2026 CVE Vulnerabilities

69,729 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-27269HIGH7.8Premiere Pro versions 25.5 and earlier are affected by an out-of-bounds read vulnerability when parsing a crafted file, ...
CVE-2026-27219MEDIUM5.5Substance3D - Painter versions 11.1.2 and earlier are affected by an Out-of-bounds Read vulnerability that could lead to...
CVE-2026-27218MEDIUM5.5Substance3D - Painter versions 11.1.2 and earlier are affected by a NULL Pointer Dereference vulnerability that could le...
CVE-2026-27217MEDIUM5.5Substance3D - Painter versions 11.1.2 and earlier are affected by a NULL Pointer Dereference vulnerability that could le...
CVE-2026-27216MEDIUM5.5Substance3D - Painter versions 11.1.2 and earlier are affected by an out-of-bounds read vulnerability that could lead to...
CVE-2026-27215MEDIUM5.5Substance3D - Painter versions 11.1.2 and earlier are affected by a NULL Pointer Dereference vulnerability that could le...
CVE-2026-27214MEDIUM5.5Substance3D - Painter versions 11.1.2 and earlier are affected by a NULL Pointer Dereference vulnerability that could le...
CVE-2026-26801HIGH7.5Server-Side Request Forgery (SSRF) vulnerability in pdfmake versions 0.3.0-beta.2 through 0.3.5 allows a remote attacker...
CVE-2026-26742HIGH8.1PX4 Autopilot versions 1.12.x through 1.15.x contain a protection mechanism failure in the "Re-arm Grace Period" logic. ...
CVE-2026-26741HIGH8.1PX4 Autopilot versions 1.12.x through 1.15.x contain a logic flaw in the mode switching mechanism. When switching from A...
CVE-2026-21365MEDIUM5.5Substance3D - Painter versions 11.1.2 and earlier are affected by an out-of-bounds read vulnerability that could lead to...
CVE-2026-21364MEDIUM5.5Substance3D - Painter versions 11.1.2 and earlier are affected by a NULL Pointer Dereference vulnerability that could le...
CVE-2026-21363MEDIUM5.5Substance3D - Painter versions 11.1.2 and earlier are affected by a NULL Pointer Dereference vulnerability that could le...
CVE-2026-3862MEDIUM4.8Cross-site Scripting (XSS) allows an attacker to submit specially crafted data to the application which is returned unal...
CVE-2026-3854HIGH8.8An improper neutralization of special elements vulnerability was identified in GitHub Enterprise Server that allowed an ...
CVE-2026-3847HIGH8.8Memory safety bugs present in Firefox 148.0.2. Some of these bugs showed evidence of memory corruption and we presume th...
CVE-2026-3846MEDIUM6.5Same-origin policy bypass in the CSS Parsing and Computation component. This vulnerability was fixed in Firefox 148.0.2.
CVE-2026-3845HIGH8.8Heap buffer overflow in the Audio/Video: Playback component in Firefox for Android. This vulnerability was fixed in Fire...
CVE-2026-3843CRITICAL9.8Nefteprodukttekhnika BUK TS-G Gas Station Automation System 2.9.1 on Linux contains a SQL Injection vulnerability (CWE-8...
CVE-2026-3483HIGH7.8An exposed dangerous method in Ivanti DSM before version 2026.1.1 allows a local authenticated attacker to escalate thei...
CVE-2026-3315HIGH7.8Incorrect Default Permissions, : Execution with Unnecessary Privileges, : Incorrect Permission Assignment for Critical R...
CVE-2026-3306MEDIUM4.3An improper authorization vulnerability was identified in GitHub Enterprise Server that allowed a user with read access ...
CVE-2026-3228MEDIUM6.4The NextScripts: Social Networks Auto-Poster plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `...
CVE-2026-31797MEDIUM6.1iccDEV provides a set of libraries and tools for working with ICC color management profiles. Prior to 2.3.1.5, there is ...
CVE-2026-31796HIGH7.8iccDEV provides a set of libraries and tools for working with ICC color management profiles. Prior to 2.3.1.5, there is ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now