2026 CVE Vulnerabilities

56,900 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-47390MEDIUM5.5PraisonAI is a multi-agent teams system. Prior to version 4.6.40 of PraisonAI, corresponding to version 1.6.40 of praiso...
CVE-2026-28321CRITICAL9.1SolarWinds Serv-U is affected by a broken access control vulnerability that could allow arbitrary file read and write, w...
CVE-2026-28317CRITICAL9.1SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to privilege esc...
CVE-2026-28316CRITICAL9.1SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to privilege esc...
CVE-2026-28315MEDIUM6.2SolarWinds Serv-U was found to be affected by a stored cross-site scripting vulnerability that could lead to session hij...
CVE-2026-28314CRITICAL9.1SolarWinds Serv-U is affected by an insecure direct object reference vulnerability that leads to an account takeover. Us...
CVE-2026-28313CRITICAL9.1SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to SMTP hijackin...
CVE-2026-28312CRITICAL9.1SolarWinds Serv-U is affected by a privilege escalation vulnerability. This would elevate a group’s access to system adm...
CVE-2026-28310CRITICAL9.1SolarWinds Serv-U is affected by a privilege escalation vulnerability that allows a domain administrator to escalate the...
CVE-2026-28309CRITICAL9.1SolarWinds Serv-U is affected by a broken access control vulnerability that allows a domain administrator to create syst...
CVE-2026-28308CRITICAL9.1SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to remote code e...
CVE-2026-28307CRITICAL9.1SolarWinds Serv-U is affected by a privilege escalation vulnerability that allows a domain user group to be elevated int...
CVE-2026-28306CRITICAL9.1SolarWinds Serv-U is affected by a privilege escalation vulnerability that allows a domain administrator to elevate thei...
CVE-2026-28305CRITICAL9.1SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to remote code e...
CVE-2026-28304CRITICAL9.1SolarWinds Serv-U is affected by a remote code execution vulnerability that, when exploited, can allow the arbitrary exe...
CVE-2026-28302CRITICAL9.1SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to privilege esc...
CVE-2026-16450MEDIUM4.3A vulnerability was identified in zsadmin2025 ZS-Admin up to b52e14536d59fda11e56e2536a1c32e82a38cead. This affects the ...
CVE-2026-16449MEDIUM6.3A vulnerability was determined in zsadmin2025 ZS-Admin up to b52e14536d59fda11e56e2536a1c32e82a38cead. The impacted elem...
CVE-2026-8933HIGH7.8A local privilege escalation vulnerability exists in snap-confine, a set-capabilities core component used internally by ...
CVE-2026-65052HIGH8.7Ninja Forms WordPress plugin version 3.14.8 and prior contains an improper input validation vulnerability that allows un...
CVE-2026-65051MEDIUM6.9Ninja Forms WordPress plugin version 3.14.8 contains a client-side enforcement of server-side security vulnerability tha...
CVE-2026-65050HIGH7.1Ninja Forms WordPress plugin version 3.14.8 and prior contains a missing authorization vulnerability in the render callb...
CVE-2026-65049CRITICAL9.3Ninja Forms plugin version 3.14.8 and prior for WordPress Multisite contains an incorrect authorization vulnerability th...
CVE-2026-65048CRITICAL9.3Ninja Forms plugin for WordPress versions 3.10.4 through 3.14.9 contains an unauthenticated stored cross-site scripting ...
CVE-2026-59851HIGH8.8A flaw was found in libssh. On servers with GSSAPIKeyExchange enabled, the gssapi-keyex path does not verify whether the...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now