2026 CVE Vulnerabilities
67,224 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-75744 | HIGH | 8.1 | — | Sep 22, 2026 | Adobe Experience Manager Forms JEE is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused... |
| CVE-2026-75743 | HIGH | 7.1 | 1.5% | Sep 22, 2026 | Adobe Experience Manager Forms JEE is affected by a Cross-Site Request Forgery (CSRF) vulnerability that could result in... |
| CVE-2026-75698 | CRITICAL | 9.3 | 0.3% | Sep 22, 2026 | Adobe Connect is affected by a reflected Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this vulner... |
| CVE-2026-75697 | CRITICAL | 9.3 | 0.3% | Sep 22, 2026 | Adobe Connect is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to in... |
| CVE-2026-75689 | CRITICAL | 9.3 | 0.3% | Sep 22, 2026 | Adobe Connect is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to in... |
| CVE-2026-75686 | CRITICAL | 9.3 | 1.1% | Sep 22, 2026 | Adobe Connect is affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in... |
| CVE-2026-75684 | CRITICAL | 9.3 | 0.3% | Sep 22, 2026 | Adobe Connect is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to in... |
| CVE-2026-75682 | CRITICAL | 9.9 | 0.5% | Sep 22, 2026 | Adobe Connect is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vul... |
| CVE-2026-75676 | HIGH | 7.8 | 0.2% | Sep 22, 2026 | Bridge is affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the c... |
| CVE-2026-75665 | HIGH | 7.8 | 0.2% | Sep 22, 2026 | Bridge is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the co... |
| CVE-2026-75663 | HIGH | 7.8 | 0.2% | Sep 22, 2026 | Bridge is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context ... |
| CVE-2026-75658 | HIGH | 7.8 | 0.1% | Sep 22, 2026 | Bridge is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context ... |
| CVE-2026-75656 | MEDIUM | 5.5 | 0.2% | Sep 22, 2026 | Bridge is affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker... |
| CVE-2026-75655 | HIGH | 7.8 | 0.2% | Sep 22, 2026 | Bridge is affected by an Uncontrolled Recursion vulnerability that could result in arbitrary code execution in the conte... |
| CVE-2026-75649 | HIGH | 7.8 | 0.2% | Sep 22, 2026 | Bridge is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the co... |
| CVE-2026-75638 | MEDIUM | 6.5 | 1.3% | Sep 22, 2026 | CAI Content Credentials is affected by an Improper Input Validation vulnerability that could result in a Security featur... |
| CVE-2026-75634 | MEDIUM | 4.3 | — | Sep 22, 2026 | CAI Content Credentials is affected by an Improper Input Validation vulnerability that could result in a Security featur... |
| CVE-2026-75633 | MEDIUM | 5.5 | 0.2% | Sep 22, 2026 | CAI Content Credentials is affected by an Improper Input Validation vulnerability that could result in an application de... |
| CVE-2026-75632 | HIGH | 7.5 | 0.9% | Sep 22, 2026 | CAI Content Credentials is affected by an Uncontrolled Resource Consumption vulnerability that could lead to application... |
| CVE-2026-63386 | MEDIUM | 5.3 | 0.5% | Sep 22, 2026 | js-toml is a TOML parser for JavaScript. Prior to 1.1.3, load() does not bound nesting or dotted-key depth in the recurs... |
| CVE-2026-57149 | CRITICAL | 9.9 | 0.6% | Sep 22, 2026 | plone.app.portlets.portlets provides a Plone-specific user interface for plone.portlets, as well as a standard set of po... |
| CVE-2026-48361 | MEDIUM | 6.1 | 0.2% | Sep 22, 2026 | Adobe Connect is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to in... |
| CVE-2026-37604 | CRITICAL | 9.8 | 0.3% | Sep 22, 2026 | pH7Software pH7Builder (pH7 Social Dating CMS) through 18.2.0 resolves the client IP address in _protected/framework/Ip/... |
| CVE-2026-37603 | MEDIUM | 6.5 | 0.4% | Sep 22, 2026 | Improper Restriction of Excessive Authentication Attempts in the administration login of pH7Software pH7Builder (pH7 Soc... |
| CVE-2026-34689 | HIGH | 8.6 | 0.7% | Sep 22, 2026 | Adobe Connect is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerabi... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now