2026 CVE Vulnerabilities
43,869 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-48255 | MEDIUM | 5.4 | 0.3% | Jul 14, 2026 | Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit ... |
| CVE-2026-48254 | MEDIUM | 5.4 | 0.3% | Jul 14, 2026 | Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit ... |
| CVE-2026-48253 | MEDIUM | 5.4 | 0.3% | Jul 14, 2026 | Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit ... |
| CVE-2026-48038 | MEDIUM | 5.3 | 0.3% | Jul 14, 2026 | joi is a schema description language and data validator for JavaScript. Prior to 17.13.4 and 18.2.1, denial of service i... |
| CVE-2026-48000 | MEDIUM | 6.1 | 0.4% | Jul 14, 2026 | Adobe Commerce is affected by an Improper Redirect (Open Redirect) vulnerability that could result in a Security feature... |
| CVE-2026-47999 | MEDIUM | 4.8 | 11.5% | Jul 14, 2026 | Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a high-privilege... |
| CVE-2026-47998 | MEDIUM | 5.9 | 0.6% | Jul 14, 2026 | Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. A... |
| CVE-2026-47997 | MEDIUM | 5.9 | 0.6% | Jul 14, 2026 | Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. A... |
| CVE-2026-47996 | MEDIUM | 6.8 | 19.9% | Jul 14, 2026 | Adobe Commerce is affected by an Incorrect Authorization vulnerability that could lead to arbitrary file system read. A ... |
| CVE-2026-47481 | MEDIUM | 6.5 | 0.3% | Jul 14, 2026 | NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause an authentication bypass t... |
| CVE-2026-47429 | MEDIUM | 5.9 | 1.0% | Jul 14, 2026 | Vitest is a testing framework powered by Vite. Prior to 3.2.5 and 4.1.0, the Vitest UI/API server on Windows used isFile... |
| CVE-2026-47212 | MEDIUM | 5.3 | 0.3% | Jul 14, 2026 | Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 6.4.40, 7.4.1... |
| CVE-2026-15714 | MEDIUM | 6.5 | 0.4% | Jul 14, 2026 | An out-of-bounds read vulnerability was found in libsoup's multipart processing subsystem. The flaw exists in the soup_m... |
| CVE-2026-15713 | MEDIUM | 5.9 | 0.3% | Jul 14, 2026 | A vulnerability was found in libsoup's HTTP/2 protocol implementation. The library fails to correctly release memory con... |
| CVE-2026-5040 | MEDIUM | 6.7 | 0.1% | Jul 14, 2026 | TP-Link Deco M5 v1 uses a weak password hashing mechanism to store user credentials. An attacker who obtains the passwo... |
| CVE-2026-45755 | MEDIUM | 5.3 | — | Jul 14, 2026 | Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 7.4.12 and 8.... |
| CVE-2026-45754 | MEDIUM | 5.3 | 0.3% | Jul 14, 2026 | Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 6.4.40, 7.4.1... |
| CVE-2026-45753 | MEDIUM | 6.1 | — | Jul 14, 2026 | Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 6.1.0-BETA1 until... |
| CVE-2026-45072 | MEDIUM | 5.4 | 0.4% | Jul 14, 2026 | Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 6.4.24 until 6.4.... |
| CVE-2026-45070 | MEDIUM | 6.5 | 0.3% | Jul 14, 2026 | Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.4... |
| CVE-2026-45064 | MEDIUM | 6.1 | 0.3% | Jul 14, 2026 | Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 6.1.0-BETA1 until... |
| CVE-2026-15712 | MEDIUM | 5.9 | 0.5% | Jul 14, 2026 | A heap buffer over-read vulnerability was discovered in libsoup's (versions: libsoup 3.0 to 3.7.0) HTTP/2 connection tra... |
| CVE-2026-62659 | MEDIUM | 4.3 | 0.2% | Jul 14, 2026 | A security flaw was discovered in the NETGEAR WAX333 Access Point that could allow someone already logged in and connect... |
| CVE-2026-62658 | MEDIUM | 4.7 | 0.2% | Jul 14, 2026 | A security flaw was discovered in certain NETGEAR Nighthawk RAX series routers that could allow someone already logged i... |
| CVE-2026-62657 | MEDIUM | 4.9 | 0.1% | Jul 14, 2026 | A security flaw in the router's certificate validation process was discovered in the NETGEAR XR1000 Gaming Router and ce... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now