2026 CVE Vulnerabilities

43,274 CVEs published in 2026.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2026-51807CRITICAL9.8Heap-based out-of-bounds write in j2k_precinct_subband::parse_packet_header() in OpenHTJ2K versions 0.18.3 and earlier (...
CVE-2026-48807CRITICAL9.1Twig is a template language for PHP. Prior to 3.27.0, the sandbox __toString() checks do not fully cover Traversable val...
CVE-2026-48806CRITICAL9.1Twig is a template language for PHP. Prior to 3.27.0, ArrayExpression does not guard dynamic mapping keys that are coerc...
CVE-2026-48805CRITICAL9.1Twig is a template language for PHP. Prior to 3.27.0, deprecated internal wrappers in src/Resources/core.php do not forw...
CVE-2026-48334CRITICAL9.3Illustrator is affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in t...
CVE-2026-46634CRITICAL9.8Twig is a template language for PHP. From 3.9.0 until 3.26.0, template_from_string() compiles an inner template under a ...
CVE-2026-46633CRITICAL9.8Twig is a template language for PHP. Prior to 3.26.0, Compiler::string() does not escape single quotes when a template n...
CVE-2026-45363CRITICAL9.1ruby-jwt is a Ruby implementation of the RFC 7519 OAuth JSON Web Token standard. Prior to 2.10.3 and 3.2.0, JWT.decode(t...
CVE-2026-38450CRITICAL9.8An issue in Aetopia Digital Asset Management DAM v.1.0.0 allows a remote attacker to execute arbitrary code via the name...
CVE-2026-53486CRITICAL9.1The decompress package for Node.js extracts archives. Prior to 10.2.1 and 11.1.3, archive extraction can create files an...
CVE-2026-52101CRITICAL9.1An issue in andreimarcu linux-server v.1.0 through v.2.3.8 allows a remote attacker to obtain sensitive information via ...
CVE-2026-48327CRITICAL9ColdFusion is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the ...
CVE-2026-48325CRITICAL9.3ColdFusion is affected by a Missing Authentication for Critical Function vulnerability that could result in arbitrary co...
CVE-2026-48324CRITICAL9.1ColdFusion is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulner...
CVE-2026-48322CRITICAL9.9ColdFusion is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability that could result i...
CVE-2026-48321CRITICAL9.3ColdFusion is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacke...
CVE-2026-48319CRITICAL9.1ColdFusion is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerabilit...
CVE-2026-48318CRITICAL9.9ColdFusion is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerabilit...
CVE-2026-48284CRITICAL9.6ColdFusion is affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in th...
CVE-2026-24227CRITICAL9.8NVIDIA TensorRT for contains a vulnerability where a user might cause a deserialization of untrusted data. A successful ...
CVE-2026-15773CRITICAL9.6Use after free in Core in Google Chrome on Windows prior to 150.0.7871.125 allowed a remote attacker to potentially perf...
CVE-2026-15643CRITICAL9.2AWS HealthLake MCP Server (awslabs.healthlake-mcp-server) is a Model Context Protocol server that enables AI assistants ...
CVE-2026-53633CRITICAL9.8Vitest is a testing framework powered by Vite. From 3.0.0 until 3.2.5, 4.1.8, and 5.0.0-beta.4, Vitest Browser Mode expo...
CVE-2026-48359CRITICAL9.6Adobe Experience Manager is affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability t...
CVE-2026-48358CRITICAL9.1Adobe Commerce is affected by an Improper Encoding or Escaping of Output vulnerability that could result in arbitrary co...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now