2026 CVE Vulnerabilities
56,900 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-47398 | HIGH | 8.1 | — | Jul 21, 2026 | PraisonAI is a multi-agent teams system. The v4.6.32 chokepoint refactor (which patched CVE-2026-44334 / GHSA-xcmw-grxf-... |
| CVE-2026-47397 | HIGH | 7.1 | 0.4% | Jul 21, 2026 | PraisonAI is a multi-agent teams system. Prior to version 4.6.40, hidden metadata in a webpage causes PraisonAI agents t... |
| CVE-2026-44907 | HIGH | 7.5 | — | Jul 21, 2026 | A denial of service vulnerability could be triggered by sending specially crafted HTTP requests to server function endpo... |
| CVE-2026-24232 | MEDIUM | 4.3 | — | Jul 21, 2026 | NVIDIA Tranformers4Rec contains a vulnerability where an attacker could cause improper deserialization of untrusted data... |
| CVE-2026-16454 | MEDIUM | 4.3 | 0.2% | Jul 21, 2026 | In Eclipse hawkBit versions 1.0.3 and prior, a privilege escalation vulnerability (CWE-284 / CWE-862) has been identifie... |
| CVE-2026-16451 | MEDIUM | 6.3 | 0.3% | Jul 21, 2026 | A security flaw has been discovered in zsadmin2025 ZS-Admin up to b52e14536d59fda11e56e2536a1c32e82a38cead. This impacts... |
| CVE-2026-15829 | HIGH | 8.6 | — | Jul 21, 2026 | A SQL injection (CWE-89) and security boundary bypass (CWE-863) vulnerability exists in the prebuilt BigQuery forecastin... |
| CVE-2026-15793 | HIGH | 7.5 | 0.2% | Jul 21, 2026 | BuildKit custom frontends or clients using the raw low-level API can set git.checkoutbundle=true when checking out Git s... |
| CVE-2026-15792 | HIGH | 7.5 | 0.2% | Jul 21, 2026 | A malicious BuildKit client or frontend could craft a request that could lead to BuildKit daemon crashing with a panic. |
| CVE-2026-15791 | HIGH | 7.5 | 0.1% | Jul 21, 2026 | A crafted message in the BuildKit low-level build API can be used to remove the contents of the /tmp directory. The acti... |
| CVE-2026-15789 | HIGH | 7.5 | 0.2% | Jul 21, 2026 | A custom client can produce such an upload request to the BuildKit daemon that files can escape from the BuildKit-contro... |
| CVE-2026-15724 | HIGH | 8.7 | 0.5% | Jul 21, 2026 | In Progress ShareFile Storage Zones Controller versions prior to 5.12.5 and 6.0.2, an authenticated administrative user ... |
| CVE-2026-15432 | HIGH | 8.2 | — | Jul 21, 2026 | When verifying a mac with a ChunkedMacVerification object, Tink compares the resulting tag with non constant time compar... |
| CVE-2026-15342 | MEDIUM | 6.5 | 0.2% | Jul 21, 2026 | Plane contains a multi‑tenant authorization flaw in its asset‑management API that allows authenticated users from one wo... |
| CVE-2026-64825 | CRITICAL | 9.3 | — | Jul 21, 2026 | Home Assistant Core before 2026.6.0 contains a path traversal vulnerability that allows unauthenticated attackers to wri... |
| CVE-2026-64824 | CRITICAL | 9.3 | — | Jul 21, 2026 | Home Assistant Core before 2026.7.0 contains a path traversal vulnerability in the backup-restore function that allows a... |
| CVE-2026-64823 | MEDIUM | 4.7 | 0.2% | Jul 21, 2026 | Home Assistant Core before 2026.5.4 contains a cross-site scripting vulnerability in the Shelly integration's async_get_... |
| CVE-2026-56586 | MEDIUM | 4.2 | 0.1% | Jul 21, 2026 | HCL IEM was affected with X-Content-Type-Options Header Missing. It may enable attackers to perform SSL stripping or man... |
| CVE-2026-56585 | MEDIUM | 4.3 | 0.1% | Jul 21, 2026 | HCL IEM was affected with the Anti Clickjacking XFrame Options Header Missing. It may allow attackers to embed the appli... |
| CVE-2026-47396 | CRITICAL | 9.8 | 0.3% | Jul 21, 2026 | PraisonAI is a multi-agent teams system. Prior to version 4.6.40, PraisonAI's call server exposes a network-facing agent... |
| CVE-2026-47395 | MEDIUM | 5.5 | — | Jul 21, 2026 | PraisonAI is a multi-agent teams system. Prior to version 4.6.40 of PraisonAI, corresponding to version 1.6.40 of praiso... |
| CVE-2026-47394 | HIGH | 8.7 | — | Jul 21, 2026 | PraisonAI is a multi-agent teams system. Prior to version 4.6.40, the fix for GHSA-9mqq-jqxf-grvw / CVE-2026-44336 is in... |
| CVE-2026-47393 | CRITICAL | 9.8 | 0.4% | Jul 21, 2026 | PraisonAI is a multi-agent teams system. CVE-2026-44338 (GHSA-6rmh-7xcm-cpxj) documents that PraisonAI ships a code-gene... |
| CVE-2026-47392 | CRITICAL | 9.9 | — | Jul 21, 2026 | PraisonAI is a multi-agent teams system. Prior to version 4.6.40 of PraisonAI, corresponding to version 1.6.40 of praiso... |
| CVE-2026-47391 | CRITICAL | 9.8 | 0.8% | Jul 21, 2026 | PraisonAI is a multi-agent teams system. Prior to version 4.6.40, PraisonAI's first-party A2A server example exposes an ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now