication. The /api/reboot en...
CVE-2026-29519HIGH8.2Lucee CFML Server versions across the 5.3.x, 6.1.x, 6.2.x, and 7.0.x release lines contain a reflected cross-site script...
CVE-2026-22660HIGH8.6FlaskBB through 2.2.0, fixed in commit a5da9a5, contains a logic flaw vulnerability that allows authenticated administra...
CVE-2026-22659HIGH8.1FlaskBB through 2.2.0, fixed in commit acc88cf, contains an authorization bypass vulnerability that allows authenticated...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now