2026 CVE Vulnerabilities

53,146 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-39308HIGH7.1PraisonAI is a multi-agent teams system. Prior to 1.5.113, PraisonAI's recipe registry publish endpoint writes uploaded ...
CVE-2026-39307HIGH8.1PraisonAI is a multi-agent teams system. Prior to 1.5.113, The PraisonAI templates installation feature is vulnerable to...
CVE-2026-39306HIGH7.3PraisonAI is a multi-agent teams system. Prior to 1.5.113, PraisonAI's recipe registry pull flow extracts attacker-contr...
CVE-2026-35615HIGH7.5PraisonAI is a multi-agent teams system. Prior to 1.5.113, _validate_path() calls os.path.normpath() first, which collap...
CVE-2026-35611HIGH7.5Addressable is an alternative implementation to the URI implementation that is part of Ruby's standard library. From 2.3...
CVE-2026-35610HIGH8.8PolarLearn is a free and open-source learning program. In 0-PRERELEASE-14 and earlier, setCustomPassword(userId, passwor...
CVE-2026-35607HIGH8.8File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a spec...
CVE-2026-35606HIGH7.5File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a spec...
CVE-2026-35605HIGH7.5File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a spec...
CVE-2026-35604HIGH8.1File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a spec...
CVE-2026-35585HIGH7.2File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a spec...
CVE-2026-35581HIGH7.2Emissary is a P2P based data-driven workflow engine. Prior to 8.39.0, the Executrix utility class constructed shell comm...
CVE-2026-35574HIGH8.7ChurchCRM is an open-source church management system. Prior to 6.5.3, a stored Cross-Site Scripting (XSS) vulnerability ...
CVE-2026-35523HIGH7.5Strawberry GraphQL is a library for creating GraphQL APIs. Strawberry up until version 0.312.3 is vulnerable to an authe...
CVE-2026-27314HIGH8.8Privilege escalation in Apache Cassandra 5.0 on an mTLS environment using MutualTlsAuthenticator allows a user with only...
CVE-2026-22683HIGH8.8Windmill versions 1.56.0 through 1.614.0 contain a missing authorization vulnerability that allows users with the Operat...
CVE-2026-4931HIGH8.6Smart contract Marginal v1 performs unsafe downcast, allowing attackers to settle a large debt position for a negligible...
CVE-2026-35534HIGH7.6ChurchCRM is an open-source church management system. Prior to 7.1.0, a stored cross-site scripting vulnerability exists...
CVE-2026-35526HIGH7.5Strawberry GraphQL is a library for creating GraphQL APIs. Prior to 0.312.3, Strawberry GraphQL's WebSocket subscription...
CVE-2026-35521HIGH8.8FTLDNS (pihole-FTL) provides an interactive API and also generates statistics for Pi-hole's Web interface. From 6.0 to b...
CVE-2026-35520HIGH8.8FTLDNS (pihole-FTL) provides an interactive API and also generates statistics for Pi-hole's Web interface. From 6.0 to b...
CVE-2026-35519HIGH8.8FTLDNS (pihole-FTL) provides an interactive API and also generates statistics for Pi-hole's Web interface. From 6.0 to b...
CVE-2026-35518HIGH8.8FTLDNS (pihole-FTL) provides an interactive API and also generates statistics for Pi-hole's Web interface. From 6.0 to b...
CVE-2026-35517HIGH8.8FTLDNS (pihole-FTL) provides an interactive API and also generates statistics for Pi-hole's Web interface. From 6.0 to b...
CVE-2026-35489HIGH7.3Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. Prior to 2.6.4, the...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now