2026 CVE Vulnerabilities
43,862 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-47730 | MEDIUM | 5.4 | 0.2% | Jul 14, 2026 | Twig is a template language for PHP. From 3.0.0 until 3.26.0, Twig\Profiler\Dumper\HtmlDumper writes Profile::getTemplat... |
| CVE-2026-46639 | MEDIUM | 6.5 | 0.4% | Jul 14, 2026 | Twig is a template language for PHP. From 3.24.0 until 3.26.0, object-destructuring assignment compiles CoreExtension::g... |
| CVE-2026-46637 | MEDIUM | 5.4 | 0.2% | Jul 14, 2026 | Twig is a template language for PHP. Prior to 3.26.0, several filters in twig/markdown-extra and twig/cssinliner-extra a... |
| CVE-2026-46635 | MEDIUM | 4.3 | 0.4% | Jul 14, 2026 | Twig is a template language for PHP. Prior to 3.26.0, the column filter passes object arrays to PHP array_column(), whic... |
| CVE-2026-46629 | MEDIUM | 6.5 | 0.3% | Jul 14, 2026 | Twig is a template language for PHP. Prior to 3.26.0, twig/intl-extra memoises IntlDateFormatter and NumberFormatter ins... |
| CVE-2026-46628 | MEDIUM | 5.4 | 0.3% | Jul 14, 2026 | Twig is a template language for PHP. Prior to 3.26.0, the deprecated spaceless filter is registered as safe for HTML, ca... |
| CVE-2026-46627 | MEDIUM | 6.5 | 0.4% | Jul 14, 2026 | Twig is a template language for PHP. Prior to 3.26.0, the Twig sandbox does not prevent a template from consuming CPU, m... |
| CVE-2026-42447 | MEDIUM | 5 | 0.1% | Jul 14, 2026 | jadx is a Dex to Java decompiler. Prior to 1.5.6, jadx-gui is affected by an HTML injection vulnerability in the Summary... |
| CVE-2026-15750 | MEDIUM | 6.3 | — | Jul 14, 2026 | A weakness has been identified in mastergo-design mastergo-magic-mcp up to 0.2.0. Impacted is the function z.string of t... |
| CVE-2026-59889 | MEDIUM | 6.5 | 0.4% | Jul 14, 2026 | jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From... |
| CVE-2026-49978 | MEDIUM | 6.1 | 0.5% | Jul 14, 2026 | DOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathML, and SVG. Prior to 3.4.7, DOMPurify IN_PLACE san... |
| CVE-2026-49854 | MEDIUM | 5.3 | 0.4% | Jul 14, 2026 | Tornado is a Python web framework and asynchronous networking library. Prior to 6.5.6, the optional native extension tor... |
| CVE-2026-49459 | MEDIUM | 6.1 | 0.3% | Jul 14, 2026 | DOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathML, and SVG. Prior to 3.4.6, DOMPurify.sanitize(roo... |
| CVE-2026-49458 | MEDIUM | 6.1 | 0.3% | Jul 14, 2026 | DOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathML, and SVG. Prior to 3.4.6, DOMPurify.sanitize(nod... |
| CVE-2026-48816 | MEDIUM | 6.5 | 0.2% | Jul 14, 2026 | sigstore-js provides JavaScript libraries for interacting with Sigstore services. Prior to 3.1.1, @sigstore/verify deriv... |
| CVE-2026-48758 | MEDIUM | 5.4 | 0.3% | Jul 14, 2026 | sigstore-js provides JavaScript libraries for interacting with Sigstore services. Prior to 3.2.1, the preAuthEncoding fu... |
| CVE-2026-48338 | MEDIUM | 6.8 | 0.3% | Jul 14, 2026 | ColdFusion is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerabilit... |
| CVE-2026-48308 | MEDIUM | 5.9 | 0.2% | Jul 14, 2026 | Premiere Pro is affected by an Improper Input Validation vulnerability that could result in a Security feature bypass. A... |
| CVE-2026-48125 | MEDIUM | 5.3 | 0.4% | Jul 14, 2026 | UAParser.js is a JavaScript library to detect browsers, operating systems, CPUs, and devices from user-agent data. From ... |
| CVE-2026-47979 | MEDIUM | 5.5 | 0.2% | Jul 14, 2026 | Media Encoder is affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An a... |
| CVE-2026-47475 | MEDIUM | 6.2 | 0.1% | Jul 14, 2026 | NVIDIA TensorRT-LLM contains a vulnerability in the OpenAI-compatible inference API where an attacker could trigger a re... |
| CVE-2026-47470 | MEDIUM | 6.2 | 0.1% | Jul 14, 2026 | NVIDIA TensorRT-LLM for any platform contains a vulnerability in the gRPC server chat API endpoint, where an attacker co... |
| CVE-2026-46644 | MEDIUM | 6.9 | 0.4% | Jul 14, 2026 | Symfony Polyfill backports PHP features and provides compatibility layers for extensions and functions. From 1.17.1 unti... |
| CVE-2026-24271 | MEDIUM | 6.2 | 0.1% | Jul 14, 2026 | NVIDIA TensorRT-LLM contains a vulnerability in the OpenAI-compatible inference API, where an attacker could cause alloc... |
| CVE-2026-24259 | MEDIUM | 6.4 | 0.1% | Jul 14, 2026 | NVIDIA TensorRT-LLM for Linux contains a vulnerability where an attacker could cause missing authentication for a critic... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now