2026 CVE Vulnerabilities
48,306 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-56075 | HIGH | 8.8 | 0.5% | Jun 18, 2026 | PraisonAI before 4.5.128 contains an arbitrary shell command execution vulnerability where the UI modules hardcode appro... |
| CVE-2026-8100 | HIGH | 8.6 | 0.4% | Jun 18, 2026 | Impact A security issue has been identified in Chef 360 that could allow unauthorized access to protected API endpoints... |
| CVE-2026-54130 | HIGH | 7.5 | 0.6% | Jun 18, 2026 | Missing authentication for critical function in M365 Copilot allows an unauthorized attacker to disclose information ove... |
| CVE-2026-54017 | HIGH | 7.7 | 0.3% | Jun 18, 2026 | Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.6, the t... |
| CVE-2026-47633 | HIGH | 7.5 | 0.6% | Jun 18, 2026 | Exposure of sensitive information to an unauthorized actor in Cost Management Interactive Experiences allows an unauthor... |
| CVE-2026-32174 | HIGH | 8.8 | 0.4% | Jun 18, 2026 | Improper authentication in Azure Bot Service allows an authorized attacker to elevate privileges over a network. |
| CVE-2026-49248 | HIGH | 8.3 | 0.4% | Jun 18, 2026 | OneDev is a Git server with CI/CD, kanban, and packages. In versions 15.0.6 and below, TarUtils.untar() creates symbolic... |
| CVE-2026-46699 | HIGH | 7.6 | 0.2% | Jun 18, 2026 | conda-smithy is a tool for combining a conda recipe with configurations to build using freely hosted CI services into a ... |
| CVE-2026-44663 | HIGH | 7.1 | 0.2% | Jun 18, 2026 | OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture in... |
| CVE-2026-48716 | HIGH | 8.7 | 0.3% | Jun 18, 2026 | nanobot is a personal AI assistant. In versions 0.1.5.post3 and prior, the WhatsApp bridge in bridge/src/whatsapp.ts con... |
| CVE-2026-25865 | HIGH | 8.5 | 0.1% | Jun 18, 2026 | Punto Switcher through 4.5.0.583 contains an unquoted search path element vulnerability that allows local attackers to e... |
| CVE-2026-48937 | HIGH | 7.5 | 0.5% | Jun 18, 2026 | A flaw in Node.js HTTP/2 server API can cause servers to keep accepting data even after sending a `GOAWAY` frame. This v... |
| CVE-2026-12390 | HIGH | 7.8 | 0.1% | Jun 18, 2026 | In AzeoTech DAQFactory versions 21.1 and prior, a Type Confusion vulnerability can be exploited by an attacker using spe... |
| CVE-2026-55237 | HIGH | 8.8 | 0.2% | Jun 18, 2026 | AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agent... |
| CVE-2026-55204 | HIGH | 8.7 | 0.4% | Jun 18, 2026 | HAProxy through 3.4.0, fixed in commit 9a6d1fe, contains a null pointer dereference vulnerability in hpack_dht_insert()... |
| CVE-2026-54104 | HIGH | 8.8 | 0.4% | Jun 18, 2026 | The U.S. Government Accountability Office (GAO) Electronic Protest Docketing System (EPDS) and Civilian Board of Contrac... |
| CVE-2026-48617 | HIGH | 8.2 | 0.2% | Jun 18, 2026 | A flaw in Node.js Permission Model enforcement allows Bypass via `process.report.writeReport()` Path Misvalidation. This... |
| CVE-2026-38718 | HIGH | 7.5 | 0.3% | Jun 18, 2026 | InHand Networks IR912 V1.0.0.r20042 and IR915 V1.0.0.r20042 (including earlier versions) were discovered to contain a bu... |
| CVE-2026-46580 | HIGH | 8.8 | 0.3% | Jun 18, 2026 | In Eclipse Theia versions prior to 1.71.0, files matching the pattern .prompts/*.prompttemplate in a workspace were auto... |
| CVE-2026-44691 | HIGH | 8.8 | 0.2% | Jun 18, 2026 | In Eclipse Theia versions prior to 1.69.0, custom task definitions in workspace files (e.g. .theia/tasks.json, .vscode/t... |
| CVE-2026-44688 | HIGH | 8.8 | 0.3% | Jun 18, 2026 | In Eclipse Theia versions prior to 1.71.0, the AI chat agent processed workspace file and directory names as part of its... |
| CVE-2026-8461 | HIGH | 8.8 | 0.5% | Jun 18, 2026 | An out-of-bounds write vulnerability in FFmpeg's libavcodec library, specifically in the MagicYUV decoder, allows denial... |
| CVE-2026-56012 | HIGH | 8.5 | 0.2% | Jun 18, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in David Lingren Medi... |
| CVE-2026-54224 | HIGH | 7.1 | 0.3% | Jun 18, 2026 | UBB.threads is vulnerable to Denial of Service (DoS). By sending multiple concurrent requests to view any user profile o... |
| CVE-2026-54223 | HIGH | 8.6 | 0.6% | Jun 18, 2026 | UBB.threads is vulnerable to Path traversal, allowing attackers with privilege to edit templates to read and write any f... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now