2026 CVE Vulnerabilities
45,056 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-48346 | HIGH | 7.9 | 0.2% | Jul 14, 2026 | Animate is affected by an Untrusted Search Path vulnerability that could result in arbitrary code execution in the conte... |
| CVE-2026-48345 | HIGH | 8.2 | 0.9% | Jul 14, 2026 | Animate is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vul... |
| CVE-2026-48310 | HIGH | 8.6 | 0.6% | Jul 14, 2026 | Adobe Experience Manager is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'... |
| CVE-2026-48252 | HIGH | 8.6 | 0.4% | Jul 14, 2026 | Adobe Experience Manager is affected by a Missing Authentication for Critical Function vulnerability that could result i... |
| CVE-2026-48069 | HIGH | 7.5 | 0.6% | Jul 14, 2026 | @grpc/grps-js implements the core functionality of gRPC purely in JavaScript, without a C++ addon. Prior to 1.9.16, 1.10... |
| CVE-2026-48068 | HIGH | 7.5 | 0.6% | Jul 14, 2026 | @grpc/grps-js implements the core functionality of gRPC purely in JavaScript, without a C++ addon. Prior to 1.9.16, 1.10... |
| CVE-2026-47995 | HIGH | 8.1 | 0.3% | Jul 14, 2026 | Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a high-privilege... |
| CVE-2026-47994 | HIGH | 8.7 | 0.3% | Jul 14, 2026 | Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged... |
| CVE-2026-47992 | HIGH | 7.2 | 19.6% | Jul 14, 2026 | Adobe Commerce is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vu... |
| CVE-2026-47988 | HIGH | 8.6 | 0.5% | Jul 14, 2026 | Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. A... |
| CVE-2026-47984 | HIGH | 8.2 | 0.5% | Jul 14, 2026 | Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. A... |
| CVE-2026-47737 | HIGH | 7.5 | 0.2% | Jul 14, 2026 | Puma is a Ruby/Rack web server built for parallelism. From 5.5.0 until 7.2.1 and 8.0.2, Puma is vulnerable to source IP ... |
| CVE-2026-47736 | HIGH | 7.5 | 0.4% | Jul 14, 2026 | Puma is a Ruby/Rack web server built for parallelism. From 5.5.0 until 7.2.1 and 8.0.2, when PROXY protocol v1 support i... |
| CVE-2026-47482 | HIGH | 7.5 | 0.3% | Jul 14, 2026 | NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause missing release of memory ... |
| CVE-2026-47480 | HIGH | 7.5 | 0.3% | Jul 14, 2026 | NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause an uncaught exception. A s... |
| CVE-2026-47479 | HIGH | 7.5 | 0.3% | Jul 14, 2026 | NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause uncontrolled resource cons... |
| CVE-2026-47478 | HIGH | 7.5 | 0.3% | Jul 14, 2026 | NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause the use of an expired file... |
| CVE-2026-47477 | HIGH | 7.5 | 0.3% | Jul 14, 2026 | NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause a stack-based buffer overf... |
| CVE-2026-47476 | HIGH | 7.5 | 0.3% | Jul 14, 2026 | NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause uncontrolled resource cons... |
| CVE-2026-47423 | HIGH | 8.2 | 0.3% | Jul 14, 2026 | DOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathML, and SVG. In 3.4.4, DOMPurify allowed selectedco... |
| CVE-2026-45071 | HIGH | 7.5 | 0.5% | Jul 14, 2026 | Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.4... |
| CVE-2026-45068 | HIGH | 7.5 | 0.5% | Jul 14, 2026 | Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.4... |
| CVE-2026-15711 | HIGH | 7.5 | 0.4% | Jul 14, 2026 | A vulnerability was found in libsoup's WebSocket frame parsing implementation. The library fails to validate length rule... |
| CVE-2026-15709 | HIGH | 7.5 | 0.5% | Jul 14, 2026 | A flaw was found in libsoup's WebSocket implementation when using the permessage-deflate extension. The extension's deco... |
| CVE-2026-15410 | HIGH | 7.2 | 1.6% | Jul 14, 2026 | Post-authentication improper control of generation of code ('Code Injection') vulnerability has been identified in the S... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now