2026 CVE Vulnerabilities

52,233 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-35196HIGH8.8Chamilo LMS is an open-source learning management system. In versions prior to 2.0.0-RC.3, an OS Command Injection vulne...
CVE-2026-34631HIGH7.8InCopy versions 20.5.2, 21.2 and earlier are affected by an out-of-bounds write vulnerability that could result in arbit...
CVE-2026-34619HIGH7.7ColdFusion versions 2023.18, 2025.6 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Dir...
CVE-2026-34602HIGH7.1Chamilo LMS is an open-source learning management system. In versions prior to 2.0.0-RC.3, the /api/course_rel_users end...
CVE-2026-33020HIGH7.1libsixel is a SIXEL encoder/decoder implementation derived from kmiya's sixel. Versions 1.8.7 and prior contain an integ...
CVE-2026-33019HIGH7.1libsixel is a SIXEL encoder/decoder implementation derived from kmiya's sixel. Versions 1.8.7 and prior contain an integ...
CVE-2026-33018HIGH7libsixel is a SIXEL encoder/decoder implementation derived from kmiya's sixel. Versions 1.8.7 and prior contain a Use-Af...
CVE-2026-27306HIGH8.4ColdFusion versions 2023.18, 2025.6 and earlier are affected by an Improper Input Validation vulnerability that could re...
CVE-2026-27305HIGH8.6ColdFusion versions 2023.18, 2025.6 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Dir...
CVE-2026-27282HIGH7.5ColdFusion versions 2023.18, 2025.6 and earlier are affected by an Improper Input Validation vulnerability that could re...
CVE-2026-34160HIGH8.6Chamilo LMS is an open-source learning management system. In versions prior to 2.0.0-RC.3, the PENS (Package Exchange No...
CVE-2026-33715HIGH7.2Chamilo LMS is an open-source learning management system. In version 2.0-RC.2, the file public/main/inc/ajax/install.aja...
CVE-2026-33714HIGH7.2Chamilo is an open-source learning management system (LMS). Version 2.0.0-RC.2 contains a SQL Injection vulnerability in...
CVE-2026-27287HIGH7.8InCopy versions 20.5.2, 21.2 and earlier are affected by an out-of-bounds read vulnerability when parsing a crafted file...
CVE-2026-24893HIGH8.8openITCOCKPIT is an open source monitoring tool built for different monitoring engines. openITCOCKPIT Community Edition ...
CVE-2026-40683HIGH7.7In OpenStack Keystone before 28.0.1, the LDAP identity backend does not convert the user enabled attribute to a boolean ...
CVE-2026-34630HIGH7.8Bridge versions 16.0.2, 15.1.4 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result ...
CVE-2026-34618HIGH7.8Illustrator versions 30.2, 29.8.5 and earlier are affected by an out-of-bounds write vulnerability that could result in ...
CVE-2026-27313HIGH7.8Bridge versions 16.0.2, 15.1.4 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result ...
CVE-2026-27312HIGH7.8Bridge versions 16.0.2, 15.1.4 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result ...
CVE-2026-27311HIGH7.8Bridge versions 16.0.2, 15.1.4 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result ...
CVE-2026-27310HIGH7.8Bridge versions 16.0.2, 15.1.4 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result ...
CVE-2026-27289HIGH7.8Photoshop Desktop versions 27.4 and earlier are affected by an out-of-bounds read vulnerability when parsing a crafted f...
CVE-2026-5756HIGH7.5Unauthenticated Configuration File Modification Vulnerability in DRC Central Office Services (COS) allows an attacker to...
CVE-2026-34629HIGH7.8InDesign Desktop versions 20.5.2, 21.2 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now