2026 CVE Vulnerabilities
53,146 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-39308 | HIGH | 7.1 | 0.3% | Apr 7, 2026 | PraisonAI is a multi-agent teams system. Prior to 1.5.113, PraisonAI's recipe registry publish endpoint writes uploaded ... |
| CVE-2026-39307 | HIGH | 8.1 | 0.3% | Apr 7, 2026 | PraisonAI is a multi-agent teams system. Prior to 1.5.113, The PraisonAI templates installation feature is vulnerable to... |
| CVE-2026-39306 | HIGH | 7.3 | 0.3% | Apr 7, 2026 | PraisonAI is a multi-agent teams system. Prior to 1.5.113, PraisonAI's recipe registry pull flow extracts attacker-contr... |
| CVE-2026-35615 | HIGH | 7.5 | 0.4% | Apr 7, 2026 | PraisonAI is a multi-agent teams system. Prior to 1.5.113, _validate_path() calls os.path.normpath() first, which collap... |
| CVE-2026-35611 | HIGH | 7.5 | 0.4% | Apr 7, 2026 | Addressable is an alternative implementation to the URI implementation that is part of Ruby's standard library. From 2.3... |
| CVE-2026-35610 | HIGH | 8.8 | 0.3% | Apr 7, 2026 | PolarLearn is a free and open-source learning program. In 0-PRERELEASE-14 and earlier, setCustomPassword(userId, passwor... |
| CVE-2026-35607 | HIGH | 8.8 | 0.4% | Apr 7, 2026 | File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a spec... |
| CVE-2026-35606 | HIGH | 7.5 | 0.3% | Apr 7, 2026 | File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a spec... |
| CVE-2026-35605 | HIGH | 7.5 | 0.4% | Apr 7, 2026 | File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a spec... |
| CVE-2026-35604 | HIGH | 8.1 | 0.3% | Apr 7, 2026 | File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a spec... |
| CVE-2026-35585 | HIGH | 7.2 | 1.9% | Apr 7, 2026 | File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a spec... |
| CVE-2026-35581 | HIGH | 7.2 | 0.6% | Apr 7, 2026 | Emissary is a P2P based data-driven workflow engine. Prior to 8.39.0, the Executrix utility class constructed shell comm... |
| CVE-2026-35574 | HIGH | 8.7 | 0.3% | Apr 7, 2026 | ChurchCRM is an open-source church management system. Prior to 6.5.3, a stored Cross-Site Scripting (XSS) vulnerability ... |
| CVE-2026-35523 | HIGH | 7.5 | 0.4% | Apr 7, 2026 | Strawberry GraphQL is a library for creating GraphQL APIs. Strawberry up until version 0.312.3 is vulnerable to an authe... |
| CVE-2026-27314 | HIGH | 8.8 | 0.3% | Apr 7, 2026 | Privilege escalation in Apache Cassandra 5.0 on an mTLS environment using MutualTlsAuthenticator allows a user with only... |
| CVE-2026-22683 | HIGH | 8.8 | 0.7% | Apr 7, 2026 | Windmill versions 1.56.0 through 1.614.0 contain a missing authorization vulnerability that allows users with the Operat... |
| CVE-2026-4931 | HIGH | 8.6 | 0.3% | Apr 7, 2026 | Smart contract Marginal v1 performs unsafe downcast, allowing attackers to settle a large debt position for a negligible... |
| CVE-2026-35534 | HIGH | 7.6 | 0.2% | Apr 7, 2026 | ChurchCRM is an open-source church management system. Prior to 7.1.0, a stored cross-site scripting vulnerability exists... |
| CVE-2026-35526 | HIGH | 7.5 | 0.3% | Apr 7, 2026 | Strawberry GraphQL is a library for creating GraphQL APIs. Prior to 0.312.3, Strawberry GraphQL's WebSocket subscription... |
| CVE-2026-35521 | HIGH | 8.8 | 0.7% | Apr 7, 2026 | FTLDNS (pihole-FTL) provides an interactive API and also generates statistics for Pi-hole's Web interface. From 6.0 to b... |
| CVE-2026-35520 | HIGH | 8.8 | 0.7% | Apr 7, 2026 | FTLDNS (pihole-FTL) provides an interactive API and also generates statistics for Pi-hole's Web interface. From 6.0 to b... |
| CVE-2026-35519 | HIGH | 8.8 | 0.5% | Apr 7, 2026 | FTLDNS (pihole-FTL) provides an interactive API and also generates statistics for Pi-hole's Web interface. From 6.0 to b... |
| CVE-2026-35518 | HIGH | 8.8 | 0.7% | Apr 7, 2026 | FTLDNS (pihole-FTL) provides an interactive API and also generates statistics for Pi-hole's Web interface. From 6.0 to b... |
| CVE-2026-35517 | HIGH | 8.8 | 0.9% | Apr 7, 2026 | FTLDNS (pihole-FTL) provides an interactive API and also generates statistics for Pi-hole's Web interface. From 6.0 to b... |
| CVE-2026-35489 | HIGH | 7.3 | 0.2% | Apr 7, 2026 | Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. Prior to 2.6.4, the... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now