2026 CVE Vulnerabilities

51,011 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-34647HIGH7.4Adobe Commerce versions 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 and earlier are affected by a S...
CVE-2026-34646HIGH7.5Adobe Commerce versions 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 and earlier are affected by an ...
CVE-2026-34645HIGH7.5Adobe Commerce versions 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 and earlier are affected by an ...
CVE-2026-23827HIGH7.5A heap-based buffer overflow vulnerability exists in a Network management service of AOS-8 and AOS-10 that could allow a...
CVE-2026-23826HIGH7.5A vulnerability in a network management service of AOS-8 Operating System could allow an unauthenticated remote attacker...
CVE-2026-23825HIGH7.5Vulnerabilities exist in a protocol-handling component of AOS-8 and AOS-10 Operating Systems. An unauthenticated attacke...
CVE-2026-23824HIGH7.5Vulnerabilities exist in a protocol-handling component of AOS-8 and AOS-10 Operating Systems. An unauthenticated attacke...
CVE-2026-8429HIGH8.8SPIP versions prior to 4.4.14 contain a remote code execution vulnerability in the private space that allows attackers t...
CVE-2026-34684HIGH7.8Substance3D - Designer versions 15.1.0 and earlier are affected by an out-of-bounds write vulnerability that could resul...
CVE-2026-34683HIGH7.8Substance3D - Designer versions 15.1.0 and earlier are affected by an out-of-bounds write vulnerability that could resul...
CVE-2026-34682HIGH7.8Substance3D - Designer versions 15.1.0 and earlier are affected by an out-of-bounds write vulnerability that could resul...
CVE-2026-34681HIGH7.8Substance3D - Designer versions 15.1.0 and earlier are affected by an out-of-bounds write vulnerability that could resul...
CVE-2026-23823HIGH7.2A vulnerability in the command line interface of Access Points running AOS-10 could allow an authenticated remote attack...
CVE-2026-23821HIGH7.2A vulnerability in the configuration processing logic of Access Points running AOS-10 could allow an authenticated remot...
CVE-2026-23820HIGH7.2A vulnerability in the command line interface of Access Points running AOS-10 and AOS-8 Instant could allow an authentic...
CVE-2026-23819HIGH8.8A vulnerability in the web-based management interface of Access Points running AOS-10 and AOS-8 Instant could allow an u...
CVE-2026-44184HIGH8Cleanuparr is a tool for automating the cleanup of unwanted or blocked files in Sonarr, Radarr, and supported download c...
CVE-2026-44167HIGH7.5phpseclib is a PHP secure communications library. Prior to 1.0.29, 2.0.54, and 3.0.52, anyone loading untrusted ASN1 fil...
CVE-2026-44166HIGH7.6Pocketbase is an open source web backend written in go. Prior to 0.22.42 and 0.37.4, in some situations, if an attacker ...
CVE-2026-43929HIGH8.2ssrfcheck is a library that checks if a string contains a potential SSRF attack. In 1.3.0 and earlier, ssrfcheck fails t...
CVE-2026-43892HIGH8.8AntSword is a cross-platform website management toolkit. Prior to 2.1.16, incomplete noxss() sanitization leads to 1-cli...
CVE-2026-43891HIGH7.5changedetection.io is a free open source web page change detection tool. Prior to 0.55.1, the vulnerability is caused by...
CVE-2026-42899HIGH7.5Loop with unreachable exit condition ('infinite loop') in ASP.NET Core allows an unauthorized attacker to deny service o...
CVE-2026-42896HIGH7.8Integer overflow or wraparound in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.
CVE-2026-42893HIGH7.5Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unauthoriz...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now