2026 CVE Vulnerabilities

43,862 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-47730MEDIUM5.4Twig is a template language for PHP. From 3.0.0 until 3.26.0, Twig\Profiler\Dumper\HtmlDumper writes Profile::getTemplat...
CVE-2026-46639MEDIUM6.5Twig is a template language for PHP. From 3.24.0 until 3.26.0, object-destructuring assignment compiles CoreExtension::g...
CVE-2026-46637MEDIUM5.4Twig is a template language for PHP. Prior to 3.26.0, several filters in twig/markdown-extra and twig/cssinliner-extra a...
CVE-2026-46635MEDIUM4.3Twig is a template language for PHP. Prior to 3.26.0, the column filter passes object arrays to PHP array_column(), whic...
CVE-2026-46629MEDIUM6.5Twig is a template language for PHP. Prior to 3.26.0, twig/intl-extra memoises IntlDateFormatter and NumberFormatter ins...
CVE-2026-46628MEDIUM5.4Twig is a template language for PHP. Prior to 3.26.0, the deprecated spaceless filter is registered as safe for HTML, ca...
CVE-2026-46627MEDIUM6.5Twig is a template language for PHP. Prior to 3.26.0, the Twig sandbox does not prevent a template from consuming CPU, m...
CVE-2026-42447MEDIUM5jadx is a Dex to Java decompiler. Prior to 1.5.6, jadx-gui is affected by an HTML injection vulnerability in the Summary...
CVE-2026-15750MEDIUM6.3A weakness has been identified in mastergo-design mastergo-magic-mcp up to 0.2.0. Impacted is the function z.string of t...
CVE-2026-59889MEDIUM6.5jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From...
CVE-2026-49978MEDIUM6.1DOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathML, and SVG. Prior to 3.4.7, DOMPurify IN_PLACE san...
CVE-2026-49854MEDIUM5.3Tornado is a Python web framework and asynchronous networking library. Prior to 6.5.6, the optional native extension tor...
CVE-2026-49459MEDIUM6.1DOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathML, and SVG. Prior to 3.4.6, DOMPurify.sanitize(roo...
CVE-2026-49458MEDIUM6.1DOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathML, and SVG. Prior to 3.4.6, DOMPurify.sanitize(nod...
CVE-2026-48816MEDIUM6.5sigstore-js provides JavaScript libraries for interacting with Sigstore services. Prior to 3.1.1, @sigstore/verify deriv...
CVE-2026-48758MEDIUM5.4sigstore-js provides JavaScript libraries for interacting with Sigstore services. Prior to 3.2.1, the preAuthEncoding fu...
CVE-2026-48338MEDIUM6.8ColdFusion is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerabilit...
CVE-2026-48308MEDIUM5.9Premiere Pro is affected by an Improper Input Validation vulnerability that could result in a Security feature bypass. A...
CVE-2026-48125MEDIUM5.3UAParser.js is a JavaScript library to detect browsers, operating systems, CPUs, and devices from user-agent data. From ...
CVE-2026-47979MEDIUM5.5Media Encoder is affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An a...
CVE-2026-47475MEDIUM6.2NVIDIA TensorRT-LLM contains a vulnerability in the OpenAI-compatible inference API where an attacker could trigger a re...
CVE-2026-47470MEDIUM6.2NVIDIA TensorRT-LLM for any platform contains a vulnerability in the gRPC server chat API endpoint, where an attacker co...
CVE-2026-46644MEDIUM6.9Symfony Polyfill backports PHP features and provides compatibility layers for extensions and functions. From 1.17.1 unti...
CVE-2026-24271MEDIUM6.2NVIDIA TensorRT-LLM contains a vulnerability in the OpenAI-compatible inference API, where an attacker could cause alloc...
CVE-2026-24259MEDIUM6.4NVIDIA TensorRT-LLM for Linux contains a vulnerability where an attacker could cause missing authentication for a critic...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now