2026 CVE Vulnerabilities

48,306 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-56075HIGH8.8PraisonAI before 4.5.128 contains an arbitrary shell command execution vulnerability where the UI modules hardcode appro...
CVE-2026-8100HIGH8.6Impact A security issue has been identified in Chef 360 that could allow unauthorized access to protected API endpoints...
CVE-2026-54130HIGH7.5Missing authentication for critical function in M365 Copilot allows an unauthorized attacker to disclose information ove...
CVE-2026-54017HIGH7.7Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.6, the t...
CVE-2026-47633HIGH7.5Exposure of sensitive information to an unauthorized actor in Cost Management Interactive Experiences allows an unauthor...
CVE-2026-32174HIGH8.8Improper authentication in Azure Bot Service allows an authorized attacker to elevate privileges over a network.
CVE-2026-49248HIGH8.3OneDev is a Git server with CI/CD, kanban, and packages. In versions 15.0.6 and below, TarUtils.untar() creates symbolic...
CVE-2026-46699HIGH7.6conda-smithy is a tool for combining a conda recipe with configurations to build using freely hosted CI services into a ...
CVE-2026-44663HIGH7.1OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture in...
CVE-2026-48716HIGH8.7nanobot is a personal AI assistant. In versions 0.1.5.post3 and prior, the WhatsApp bridge in bridge/src/whatsapp.ts con...
CVE-2026-25865HIGH8.5Punto Switcher through 4.5.0.583 contains an unquoted search path element vulnerability that allows local attackers to e...
CVE-2026-48937HIGH7.5A flaw in Node.js HTTP/2 server API can cause servers to keep accepting data even after sending a `GOAWAY` frame. This v...
CVE-2026-12390HIGH7.8In AzeoTech DAQFactory versions 21.1 and prior, a Type Confusion vulnerability can be exploited by an attacker using spe...
CVE-2026-55237HIGH8.8AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agent...
CVE-2026-55204HIGH8.7HAProxy through 3.4.0, fixed in commit 9a6d1fe, contains a null pointer dereference vulnerability in hpack_dht_insert()...
CVE-2026-54104HIGH8.8The U.S. Government Accountability Office (GAO) Electronic Protest Docketing System (EPDS) and Civilian Board of Contrac...
CVE-2026-48617HIGH8.2A flaw in Node.js Permission Model enforcement allows Bypass via `process.report.writeReport()` Path Misvalidation. This...
CVE-2026-38718HIGH7.5InHand Networks IR912 V1.0.0.r20042 and IR915 V1.0.0.r20042 (including earlier versions) were discovered to contain a bu...
CVE-2026-46580HIGH8.8In Eclipse Theia versions prior to 1.71.0, files matching the pattern .prompts/*.prompttemplate in a workspace were auto...
CVE-2026-44691HIGH8.8In Eclipse Theia versions prior to 1.69.0, custom task definitions in workspace files (e.g. .theia/tasks.json, .vscode/t...
CVE-2026-44688HIGH8.8In Eclipse Theia versions prior to 1.71.0, the AI chat agent processed workspace file and directory names as part of its...
CVE-2026-8461HIGH8.8An out-of-bounds write vulnerability in FFmpeg's libavcodec library, specifically in the MagicYUV decoder, allows denial...
CVE-2026-56012HIGH8.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in David Lingren Medi...
CVE-2026-54224HIGH7.1UBB.threads is vulnerable to Denial of Service (DoS). By sending multiple concurrent requests to view any user profile o...
CVE-2026-54223HIGH8.6UBB.threads is vulnerable to Path traversal, allowing attackers with privilege to edit templates to read and write any f...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now