2026 CVE Vulnerabilities
43,274 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-51807 | CRITICAL | 9.8 | 0.5% | Jul 14, 2026 | Heap-based out-of-bounds write in j2k_precinct_subband::parse_packet_header() in OpenHTJ2K versions 0.18.3 and earlier (... |
| CVE-2026-48807 | CRITICAL | 9.1 | 0.2% | Jul 14, 2026 | Twig is a template language for PHP. Prior to 3.27.0, the sandbox __toString() checks do not fully cover Traversable val... |
| CVE-2026-48806 | CRITICAL | 9.1 | 0.2% | Jul 14, 2026 | Twig is a template language for PHP. Prior to 3.27.0, ArrayExpression does not guard dynamic mapping keys that are coerc... |
| CVE-2026-48805 | CRITICAL | 9.1 | 0.3% | Jul 14, 2026 | Twig is a template language for PHP. Prior to 3.27.0, deprecated internal wrappers in src/Resources/core.php do not forw... |
| CVE-2026-48334 | CRITICAL | 9.3 | 0.4% | Jul 14, 2026 | Illustrator is affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in t... |
| CVE-2026-46634 | CRITICAL | 9.8 | 0.4% | Jul 14, 2026 | Twig is a template language for PHP. From 3.9.0 until 3.26.0, template_from_string() compiles an inner template under a ... |
| CVE-2026-46633 | CRITICAL | 9.8 | 0.5% | Jul 14, 2026 | Twig is a template language for PHP. Prior to 3.26.0, Compiler::string() does not escape single quotes when a template n... |
| CVE-2026-45363 | CRITICAL | 9.1 | 0.2% | Jul 14, 2026 | ruby-jwt is a Ruby implementation of the RFC 7519 OAuth JSON Web Token standard. Prior to 2.10.3 and 3.2.0, JWT.decode(t... |
| CVE-2026-38450 | CRITICAL | 9.8 | 0.3% | Jul 14, 2026 | An issue in Aetopia Digital Asset Management DAM v.1.0.0 allows a remote attacker to execute arbitrary code via the name... |
| CVE-2026-53486 | CRITICAL | 9.1 | 0.6% | Jul 14, 2026 | The decompress package for Node.js extracts archives. Prior to 10.2.1 and 11.1.3, archive extraction can create files an... |
| CVE-2026-52101 | CRITICAL | 9.1 | 0.2% | Jul 14, 2026 | An issue in andreimarcu linux-server v.1.0 through v.2.3.8 allows a remote attacker to obtain sensitive information via ... |
| CVE-2026-48327 | CRITICAL | 9 | 0.2% | Jul 14, 2026 | ColdFusion is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the ... |
| CVE-2026-48325 | CRITICAL | 9.3 | 0.3% | Jul 14, 2026 | ColdFusion is affected by a Missing Authentication for Critical Function vulnerability that could result in arbitrary co... |
| CVE-2026-48324 | CRITICAL | 9.1 | 1.1% | Jul 14, 2026 | ColdFusion is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulner... |
| CVE-2026-48322 | CRITICAL | 9.9 | 0.9% | Jul 14, 2026 | ColdFusion is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability that could result i... |
| CVE-2026-48321 | CRITICAL | 9.3 | 0.8% | Jul 14, 2026 | ColdFusion is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacke... |
| CVE-2026-48319 | CRITICAL | 9.1 | 27.0% | Jul 14, 2026 | ColdFusion is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerabilit... |
| CVE-2026-48318 | CRITICAL | 9.9 | 6.7% | Jul 14, 2026 | ColdFusion is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerabilit... |
| CVE-2026-48284 | CRITICAL | 9.6 | 28.0% | Jul 14, 2026 | ColdFusion is affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in th... |
| CVE-2026-24227 | CRITICAL | 9.8 | 0.5% | Jul 14, 2026 | NVIDIA TensorRT for contains a vulnerability where a user might cause a deserialization of untrusted data. A successful ... |
| CVE-2026-15773 | CRITICAL | 9.6 | 0.3% | Jul 14, 2026 | Use after free in Core in Google Chrome on Windows prior to 150.0.7871.125 allowed a remote attacker to potentially perf... |
| CVE-2026-15643 | CRITICAL | 9.2 | 0.2% | Jul 14, 2026 | AWS HealthLake MCP Server (awslabs.healthlake-mcp-server) is a Model Context Protocol server that enables AI assistants ... |
| CVE-2026-53633 | CRITICAL | 9.8 | 0.6% | Jul 14, 2026 | Vitest is a testing framework powered by Vite. From 3.0.0 until 3.2.5, 4.1.8, and 5.0.0-beta.4, Vitest Browser Mode expo... |
| CVE-2026-48359 | CRITICAL | 9.6 | 0.5% | Jul 14, 2026 | Adobe Experience Manager is affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability t... |
| CVE-2026-48358 | CRITICAL | 9.1 | 1.5% | Jul 14, 2026 | Adobe Commerce is affected by an Improper Encoding or Escaping of Output vulnerability that could result in arbitrary co... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now