2026 CVE Vulnerabilities

53,163 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-66018MEDIUM6.5Build readers can access another repository's environment properties. A caller with read access to an ordinary repositor...
CVE-2026-66015HIGH7.2An authenticated privilege-escalation vulnerability in JFrog Platform may be exploited under admin-provisioned account c...
CVE-2026-66014CRITICAL9.8JFrog Artifactory contains an authentication handling weakness in internal request processing that, under specific condi...
CVE-2026-65925MEDIUM6.5A user with JFrog Artifactory Cargo remote repository read access could make Artifactory request unintended URLs and ret...
CVE-2026-65924MEDIUM6.5JFrog Artifactory support for Terraform remote repositories was found to be susceptible to Server-Side Request Forgery (...
CVE-2026-65923MEDIUM6.8A URL validation weakness in JFrog Artifactory Ansible repository handling could allow a user, under specific repository...
CVE-2026-65922MEDIUM5.4An authorization weakness in JFrog Artifactory internal metadata handling could allow a user with limited repository acc...
CVE-2026-65921HIGH8.8A path validation weakness in archive extraction/write handling allows entries with traversal sequences to be written ou...
CVE-2026-65618MEDIUM6.5Improper URL validation when handling specific URLs, allows an attacker, under certain conditions, to make unauthorized ...
CVE-2026-65617HIGH8.8A deserialization weakness in JFrog Artifactory package handling could allow a low-privileged user to impact confidentia...
CVE-2026-65616HIGH8.8Incorrect authorization validation in refresh token signature allows non-admin users to obtain a signed JFrog administra...
CVE-2026-64649MEDIUM6.5Next.js is a React framework for building full-stack web applications. In versions 14.1.1 through 15.5.20 and 16.0.0 thr...
CVE-2026-64648MEDIUM5.4Next.js is a React framework for building full-stack web applications. In versions 12.0.0 through 15.5.20 and 16.0.0 thr...
CVE-2026-59729MEDIUM5.1Astro is a web framework for content-driven websites. Versions prior to 7.0.6 are vulnerable to XSS through unescaped sp...
CVE-2026-59727LOW2.1Astro is a web framework for content-driven websites. In versions 3.10.0 through 7.0.3, when a transition:persist, trans...
CVE-2026-56748HIGH8.8Improper validation of symbolic links in the Pack Git import feature in Cribl Stream before 4.18.2 allows a remote authe...
CVE-2026-56747HIGH8.8Improper control of generation of code in the JSON Pointer-to-accessor compiler in Cribl Stream before 4.18.2 allows a r...
CVE-2026-42017HIGH8.8An event-handling weakness in JFrog Artifactory could expose privileged authorization material to a lower-privileged use...
CVE-2026-42016HIGH8.8JFrog Artifactory (Self Hosted) versions before 7.133.11 are vulnerable to a privilege escalation attack due to a valida...
CVE-2026-66759HIGH7.1A flaw was found in the file-icns plugin in GIMP. When applying a decompressed mask during ICNS image processing, the pl...
CVE-2026-66758HIGH7.8A flaw was found in the file-fits plugin in GIMP. When processing a FITS image file, the plugin calculates memory alloca...
CVE-2026-66757MEDIUM5.5A flaw was found in the file-sgi plugin in GIMP. When processing an RLE-compressed SGI image, the plugin allocates memor...
CVE-2026-66031MEDIUM5.4Ekushey Project Manager CRM through version 5.0 contains a stored cross-site scripting vulnerability that allows authent...
CVE-2026-64647MEDIUM5.4Next.js is a React framework for building full-stack web applications. In versions 12.0.0 through 15.5.20 and 16.0.0 thr...
CVE-2026-64646MEDIUM5.3Next.js is a React framework for building full-stack web applications. In versions 13.0.0 through 15.5.20 and 16.0.0 thr...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now