2026 CVE Vulnerabilities

49,722 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-70616HIGH7.1boringproxy through 0.10.0 contains a resource exhaustion vulnerability that allows any authenticated user to permanentl...
CVE-2026-70615CRITICAL9.9boringproxy through 0.10.0 contains a newline injection vulnerability that allows authenticated low-privileged users wit...
CVE-2026-69111HIGH8.7Milvus through 2.6.22 and 3.0.0 contains an unauthenticated denial of service vulnerability that allows remote attackers...
CVE-2026-68746HIGH8.8Not Failing Securely ('Failing Open') vulnerability in livebook-dev livebook allows an unauthenticated network client to...
CVE-2026-66885MEDIUM6.5Cross-Site Request Forgery (CSRF) vulnerability in livebook-dev livebook allows an attacker to authenticate a victim's b...
CVE-2026-66881HIGH8.1Relative Path Traversal vulnerability in livebook-dev livebook allows an attacker-authored notebook to write a file with...
CVE-2026-66298HIGH8.8Origin Validation Error vulnerability in livebook-dev livebook allows untrusted notebook output JavaScript to trigger se...
CVE-2026-66297HIGH8Improper Neutralization of Special Elements used in an OS Command (OS Command Injection) vulnerability in livebook-dev l...
CVE-2026-55524HIGH7.5PraisonAI is a multi-agent teams system. In versions prior to 1.6.58, the web_crawl tool performs its SSRF check only on...
CVE-2026-55523HIGH7.7PraisonAI is a multi-agent teams system. In versions 1.5.128 through 1.6.57, the praisonaiagents.tools.web_crawl_tools.w...
CVE-2026-55522HIGH7.8PraisonAI is a multi-agent teams system. In versions 3.9.26 through 4.6.57 of praiseonai and 0.12.12 through 1.6.57 of p...
CVE-2026-21766MEDIUM5.4The default login portlet in HCL Digital Experience and Digital Experience Compose insufficiently protects credentials. ...
CVE-2026-18958HIGH7.3A vulnerability was detected in imranrisal-dev Student-Management-System 18ea7904c339e0c7b0234724a79c939ce6191def/a8d43a...
CVE-2026-18954MEDIUM5.7Incorrect authorization in the aggregation pipeline tool in Amazon AWS Labs DocumentDB MCP Server before 1.0.12 might al...
CVE-2026-18953HIGH8.8Improper limitation of a pathname to a restricted directory in the get_resource tool in Amazon awslabs.aws-transform-mcp...
CVE-2026-17556CRITICAL9.1A path traversal vulnerability was identified in GitHub Enterprise Server that allowed an unauthenticated attacker to de...
CVE-2026-9205CRITICAL9.8IBM Langflow OSS contains a weak cryptographic key derivation vulnerability in the ensure_fernet_key() function.
CVE-2026-9201HIGH8.8IBM Langflow OSS 1.0.0 through 1.10.3 could allow an authenticated attacker to execute arbitrary code due to a cryptogra...
CVE-2026-9196HIGH8.8IBM Langflow OSS 1.0.0 through 1.10.3 could allow an authenticated attacker to execute unintended code during Agentic As...
CVE-2026-9130HIGH7.1IBM Langflow OSS 1.0.0 through 1.10.3 contain an authorization bypass vulnerability in the MemoryComponent that allows a...
CVE-2026-8478HIGH8.8IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote attacker to inject arbitrary code on the system, due to the i...
CVE-2026-8470CRITICAL9.1IBM Langflow OSS 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, and 1.0.0 through 1.10.3 use Python's...
CVE-2026-8183HIGH7.7IBM Langflow OSS 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1...
CVE-2026-8182HIGH8.8IBM Langflow OSS 1.0.0 through 1.10.3 installations allow anyone on the internet to execute arbitrary code on the server...
CVE-2026-7869MEDIUM5.4IBM Langflow OSS 1.0.0 through 1.10.3 is vulnerable to Path Traversal in the Knowledge Bases API (`POST /api/v1/knowledg...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now