2026 CVE Vulnerabilities

50,972 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-48399HIGH7.5Adobe Campaign Classic (ACC) is affected by a Violation of Secure Design Principles vulnerability that could result in a...
CVE-2026-48333CRITICAL9.8Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in privilege esca...
CVE-2026-48331CRITICAL10Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in priv...
CVE-2026-48330CRITICAL10Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL ...
CVE-2026-48326CRITICAL9.9Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL ...
CVE-2026-48323CRITICAL10Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements Used in a Template Engine vul...
CVE-2026-48317CRITICAL9.6Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Directives in Dynamically Evaluated Code ('Eva...
CVE-2026-18684CRITICAL9.8A weakness has been identified in GL.iNet GL-MT3000 up to 4.4.5. This issue affects the function remove_profile of the f...
CVE-2026-18667CRITICAL9.6A vulnerability in Tenable Sensor Proxy allows a remote attacker to execute code with elevated privileges by inducing an...
CVE-2026-69249HIGH8.7python-cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Prior to ...
CVE-2026-69248MEDIUM6.9cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Prior to 49.0.0,...
CVE-2026-69247HIGH8.2cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. From 44.0.0 unti...
CVE-2026-67977HIGH7.5An integer overflow in the Svc::FileDownlink::SendPartial component of fprime framework v4.2.2 allows attackers to cause...
CVE-2026-67975HIGH7.5Incorrect access control in NASA cFS v7.0.1 allows attackers to arbitrarily remove low-index subscriptions and add new s...
CVE-2026-67974HIGH7.5A parser boundary flaw in the Software Bus Network (SBN) application's peer subscription message handling in NASA cFS v7...
CVE-2026-67973HIGH7.5An issue in the CFDP receive path of NASA cFS v7.0.1 allows attackers to cause a Denial of Service (DoS) via replaying f...
CVE-2026-67970HIGH7.5Incorrect access control in the DS_SetDestPathCmd() component of NASA cFS v7.0.1 allows attackers to access sensitive co...
CVE-2026-67969HIGH7.5An issue in the HS_MonitorApplications() component of NASA cFS v7.0.1 allows attackers to force the processor to reset v...
CVE-2026-67617MEDIUM4.8Microweber CMS through 2.0.20 contains a stored cross-site scripting vulnerability in the content tagging system that al...
CVE-2026-67616MEDIUM5.3Camaleon CMS through 2.9.2, fixed in commit 88ab703, contains a missing authorization vulnerability on the drafts endpoi...
CVE-2026-48115MEDIUM6.3Misskey is an open source, federated social media platform. All Misskey servers running versions 2024.5.0 and later, but...
CVE-2026-47746HIGH8.9Misskey is an open source, federated social media platform. Versions 12.37.0 and later, but prior to 2026.5.4, are vulne...
CVE-2026-46714MEDIUM5.1Misskey is an open source, federated social media platform. IVersions 8.63.0 and later, but prior to 2026.5.4, contain a...
CVE-2026-46713CRITICAL9.2Misskey is an open source, federated social media platform. Versions 12.37.0 and later, but prior to 2026.5.4, contain a...
CVE-2026-46712LOW2.3Misskey is an open source, federated social media platform. Versions 2025.3.2 and later, but prior to 2026.5.4, contain ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now