2026 CVE Vulnerabilities
43,246 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-48405 | HIGH | 7.8 | 0.2% | Aug 11, 2026 | Lightroom Classic is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in t... |
| CVE-2026-48404 | HIGH | 7.8 | 0.2% | Aug 11, 2026 | Lightroom Classic is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in t... |
| CVE-2026-48397 | HIGH | 8.6 | 0.5% | Aug 11, 2026 | Lightroom Classic is affected by a Deserialization of Untrusted Data vulnerability that could result in arbitrary code e... |
| CVE-2026-48381 | CRITICAL | 9 | 0.5% | Aug 11, 2026 | Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL ... |
| CVE-2026-47940 | HIGH | 7.8 | 0.2% | Aug 11, 2026 | Lightroom Classic is affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code exe... |
| CVE-2026-47705 | CRITICAL | 9.6 | — | Aug 11, 2026 | TypeBot is a chatbot builder tool. Version 3.16.1 has a CSV injection vulnerability in the result export functionality. ... |
| CVE-2026-27302 | CRITICAL | 10 | 0.6% | Aug 11, 2026 | Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrary code... |
| CVE-2026-20917 | MEDIUM | 4 | 0.1% | Aug 11, 2026 | Exposure of sensitive information caused by incorrect data forwarding during transient execution for some Intel(R) Proce... |
| CVE-2026-20901 | MEDIUM | 4 | 0.1% | Aug 11, 2026 | Improper input validation for some Intel(R) Xeon(R) processors within firmware may allow an escalation of privilege. Sta... |
| CVE-2026-20712 | MEDIUM | 4 | 0.1% | Aug 11, 2026 | Incomplete cleanup in some UEFI firmware for some Intel(R) reference platforms within UEFI may allow an information disc... |
| CVE-2026-0465 | MEDIUM | 5.6 | 0.1% | Aug 11, 2026 | A Use‑After‑Free (UAF) vulnerability in the AMD Ryzen™ Master Utility Driver could allow a local attacker to access kern... |
| CVE-2026-73089 | HIGH | 7.5 | — | Aug 11, 2026 | Browserslist is a configuration tool for sharing target browsers and Node.js versions between front-end tools. Prior to ... |
| CVE-2026-73088 | HIGH | 7.5 | — | Aug 11, 2026 | Browserslist is a configuration tool for sharing target browsers and Node.js versions between front-end tools. Prior to ... |
| CVE-2026-73087 | LOW | 2.3 | — | Aug 11, 2026 | Dozzle is a realtime log viewer for docker containers. From 10.5.2 until 10.6.15, the isBlockedIP SSRF guard in internal... |
| CVE-2026-73086 | HIGH | 7.4 | 0.3% | Aug 11, 2026 | nanoid is a secure, URL-friendly, unique string ID generator for JavaScript. Prior to versions 3.3.12 and 5.1.11, the na... |
| CVE-2026-73085 | MEDIUM | 5.3 | — | Aug 11, 2026 | Audiobookshelf is a self-hosted audiobook and podcast server. Prior to 2.36.0, the jwtAuthCheck function in server/auth/... |
| CVE-2026-73084 | MEDIUM | 6.1 | — | Aug 11, 2026 | Activepieces is an open source AI workflow automation platform. Prior to 0.83.0, the /api/redirect OAuth callback endpoi... |
| CVE-2026-73083 | HIGH | 7.6 | — | Aug 11, 2026 | Activepieces is an open source AI workflow automation platform. Prior to 0.80.0, in SANDBOX_CODE_ONLY mode, the engine l... |
| CVE-2026-73082 | MEDIUM | 5.3 | — | Aug 11, 2026 | Activepieces is an open source AI workflow automation platform. Prior to 0.82.0, the POST /api/v1/projects/:projectId/mc... |
| CVE-2026-73081 | HIGH | 8.7 | 0.3% | Aug 11, 2026 | Activepieces is an open source AI workflow automation platform. Prior to 0.80.0, the worker's code-compilation pipeline ... |
| CVE-2026-72971 | MEDIUM | 5.5 | — | Aug 11, 2026 | Improper link resolution before file access ('link following') in Windows Container Isolation FS Filter Driver (unionfs.... |
| CVE-2026-71390 | MEDIUM | 4 | 0.2% | Aug 11, 2026 | CAI Content Credentials is affected by an Improper Input Validation vulnerability that could result in a Security featur... |
| CVE-2026-71389 | MEDIUM | 6.2 | 0.2% | Aug 11, 2026 | CAI Content Credentials is affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in an a... |
| CVE-2026-71387 | HIGH | 8.8 | 0.3% | Aug 11, 2026 | ColdFusion is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the ... |
| CVE-2026-71386 | HIGH | 8.8 | 0.3% | Aug 11, 2026 | is affected by a Cross-site Scripting (XSS) vulnerability that could result in arbitrary code execution in the context o... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now