2026 CVE Vulnerabilities

67,222 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-61570HIGH7.5MPXJ is an open source library to read and write project plans from a variety of file formats and databases. From 5.5.5 ...
CVE-2026-59991HIGH7.5psd-tools is a Python package for working with Adobe Photoshop PSD files. Prior to 1.17.4, PSDImage.composite() and PSDI...
CVE-2026-58268HIGH7.5SIPGO is a library for writing SIP services in the GO language. Prior to 1.4.1, ParserStream.parseSingle in sip/parser_s...
CVE-2026-47116CRITICAL9.8LTSecurity LTK3500SF contains a hard-coded credentials vulnerability where the root and guest account passwords are stor...
CVE-2026-28325HIGH8.8SolarWinds Observability Self-Hosted was found to be affected by an unauthenticated remote code execution vulnerability ...
CVE-2026-28324CRITICAL9.8SolarWinds Observability Self-Hosted was found to be affected by an unauthenticated remote code execution vulnerability ...
CVE-2026-95862HIGH7.5A malicious actor with access to the network could exploit an Out-of-bounds Write vulnerability found in certain UniFi g...
CVE-2026-95861HIGH7.5A malicious actor with access to the network could exploit an Uncontrolled Recursion vulnerability found in certain UniF...
CVE-2026-95831HIGH7.8Crypt::SelfCertificate versions from 1.01 through 1.05 for Perl contains malware which executes Python code from an obfu...
CVE-2026-94462HIGH7.1Spree is an open source e-commerce solution built with Ruby on Rails. From 5.4.0 until 5.4.4 and 5.5.4, PATCH /api/v3/st...
CVE-2026-91130CRITICAL9.3Home Assistant is open source home automation software focused on local control and privacy. Prior to 2026.7.0, the Stat...
CVE-2026-91129MEDIUM5.4Home Assistant is open source home automation software focused on local control and privacy. Prior to 2026.2.3, the IPP ...
CVE-2026-89277MEDIUM5.5CAI Content Credentials is affected by an Integer Overflow or Wraparound vulnerability that could result in an applicati...
CVE-2026-88415HIGH8.7MCMS 6.1.1 through 6.2.1 is vulnerable to stored Cross-Site Scripting (XSS). The article content field `contentDetails` ...
CVE-2026-88414CRITICAL9.8MCMS 6.1.1 through 6.2.1 contains a SQL injection vulnerability in the PageAction.verify endpoint (GET /ms/mdiy/page/ver...
CVE-2026-84396MEDIUM5.5InDesign Desktop is affected by a NULL Pointer Dereference vulnerability that could result in an application denial-of-s...
CVE-2026-84395HIGH7.1Premiere Pro is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in privilege escalation...
CVE-2026-83964HIGH7.5Adobe Connect is affected by an Improper Certificate Validation vulnerability that could lead to disclosure of sensitive...
CVE-2026-83963HIGH7.8Substance3D - Modeler is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution ...
CVE-2026-83962HIGH7.8Substance3D - Modeler is affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code exe...
CVE-2026-82000CRITICAL9.6Adobe Experience Manager Forms JEE is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result i...
CVE-2026-81999HIGH8.7Adobe Experience Manager Forms JEE is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result i...
CVE-2026-81998HIGH7.8Substance3D - Modeler is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution ...
CVE-2026-81995CRITICAL9.1Adobe Experience Manager Forms JEE is affected by an Improper Input Validation vulnerability that could result in arbitr...
CVE-2026-79906HIGH7.8Substance3D - Modeler is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now