2026 CVE Vulnerabilities

45,006 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-48337HIGH7.8Illustrator is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the con...
CVE-2026-48336HIGH7.8Illustrator is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the con...
CVE-2026-48335HIGH7.8Illustrator is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the con...
CVE-2026-48295HIGH7.5CAI Content Credentials is affected by an Insufficiently Protected Credentials vulnerability that could result in disclo...
CVE-2026-48290HIGH8.2CAI Content Credentials is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in arbitrary...
CVE-2026-48287HIGH7.4CAI Content Credentials is affected by an Untrusted Search Path vulnerability that could result in arbitrary code execut...
CVE-2026-48275HIGH8.6Illustrator is affected by an Untrusted Search Path vulnerability that could result in arbitrary code execution in the c...
CVE-2026-46640HIGH8.8Twig is a template language for PHP. From 3.15.0 until 3.26.0, _self.(<string>) and import-alias dynamic attribute synta...
CVE-2026-46638HIGH8.1Twig is a template language for PHP. Prior to 3.26.0, {% sandbox %}{% include %} can include a template that was previou...
CVE-2026-42049HIGH8.4jadx is a Dex to Java decompiler. Prior to 1.5.6, jadx inserts the android:versionName value from an AndroidManifest int...
CVE-2026-61520HIGH7.7Simple Machines Forum 2.1 prior to commit 4bf35cf and 3.0 prior to commit b4d23df contains a server-side request forgery...
CVE-2026-52100HIGH7.5Cross Site Request Forgery vulnerability in andreimarcu linux-server v.1.0 through v.2.3.8 allows a remote attacker to e...
CVE-2026-49855HIGH7.5Tornado is a Python web framework and asynchronous networking library. Prior to 6.5.6, Tornado gzip decompression routin...
CVE-2026-49853HIGH7.7Tornado is a Python web framework and asynchronous networking library. Prior to 6.5.6, SimpleAsyncHTTPClient shallow-cop...
CVE-2026-49477HIGH7.5Soup Sieve is a CSS selector library designed to be used with Beautiful Soup 4. Prior to 2.8.4, the CSS selector parser ...
CVE-2026-49476HIGH7.5Soup Sieve is a CSS selector library designed to be used with Beautiful Soup 4. Prior to 2.8.4, the CSS selector parser ...
CVE-2026-48815HIGH7.5sigstore-js provides JavaScript libraries for interacting with Sigstore services. Prior to 4.1.1, the documented certifi...
CVE-2026-48801HIGH7.5linkify-it is a links recognition library with full Unicode support. Prior to 5.0.1, LinkifyIt.prototype.match, the pack...
CVE-2026-48370HIGH7.8Media Encoder is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the c...
CVE-2026-48369HIGH7.8Premiere Pro is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the co...
CVE-2026-48367HIGH7.8After Effects is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the c...
CVE-2026-48366HIGH7.8Media Encoder is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the c...
CVE-2026-48344HIGH7.8Creative Cloud Desktop is affected by a Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability that could resul...
CVE-2026-48343HIGH7.8Bridge is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context ...
CVE-2026-48342HIGH7.8Bridge is affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code execution in t...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now