2026 CVE Vulnerabilities

43,273 CVEs published in 2026.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2026-64878CRITICAL9.9Unvalidated input in asset filter parameters allows shell metacharacters to escape command argument handling, resulting ...
CVE-2026-59147CRITICAL9.8Data::DisjointSet::Shared versions before 0.02 for Perl allow out-of-bounds reads and writes via an unvalidated parent i...
CVE-2026-59145CRITICAL9.1Data::Intern::Shared versions before 0.02 for Perl allow an out-of-bounds read via unvalidated slot, reverse and arena i...
CVE-2026-59144CRITICAL9.8Data::RingBuffer::Shared versions before 0.04 for Perl allow a stack buffer overflow via an unvalidated elem_size in rin...
CVE-2026-50755CRITICAL9.8An issue in DayuanJiang next-ai-draw-io 0.4.13 allows a remote attacker to obtain sensitive information via the X-Forwar...
CVE-2026-64877CRITICAL9.4An authenticated non-admin user can exploit a SQL injection flaw in the ticketing REST API to access sensitive data stor...
CVE-2026-59142CRITICAL9.1Data::HashMap::Shared versions before 0.14 for Perl allow an out-of-bounds read via an unvalidated arena offset and leng...
CVE-2026-59141CRITICAL9.1Data::RadixTree::Shared versions before 0.02 for Perl allow an out-of-bounds read via unvalidated node and arena indices...
CVE-2026-59140CRITICAL9.1Data::SortedSet::Shared versions before 0.03 for Perl allow an out-of-bounds read via unvalidated node indices in the ra...
CVE-2026-59139CRITICAL9.1Data::ReqRep::Shared versions before 0.05 for Perl allow an out-of-bounds read via an unvalidated arena offset and lengt...
CVE-2026-47416CRITICAL9.6PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 are vulnera...
CVE-2026-47413CRITICAL9.6PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have aprivi...
CVE-2026-16439CRITICAL9.1In Eclipse OpenJ9 versions up to 0.60, using -Xtrace to trace method arguments can lead to buffer underflow.
CVE-2026-47410CRITICAL9.8PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have an ins...
CVE-2026-47407CRITICAL9.4PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Prior to version 0.1.4, the Platfor...
CVE-2026-64825CRITICAL9.3Home Assistant Core before 2026.6.0 contains a path traversal vulnerability that allows unauthenticated attackers to wri...
CVE-2026-64824CRITICAL9.3Home Assistant Core before 2026.7.0 contains a path traversal vulnerability in the backup-restore function that allows a...
CVE-2026-47396CRITICAL9.8PraisonAI is a multi-agent teams system. Prior to version 4.6.40, PraisonAI's call server exposes a network-facing agent...
CVE-2026-47393CRITICAL9.8PraisonAI is a multi-agent teams system. CVE-2026-44338 (GHSA-6rmh-7xcm-cpxj) documents that PraisonAI ships a code-gene...
CVE-2026-47392CRITICAL9.9PraisonAI is a multi-agent teams system. Prior to version 4.6.40 of PraisonAI, corresponding to version 1.6.40 of praiso...
CVE-2026-47391CRITICAL9.8PraisonAI is a multi-agent teams system. Prior to version 4.6.40, PraisonAI's first-party A2A server example exposes an ...
CVE-2026-28321CRITICAL9.1SolarWinds Serv-U is affected by a broken access control vulnerability that could allow arbitrary file read and write, w...
CVE-2026-28317CRITICAL9.1SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to privilege esc...
CVE-2026-28316CRITICAL9.1SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to privilege esc...
CVE-2026-28314CRITICAL9.1SolarWinds Serv-U is affected by an insecure direct object reference vulnerability that leads to an account takeover. Us...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now