2026 CVE Vulnerabilities

43,869 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-48255MEDIUM5.4Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit ...
CVE-2026-48254MEDIUM5.4Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit ...
CVE-2026-48253MEDIUM5.4Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit ...
CVE-2026-48038MEDIUM5.3joi is a schema description language and data validator for JavaScript. Prior to 17.13.4 and 18.2.1, denial of service i...
CVE-2026-48000MEDIUM6.1Adobe Commerce is affected by an Improper Redirect (Open Redirect) vulnerability that could result in a Security feature...
CVE-2026-47999MEDIUM4.8Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a high-privilege...
CVE-2026-47998MEDIUM5.9Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. A...
CVE-2026-47997MEDIUM5.9Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. A...
CVE-2026-47996MEDIUM6.8Adobe Commerce is affected by an Incorrect Authorization vulnerability that could lead to arbitrary file system read. A ...
CVE-2026-47481MEDIUM6.5NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause an authentication bypass t...
CVE-2026-47429MEDIUM5.9Vitest is a testing framework powered by Vite. Prior to 3.2.5 and 4.1.0, the Vitest UI/API server on Windows used isFile...
CVE-2026-47212MEDIUM5.3Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 6.4.40, 7.4.1...
CVE-2026-15714MEDIUM6.5An out-of-bounds read vulnerability was found in libsoup's multipart processing subsystem. The flaw exists in the soup_m...
CVE-2026-15713MEDIUM5.9A vulnerability was found in libsoup's HTTP/2 protocol implementation. The library fails to correctly release memory con...
CVE-2026-5040MEDIUM6.7TP-Link Deco M5 v1 uses a weak password hashing mechanism to store user credentials. An attacker who obtains the passwo...
CVE-2026-45755MEDIUM5.3Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 7.4.12 and 8....
CVE-2026-45754MEDIUM5.3Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 6.4.40, 7.4.1...
CVE-2026-45753MEDIUM6.1Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 6.1.0-BETA1 until...
CVE-2026-45072MEDIUM5.4Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 6.4.24 until 6.4....
CVE-2026-45070MEDIUM6.5Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.4...
CVE-2026-45064MEDIUM6.1Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 6.1.0-BETA1 until...
CVE-2026-15712MEDIUM5.9A heap buffer over-read vulnerability was discovered in libsoup's (versions: libsoup 3.0 to 3.7.0) HTTP/2 connection tra...
CVE-2026-62659MEDIUM4.3A security flaw was discovered in the NETGEAR WAX333 Access Point that could allow someone already logged in and connect...
CVE-2026-62658MEDIUM4.7A security flaw was discovered in certain NETGEAR Nighthawk RAX series routers that could allow someone already logged i...
CVE-2026-62657MEDIUM4.9A security flaw in the router's certificate validation process was discovered in the NETGEAR XR1000 Gaming Router and ce...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now