2026 CVE Vulnerabilities

64,763 CVEs published in 2026.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2026-54333CRITICAL9.8UEFI Firmware Parser parses BIOS, Intel ME, and UEFI firmware structures including volumes, file systems, and files. Pri...
CVE-2026-50006CRITICAL9.1Anyquery is an SQL query engine built on top of SQLite. Prior to 0.4.5, anyquery server forwards unauthenticated SQL fro...
CVE-2026-18119CRITICAL9Concrete CMS below 9.5.3 did not sanitize custom style values in the Block Design dialog before writing them into page C...
CVE-2026-16338CRITICAL9.9IBM DataStage on Cloud Pak for Data 5.4.0.0 IBM DataStage could allow a remote authenticated attacker to perform an arbi...
CVE-2026-59178CRITICAL9.8ESPHome Device Builder Dashboard is a dashboard for the ESPHome home management software. Prior to version 1.0.12, the d...
CVE-2026-90945CRITICAL9.8Crawlab through 0.6.3 uses a hard-coded HMAC-SHA256 secret for JWT token signing that cannot be overridden via configura...
CVE-2026-90942CRITICAL9.6Casdoor through 4.4.0 fails to properly mask the instance-wide built-in certificate private key in /api/get-certs and /a...
CVE-2026-57578CRITICAL9.2DotVVM is an open source MVVM framework for web applications. Prior to 4.2.11, 4.3.15, and 5.0.0-preview09-final, Author...
CVE-2026-76461CRITICAL9.8A vulnerability in the email parsing of Cisco AsyncOS Software for Cisco Secure Email Gateway could allow an unauthentic...
CVE-2026-76443CRITICAL9.8As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Email Gateway and Cisc...
CVE-2026-76441CRITICAL9.8As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Email Gateway and Cisc...
CVE-2026-76440CRITICAL9.8As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Email Gateway and Cisc...
CVE-2026-20353CRITICAL9.8As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Email Gateway and Cisc...
CVE-2026-61534CRITICAL9.1Yayson is a library for serializing and reading JSON API data in JavaScript. Prior to 4.3.0, Store and LegacyStore use a...
CVE-2026-57145CRITICAL9.1PraisonAI is a multi-agent teams system. Prior to 4.6.62, src/praisonai/praisonai/tools/multiedit.py passes the LLM-cont...
CVE-2026-57131CRITICAL9.8PraisonAI is a multi-agent teams system. Prior to 4.6.58, praisonai.jobs.server.create_app mounts praisonai.jobs.router....
CVE-2026-57127CRITICAL9.8PraisonAI is a multi-agent teams system. Prior to 4.6.58, recipe serve installs APIKeyAuthMiddleware or JWTAuthMiddlewar...
CVE-2026-57124CRITICAL9.8PraisonAI is a multi-agent teams system. Prior to 4.6.59, the default UI host applications expose POST /api/mcp/connect ...
CVE-2026-82435CRITICAL9.8Description The worker's Netty message decoder is installed ahead of the SASL authentication handlers in the pipeline a...
CVE-2026-82431CRITICAL9.8Description `SimpleACLAuthorizer` evaluated the user-level command set by returning early when `nimbus.users` was empty...
CVE-2026-57125CRITICAL9.8PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.59 and praisonaiagents 1.6.59, the unauthenticated POST ...
CVE-2026-57123CRITICAL9.8PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.59, ToolsMCPServer.run_sse and launch_tools_mcp_se...
CVE-2026-90961CRITICAL9.3The LdapAuth and LinOTPAuth authentication plugins in MISP contain an authentication bypass vulnerability. Both LdapAuth...
CVE-2026-82441CRITICAL9.1Description A submitted topology carries two lists of blobstore keys, `dependency_jars` and `dependency_artifacts`, whi...
CVE-2026-82439CRITICAL9.8Description The DRPC server kept a map from function name to request queue and created an entry the first time a functi...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now