2026 CVE Vulnerabilities

43,246 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-73090CRITICAL9.3PeerTube is an ActivityPub-federated video streaming platform. Prior to 8.2.2, processUpdateActivity and processUpdateVi...
CVE-2026-72713HIGH8.7XAgent contains a path traversal vulnerability in the workspace file endpoint that allows self-registered or default-cre...
CVE-2026-72712MEDIUM6.5Nmap versions up to and including 7.99 contains a denial of service vulnerability that allows remote attackers to crash ...
CVE-2026-71398CRITICAL10Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrary code...
CVE-2026-71362CRITICAL9.1Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An att...
CVE-2026-69113MEDIUM5.4Cap v0.3.1 contains a broken access control vulnerability in the POST /api/video/comment endpoint that allows authentica...
CVE-2026-69102CRITICAL9.8MaxKey contains an unauthorized access vulnerability due to a hard-coded JWT signing secret in application-maxkey.proper...
CVE-2026-65680MEDIUM6.7Improper link resolution before file access ('link following') in Microsoft OneDrive allows an authorized attacker to el...
CVE-2026-48790MEDIUM5.5Turso CLI is the command line interface (CLI) to the open-source database Turso. Versions prior to 1.0.26 persist the us...
CVE-2026-48771HIGH8.2ishankportfolio is a portfolio website. Prior to version 1.0.1, contact form submissions could potentially be exposed du...
CVE-2026-48767HIGH7.6TypeBot is a chatbot builder tool. Versions prior to 3.17.0 allow a low-privilege guest member of a workspace to obtain ...
CVE-2026-48494HIGH7.1TypeBot is a chatbot builder tool. In version 3.16.1, an authenticated user who has read access to any typebot can resum...
CVE-2026-48447HIGH7.7Lightroom Classic is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution ...
CVE-2026-48441HIGH8.6Lightroom Classic is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulne...
CVE-2026-48416HIGH7.5Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. A...
CVE-2026-48415HIGH7.6Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. A...
CVE-2026-48414HIGH7.7Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged...
CVE-2026-48413HIGH8.7Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged...
CVE-2026-48412LOW2.7Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An att...
CVE-2026-48411MEDIUM6.5Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. A...
CVE-2026-48410HIGH7.8Lightroom Classic is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in t...
CVE-2026-48409HIGH7.8Lightroom Classic is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in t...
CVE-2026-48408HIGH7.8Lightroom Classic is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in t...
CVE-2026-48407HIGH7.8Lightroom Classic is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in t...
CVE-2026-48406HIGH7.8Lightroom Classic is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in t...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now