2026 CVE Vulnerabilities

43,277 CVEs published in 2026.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2026-15143CRITICAL9.3A flaw was found in the file_type content detector of guardrails-detectors. This vulnerability allows a remote attacker ...
CVE-2026-61444CRITICAL9.4PraisonAI versions before 4.6.78 contain a code injection vulnerability in deploy/api.py where the agents_file parameter...
CVE-2026-59792CRITICAL9.8In JetBrains IntelliJ IDEA before 2026.1.4, 2026.2 code execution via path traversal in project workspace ID handling w...
CVE-2026-56765CRITICAL9.8Vikunja before 2.2.1 contains an authorization flaw where the LinkSharing.ReadAll endpoint exposes share hashes to users...
CVE-2026-56688CRITICAL9.1Dell PowerFlex Manager, Version prior to 5.1.0.1, contain(s) an Improper Neutralization of Special Elements used in an O...
CVE-2026-53363CRITICAL9.8In the Linux kernel, the following vulnerability has been resolved: xfrm: iptfs: preserve shared-frag marker in iptfs_c...
CVE-2026-41880CRITICAL9R-SOFT DMS is vulnerable to OS Command Injection in the Optical Character Recognition (OCR) module. Multiple command exe...
CVE-2026-15378CRITICAL9.3A flaw was found in the `guardrails-detectors` component. This vulnerability allows a remote attacker to perform a blind...
CVE-2026-40008CRITICAL9.8Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability in Apache IoTDB. The pi...
CVE-2026-40005CRITICAL9.1Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache IoTDB. An attacke...
CVE-2026-28564CRITICAL9.8Insufficient Session Expiration, Authentication Bypass by Capture-replay vulnerability in Apache IoTDB. REST Basic Authe...
CVE-2026-15300CRITICAL9.1The GEO my WP plugin for WordPress was vulnerable to SQL Injection via the 'distance', 'lat', and 'lng' parameters in ve...
CVE-2026-15282CRITICAL9.8The Instant Appointment plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation...
CVE-2026-14894CRITICAL9.8The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Arbitrary File Upload in all versions u...
CVE-2026-55615CRITICAL9.2Langroid is a framework for building large-language-model-powered applications. Prior to version 0.65.5, Neo4jChatAgent ...
CVE-2026-54769CRITICAL10Langroid is a framework for building large-language-model-powered applications. Versions prior to 0.65.2 are vulnerable ...
CVE-2026-54760CRITICAL9.3Langroid is a framework for building large-language-model-powered applications. Prior to version 0.65.1, the `SQLChatAge...
CVE-2026-58123CRITICAL9.8Hermes WebUI before 0.51.788 contains an unauthenticated remote code execution vulnerability that allows remote attacker...
CVE-2026-58122CRITICAL9.3Hermes WebUI before 0.51.307 contains an authentication bypass vulnerability that allows unauthenticated remote attacker...
CVE-2026-53963CRITICAL9Discourse is an open-source discussion platform. Prior to 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5, a malicious second...
CVE-2026-54003CRITICAL9.1Kirby is an open-source content management system. Prior to 4.9.4 and from 5.4.4, Kirby sites with no configured user ac...
CVE-2026-0284CRITICAL9.9An XML injection vulnerability in the Large Scale VPN (LSVPN) functionality of Palo Alto Networks PAN-OS® software enabl...
CVE-2026-59826CRITICAL9.1Metabase is an open-source business intelligence and embedded analytics tool. From 1.55.0 until 1.58.15.1, 1.59.12, 1.60...
CVE-2026-59726CRITICAL10Ruflo is an agent meta-harness for Claude Code and Codex. Prior to 3.16.3, ruflo's default docker-compose deployment exp...
CVE-2026-59216CRITICAL9Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. Prior to 0.10.0, get_event_call de...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now