2026 CVE Vulnerabilities

45,056 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-48346HIGH7.9Animate is affected by an Untrusted Search Path vulnerability that could result in arbitrary code execution in the conte...
CVE-2026-48345HIGH8.2Animate is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vul...
CVE-2026-48310HIGH8.6Adobe Experience Manager is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'...
CVE-2026-48252HIGH8.6Adobe Experience Manager is affected by a Missing Authentication for Critical Function vulnerability that could result i...
CVE-2026-48069HIGH7.5@grpc/grps-js implements the core functionality of gRPC purely in JavaScript, without a C++ addon. Prior to 1.9.16, 1.10...
CVE-2026-48068HIGH7.5@grpc/grps-js implements the core functionality of gRPC purely in JavaScript, without a C++ addon. Prior to 1.9.16, 1.10...
CVE-2026-47995HIGH8.1Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a high-privilege...
CVE-2026-47994HIGH8.7Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged...
CVE-2026-47992HIGH7.2Adobe Commerce is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vu...
CVE-2026-47988HIGH8.6Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. A...
CVE-2026-47984HIGH8.2Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. A...
CVE-2026-47737HIGH7.5Puma is a Ruby/Rack web server built for parallelism. From 5.5.0 until 7.2.1 and 8.0.2, Puma is vulnerable to source IP ...
CVE-2026-47736HIGH7.5Puma is a Ruby/Rack web server built for parallelism. From 5.5.0 until 7.2.1 and 8.0.2, when PROXY protocol v1 support i...
CVE-2026-47482HIGH7.5NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause missing release of memory ...
CVE-2026-47480HIGH7.5NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause an uncaught exception. A s...
CVE-2026-47479HIGH7.5NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause uncontrolled resource cons...
CVE-2026-47478HIGH7.5NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause the use of an expired file...
CVE-2026-47477HIGH7.5NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause a stack-based buffer overf...
CVE-2026-47476HIGH7.5NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause uncontrolled resource cons...
CVE-2026-47423HIGH8.2DOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathML, and SVG. In 3.4.4, DOMPurify allowed selectedco...
CVE-2026-45071HIGH7.5Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.4...
CVE-2026-45068HIGH7.5Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.4...
CVE-2026-15711HIGH7.5A vulnerability was found in libsoup's WebSocket frame parsing implementation. The library fails to validate length rule...
CVE-2026-15709HIGH7.5A flaw was found in libsoup's WebSocket implementation when using the permessage-deflate extension. The extension's deco...
CVE-2026-15410HIGH7.2Post-authentication improper control of generation of code ('Code Injection') vulnerability has been identified in the S...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now