2026 CVE Vulnerabilities

49,221 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-70615CRITICAL9.9boringproxy through 0.10.0 contains a newline injection vulnerability that allows authenticated low-privileged users wit...
CVE-2026-69111HIGH8.7Milvus through 2.6.22 and 3.0.0 contains an unauthenticated denial of service vulnerability that allows remote attackers...
CVE-2026-68746HIGH8.8Not Failing Securely ('Failing Open') vulnerability in livebook-dev livebook allows an unauthenticated network client to...
CVE-2026-66885MEDIUM6.5Cross-Site Request Forgery (CSRF) vulnerability in livebook-dev livebook allows an attacker to authenticate a victim's b...
CVE-2026-66881HIGH8.1Relative Path Traversal vulnerability in livebook-dev livebook allows an attacker-authored notebook to write a file with...
CVE-2026-66298HIGH8.8Origin Validation Error vulnerability in livebook-dev livebook allows untrusted notebook output JavaScript to trigger se...
CVE-2026-66297HIGH8Improper Neutralization of Special Elements used in an OS Command (OS Command Injection) vulnerability in livebook-dev l...
CVE-2026-55524HIGH7.5PraisonAI is a multi-agent teams system. In versions prior to 1.6.58, the web_crawl tool performs its SSRF check only on...
CVE-2026-55523HIGH7.7PraisonAI is a multi-agent teams system. In versions 1.5.128 through 1.6.57, the praisonaiagents.tools.web_crawl_tools.w...
CVE-2026-55522HIGH7.8PraisonAI is a multi-agent teams system. In versions 3.9.26 through 4.6.57 of praiseonai and 0.12.12 through 1.6.57 of p...
CVE-2026-21766MEDIUM5.4The default login portlet in HCL Digital Experience and Digital Experience Compose insufficiently protects credentials. ...
CVE-2026-18958HIGH7.3A vulnerability was detected in imranrisal-dev Student-Management-System 18ea7904c339e0c7b0234724a79c939ce6191def/a8d43a...
CVE-2026-18954MEDIUM5.7Incorrect authorization in the aggregation pipeline tool in Amazon AWS Labs DocumentDB MCP Server before 1.0.12 might al...
CVE-2026-18953HIGH8.8Improper limitation of a pathname to a restricted directory in the get_resource tool in Amazon awslabs.aws-transform-mcp...
CVE-2026-17556CRITICAL9.1A path traversal vulnerability was identified in GitHub Enterprise Server that allowed an unauthenticated attacker to de...
CVE-2026-9205CRITICAL9.8IBM Langflow OSS contains a weak cryptographic key derivation vulnerability in the ensure_fernet_key() function.
CVE-2026-9201HIGH8.8IBM Langflow OSS 1.0.0 through 1.10.3 could allow an authenticated attacker to execute arbitrary code due to a cryptogra...
CVE-2026-9196HIGH8.8IBM Langflow OSS 1.0.0 through 1.10.3 could allow an authenticated attacker to execute unintended code during Agentic As...
CVE-2026-9130HIGH7.1IBM Langflow OSS 1.0.0 through 1.10.3 contain an authorization bypass vulnerability in the MemoryComponent that allows a...
CVE-2026-8478HIGH8.8IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote attacker to inject arbitrary code on the system, due to the i...
CVE-2026-8470CRITICAL9.1IBM Langflow OSS 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, and 1.0.0 through 1.10.3 use Python's...
CVE-2026-8183HIGH7.7IBM Langflow OSS 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1...
CVE-2026-8182HIGH8.8IBM Langflow OSS 1.0.0 through 1.10.3 installations allow anyone on the internet to execute arbitrary code on the server...
CVE-2026-7869MEDIUM5.4IBM Langflow OSS 1.0.0 through 1.10.3 is vulnerable to Path Traversal in the Knowledge Bases API (`POST /api/v1/knowledg...
CVE-2026-7658MEDIUM6.5IBM Langflow OSS 1.0.0 through 1.10.3 does not properly validate the username field, allowing attackers to inject path t...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now