2026 CVE Vulnerabilities

43,246 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-48405HIGH7.8Lightroom Classic is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in t...
CVE-2026-48404HIGH7.8Lightroom Classic is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in t...
CVE-2026-48397HIGH8.6Lightroom Classic is affected by a Deserialization of Untrusted Data vulnerability that could result in arbitrary code e...
CVE-2026-48381CRITICAL9Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL ...
CVE-2026-47940HIGH7.8Lightroom Classic is affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code exe...
CVE-2026-47705CRITICAL9.6TypeBot is a chatbot builder tool. Version 3.16.1 has a CSV injection vulnerability in the result export functionality. ...
CVE-2026-27302CRITICAL10Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrary code...
CVE-2026-20917MEDIUM4Exposure of sensitive information caused by incorrect data forwarding during transient execution for some Intel(R) Proce...
CVE-2026-20901MEDIUM4Improper input validation for some Intel(R) Xeon(R) processors within firmware may allow an escalation of privilege. Sta...
CVE-2026-20712MEDIUM4Incomplete cleanup in some UEFI firmware for some Intel(R) reference platforms within UEFI may allow an information disc...
CVE-2026-0465MEDIUM5.6A Use‑After‑Free (UAF) vulnerability in the AMD Ryzen™ Master Utility Driver could allow a local attacker to access kern...
CVE-2026-73089HIGH7.5Browserslist is a configuration tool for sharing target browsers and Node.js versions between front-end tools. Prior to ...
CVE-2026-73088HIGH7.5Browserslist is a configuration tool for sharing target browsers and Node.js versions between front-end tools. Prior to ...
CVE-2026-73087LOW2.3Dozzle is a realtime log viewer for docker containers. From 10.5.2 until 10.6.15, the isBlockedIP SSRF guard in internal...
CVE-2026-73086HIGH7.4nanoid is a secure, URL-friendly, unique string ID generator for JavaScript. Prior to versions 3.3.12 and 5.1.11, the na...
CVE-2026-73085MEDIUM5.3Audiobookshelf is a self-hosted audiobook and podcast server. Prior to 2.36.0, the jwtAuthCheck function in server/auth/...
CVE-2026-73084MEDIUM6.1Activepieces is an open source AI workflow automation platform. Prior to 0.83.0, the /api/redirect OAuth callback endpoi...
CVE-2026-73083HIGH7.6Activepieces is an open source AI workflow automation platform. Prior to 0.80.0, in SANDBOX_CODE_ONLY mode, the engine l...
CVE-2026-73082MEDIUM5.3Activepieces is an open source AI workflow automation platform. Prior to 0.82.0, the POST /api/v1/projects/:projectId/mc...
CVE-2026-73081HIGH8.7Activepieces is an open source AI workflow automation platform. Prior to 0.80.0, the worker's code-compilation pipeline ...
CVE-2026-72971MEDIUM5.5Improper link resolution before file access ('link following') in Windows Container Isolation FS Filter Driver (unionfs....
CVE-2026-71390MEDIUM4CAI Content Credentials is affected by an Improper Input Validation vulnerability that could result in a Security featur...
CVE-2026-71389MEDIUM6.2CAI Content Credentials is affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in an a...
CVE-2026-71387HIGH8.8ColdFusion is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the ...
CVE-2026-71386HIGH8.8is affected by a Cross-site Scripting (XSS) vulnerability that could result in arbitrary code execution in the context o...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now