2026 CVE Vulnerabilities
56,900 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-47390 | MEDIUM | 5.5 | 0.2% | Jul 21, 2026 | PraisonAI is a multi-agent teams system. Prior to version 4.6.40 of PraisonAI, corresponding to version 1.6.40 of praiso... |
| CVE-2026-28321 | CRITICAL | 9.1 | 0.4% | Jul 21, 2026 | SolarWinds Serv-U is affected by a broken access control vulnerability that could allow arbitrary file read and write, w... |
| CVE-2026-28317 | CRITICAL | 9.1 | 0.3% | Jul 21, 2026 | SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to privilege esc... |
| CVE-2026-28316 | CRITICAL | 9.1 | 1.3% | Jul 21, 2026 | SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to privilege esc... |
| CVE-2026-28315 | MEDIUM | 6.2 | 0.3% | Jul 21, 2026 | SolarWinds Serv-U was found to be affected by a stored cross-site scripting vulnerability that could lead to session hij... |
| CVE-2026-28314 | CRITICAL | 9.1 | 0.4% | Jul 21, 2026 | SolarWinds Serv-U is affected by an insecure direct object reference vulnerability that leads to an account takeover. Us... |
| CVE-2026-28313 | CRITICAL | 9.1 | 0.3% | Jul 21, 2026 | SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to SMTP hijackin... |
| CVE-2026-28312 | CRITICAL | 9.1 | 0.4% | Jul 21, 2026 | SolarWinds Serv-U is affected by a privilege escalation vulnerability. This would elevate a group’s access to system adm... |
| CVE-2026-28310 | CRITICAL | 9.1 | 0.3% | Jul 21, 2026 | SolarWinds Serv-U is affected by a privilege escalation vulnerability that allows a domain administrator to escalate the... |
| CVE-2026-28309 | CRITICAL | 9.1 | 0.3% | Jul 21, 2026 | SolarWinds Serv-U is affected by a broken access control vulnerability that allows a domain administrator to create syst... |
| CVE-2026-28308 | CRITICAL | 9.1 | 0.5% | Jul 21, 2026 | SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to remote code e... |
| CVE-2026-28307 | CRITICAL | 9.1 | 0.3% | Jul 21, 2026 | SolarWinds Serv-U is affected by a privilege escalation vulnerability that allows a domain user group to be elevated int... |
| CVE-2026-28306 | CRITICAL | 9.1 | 0.3% | Jul 21, 2026 | SolarWinds Serv-U is affected by a privilege escalation vulnerability that allows a domain administrator to elevate thei... |
| CVE-2026-28305 | CRITICAL | 9.1 | 0.5% | Jul 21, 2026 | SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to remote code e... |
| CVE-2026-28304 | CRITICAL | 9.1 | 0.5% | Jul 21, 2026 | SolarWinds Serv-U is affected by a remote code execution vulnerability that, when exploited, can allow the arbitrary exe... |
| CVE-2026-28302 | CRITICAL | 9.1 | 0.6% | Jul 21, 2026 | SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to privilege esc... |
| CVE-2026-16450 | MEDIUM | 4.3 | 0.4% | Jul 21, 2026 | A vulnerability was identified in zsadmin2025 ZS-Admin up to b52e14536d59fda11e56e2536a1c32e82a38cead. This affects the ... |
| CVE-2026-16449 | MEDIUM | 6.3 | 0.3% | Jul 21, 2026 | A vulnerability was determined in zsadmin2025 ZS-Admin up to b52e14536d59fda11e56e2536a1c32e82a38cead. The impacted elem... |
| CVE-2026-8933 | HIGH | 7.8 | — | Jul 21, 2026 | A local privilege escalation vulnerability exists in snap-confine, a set-capabilities core component used internally by ... |
| CVE-2026-65052 | HIGH | 8.7 | 0.3% | Jul 21, 2026 | Ninja Forms WordPress plugin version 3.14.8 and prior contains an improper input validation vulnerability that allows un... |
| CVE-2026-65051 | MEDIUM | 6.9 | 0.3% | Jul 21, 2026 | Ninja Forms WordPress plugin version 3.14.8 contains a client-side enforcement of server-side security vulnerability tha... |
| CVE-2026-65050 | HIGH | 7.1 | 0.3% | Jul 21, 2026 | Ninja Forms WordPress plugin version 3.14.8 and prior contains a missing authorization vulnerability in the render callb... |
| CVE-2026-65049 | CRITICAL | 9.3 | — | Jul 21, 2026 | Ninja Forms plugin version 3.14.8 and prior for WordPress Multisite contains an incorrect authorization vulnerability th... |
| CVE-2026-65048 | CRITICAL | 9.3 | — | Jul 21, 2026 | Ninja Forms plugin for WordPress versions 3.10.4 through 3.14.9 contains an unauthenticated stored cross-site scripting ... |
| CVE-2026-59851 | HIGH | 8.8 | 0.3% | Jul 21, 2026 | A flaw was found in libssh. On servers with GSSAPIKeyExchange enabled, the gssapi-keyex path does not verify whether the... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now