2026 CVE Vulnerabilities

46,851 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-61437HIGH8.5PraisonAI (pip package praisonaiagents) before 1.6.78 contains an unsafe dynamic module loading vulnerability in AgentFl...
CVE-2026-61434HIGH8.8PraisonAI versions before 4.6.78 contain an allowlist bypass vulnerability in shell command execution that allows attack...
CVE-2026-60091HIGH7.2PraisonAI before 4.6.78 contains an unauthenticated server-side request forgery vulnerability in the Jobs API /api/v1/ru...
CVE-2026-59796HIGH8.1In JetBrains TeamCity before 2026.1.2 pipeline modification was possible due to improper permission checks
CVE-2026-59793HIGH8.8In JetBrains TeamCity before 2026.1.2 arbitrary file access was possible via the Perforce VCS integration
CVE-2026-56335HIGH7.1Capgo before 12.128.2 contains an authorization bypass vulnerability where write-scoped API keys can directly mutate pro...
CVE-2026-56305HIGH8.7Capgo before 12.128.2 contains an authentication bypass vulnerability in the password change endpoint that allows attack...
CVE-2026-56279HIGH8.7Capgo before 12.128.2 contains an information disclosure vulnerability in the get_orgs_v7(userid) RPC function that rema...
CVE-2026-56261HIGH7.5Crawl4AI before 0.8.7 contains a server-side request forgery (SSRF) vulnerability in the Docker API server's /crawl/job ...
CVE-2026-56254HIGH8.3In @capgo/capacitor-updater (Cap-go/capgo) before 12.128.2, the end-to-end encryption scheme distributes the private key...
CVE-2026-38059HIGH8.7The iDirect iQ200 exposes the /api/identity and /api/ REST API endpoints without authentication. An unauthenticated atta...
CVE-2026-38057HIGH8.1The iDirect iQ200 does not validate CSRF tokens on state-changing API endpoints after authentication. The /api/reboot en...
CVE-2026-29519HIGH8.2Lucee CFML Server versions across the 5.3.x, 6.1.x, 6.2.x, and 7.0.x release lines contain a reflected cross-site script...
CVE-2026-22660HIGH8.6FlaskBB through 2.2.0, fixed in commit a5da9a5, contains a logic flaw vulnerability that allows authenticated administra...
CVE-2026-22659HIGH8.1FlaskBB through 2.2.0, fixed in commit acc88cf, contains an authorization bypass vulnerability that allows authenticated...
CVE-2026-54469HIGH8.8Dell Unisphere for PowerMax, version(s) 10.3.0.5 and prior, contain(s) a Deserialization of Untrusted Data vulnerability...
CVE-2026-56690HIGH8.5Dell PowerFlex Manager, Version prior to 5.1.0.1, contain(s) an Improper Neutralization of Special Elements used in an S...
CVE-2026-56689HIGH7.7Dell PowerFlex Manager, Version prior to 5.1.0.1, contain(s) an Improper Neutralization of Special Elements used in an S...
CVE-2026-41879HIGH8.2R-SOFT DMS stores superadmin credentials using a non-salted nested MD5 hash. This allows an attacker who obtain password...
CVE-2026-41878HIGH7.1R-SOFT DMS is vulnerable to Insecure Direct Object Reference (IDOR) attack in multiple file download endpoints. The appl...
CVE-2026-41876HIGH8.7R-SOFT DMS is vulnerable to OS Command Injection in konwertujAction() function. The document converter executes shell co...
CVE-2026-40454HIGH7.5Out-of-bounds Read, Improper Input Validation vulnerability in Apache IoTDB C++ client. Out-of-bounds reads in IoTDB C++...
CVE-2026-40452HIGH7.5Incorrect Authorization, Improper Access Control vulnerability in Apache IoTDB. Authorization bypass in /rest/v2/fastLas...
CVE-2026-40007HIGH7.5Uncontrolled Recursion, Uncontrolled Resource Consumption vulnerability in Apache IoTDB. When pipe_air_gap_receiver_enab...
CVE-2026-40006HIGH7.5Memory Allocation with Excessive Size Value, Allocation of Resources Without Limits or Throttling, Missing Authenticatio...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now