2026 CVE Vulnerabilities
43,273 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-64878 | CRITICAL | 9.9 | 0.5% | Jul 21, 2026 | Unvalidated input in asset filter parameters allows shell metacharacters to escape command argument handling, resulting ... |
| CVE-2026-59147 | CRITICAL | 9.8 | 0.2% | Jul 21, 2026 | Data::DisjointSet::Shared versions before 0.02 for Perl allow out-of-bounds reads and writes via an unvalidated parent i... |
| CVE-2026-59145 | CRITICAL | 9.1 | 0.2% | Jul 21, 2026 | Data::Intern::Shared versions before 0.02 for Perl allow an out-of-bounds read via unvalidated slot, reverse and arena i... |
| CVE-2026-59144 | CRITICAL | 9.8 | 0.2% | Jul 21, 2026 | Data::RingBuffer::Shared versions before 0.04 for Perl allow a stack buffer overflow via an unvalidated elem_size in rin... |
| CVE-2026-50755 | CRITICAL | 9.8 | 0.2% | Jul 21, 2026 | An issue in DayuanJiang next-ai-draw-io 0.4.13 allows a remote attacker to obtain sensitive information via the X-Forwar... |
| CVE-2026-64877 | CRITICAL | 9.4 | 0.2% | Jul 21, 2026 | An authenticated non-admin user can exploit a SQL injection flaw in the ticketing REST API to access sensitive data stor... |
| CVE-2026-59142 | CRITICAL | 9.1 | 0.2% | Jul 21, 2026 | Data::HashMap::Shared versions before 0.14 for Perl allow an out-of-bounds read via an unvalidated arena offset and leng... |
| CVE-2026-59141 | CRITICAL | 9.1 | 0.2% | Jul 21, 2026 | Data::RadixTree::Shared versions before 0.02 for Perl allow an out-of-bounds read via unvalidated node and arena indices... |
| CVE-2026-59140 | CRITICAL | 9.1 | 0.2% | Jul 21, 2026 | Data::SortedSet::Shared versions before 0.03 for Perl allow an out-of-bounds read via unvalidated node indices in the ra... |
| CVE-2026-59139 | CRITICAL | 9.1 | 0.2% | Jul 21, 2026 | Data::ReqRep::Shared versions before 0.05 for Perl allow an out-of-bounds read via an unvalidated arena offset and lengt... |
| CVE-2026-47416 | CRITICAL | 9.6 | 0.2% | Jul 21, 2026 | PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 are vulnera... |
| CVE-2026-47413 | CRITICAL | 9.6 | 0.2% | Jul 21, 2026 | PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have aprivi... |
| CVE-2026-16439 | CRITICAL | 9.1 | 0.2% | Jul 21, 2026 | In Eclipse OpenJ9 versions up to 0.60, using -Xtrace to trace method arguments can lead to buffer underflow. |
| CVE-2026-47410 | CRITICAL | 9.8 | 0.3% | Jul 21, 2026 | PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have an ins... |
| CVE-2026-47407 | CRITICAL | 9.4 | 0.2% | Jul 21, 2026 | PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Prior to version 0.1.4, the Platfor... |
| CVE-2026-64825 | CRITICAL | 9.3 | — | Jul 21, 2026 | Home Assistant Core before 2026.6.0 contains a path traversal vulnerability that allows unauthenticated attackers to wri... |
| CVE-2026-64824 | CRITICAL | 9.3 | — | Jul 21, 2026 | Home Assistant Core before 2026.7.0 contains a path traversal vulnerability in the backup-restore function that allows a... |
| CVE-2026-47396 | CRITICAL | 9.8 | 0.3% | Jul 21, 2026 | PraisonAI is a multi-agent teams system. Prior to version 4.6.40, PraisonAI's call server exposes a network-facing agent... |
| CVE-2026-47393 | CRITICAL | 9.8 | 0.4% | Jul 21, 2026 | PraisonAI is a multi-agent teams system. CVE-2026-44338 (GHSA-6rmh-7xcm-cpxj) documents that PraisonAI ships a code-gene... |
| CVE-2026-47392 | CRITICAL | 9.9 | — | Jul 21, 2026 | PraisonAI is a multi-agent teams system. Prior to version 4.6.40 of PraisonAI, corresponding to version 1.6.40 of praiso... |
| CVE-2026-47391 | CRITICAL | 9.8 | 0.8% | Jul 21, 2026 | PraisonAI is a multi-agent teams system. Prior to version 4.6.40, PraisonAI's first-party A2A server example exposes an ... |
| CVE-2026-28321 | CRITICAL | 9.1 | 0.4% | Jul 21, 2026 | SolarWinds Serv-U is affected by a broken access control vulnerability that could allow arbitrary file read and write, w... |
| CVE-2026-28317 | CRITICAL | 9.1 | 0.3% | Jul 21, 2026 | SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to privilege esc... |
| CVE-2026-28316 | CRITICAL | 9.1 | 1.3% | Jul 21, 2026 | SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to privilege esc... |
| CVE-2026-28314 | CRITICAL | 9.1 | 0.4% | Jul 21, 2026 | SolarWinds Serv-U is affected by an insecure direct object reference vulnerability that leads to an account takeover. Us... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now