2026 CVE Vulnerabilities

52,673 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-33414HIGH7.8Podman is a tool for managing OCI containers and pods. Versions 4.8.0 through 5.8.1 contain a command injection vulnerab...
CVE-2026-33023HIGH7.8libsixel is a SIXEL encoder/decoder implementation derived from kmiya's sixel. In versions 1.8.7 and prior, when built w...
CVE-2026-33021HIGH7.3libsixel is a SIXEL encoder/decoder implementation derived from kmiya's sixel. Versions 1.8.7 and prior contain a use-af...
CVE-2026-27298HIGH7.8Adobe Framemaker versions 2022.8 and earlier are affected by an Access of Resource Using Incompatible Type ('Type Confus...
CVE-2026-27297HIGH7.8Adobe Framemaker versions 2022.8 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability tha...
CVE-2026-27296HIGH7.8Adobe Framemaker versions 2022.8 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability tha...
CVE-2026-27295HIGH7.8Adobe Framemaker versions 2022.8 and earlier are affected by an out-of-bounds write vulnerability that could result in a...
CVE-2026-27294HIGH7.8Adobe Framemaker versions 2022.8 and earlier are affected by an out-of-bounds read vulnerability when parsing a crafted ...
CVE-2026-27293HIGH7.8Adobe Framemaker versions 2022.8 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could resul...
CVE-2026-27292HIGH7.8Adobe Framemaker versions 2022.8 and earlier are affected by a Use After Free vulnerability that could result in arbitra...
CVE-2026-27290HIGH8.6Adobe Framemaker versions 2022.8 and earlier are affected by an Untrusted Search Path vulnerability that might allow att...
CVE-2026-40291HIGH8.8Chamilo LMS is an open-source learning management system. In versions prior to 2.0.0-RC.3, an insecure direct object mod...
CVE-2026-35196HIGH8.8Chamilo LMS is an open-source learning management system. In versions prior to 2.0.0-RC.3, an OS Command Injection vulne...
CVE-2026-34631HIGH7.8InCopy versions 20.5.2, 21.2 and earlier are affected by an out-of-bounds write vulnerability that could result in arbit...
CVE-2026-34619HIGH7.7ColdFusion versions 2023.18, 2025.6 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Dir...
CVE-2026-34602HIGH7.1Chamilo LMS is an open-source learning management system. In versions prior to 2.0.0-RC.3, the /api/course_rel_users end...
CVE-2026-33020HIGH7.1libsixel is a SIXEL encoder/decoder implementation derived from kmiya's sixel. Versions 1.8.7 and prior contain an integ...
CVE-2026-33019HIGH7.1libsixel is a SIXEL encoder/decoder implementation derived from kmiya's sixel. Versions 1.8.7 and prior contain an integ...
CVE-2026-33018HIGH7libsixel is a SIXEL encoder/decoder implementation derived from kmiya's sixel. Versions 1.8.7 and prior contain a Use-Af...
CVE-2026-27306HIGH8.4ColdFusion versions 2023.18, 2025.6 and earlier are affected by an Improper Input Validation vulnerability that could re...
CVE-2026-27305HIGH8.6ColdFusion versions 2023.18, 2025.6 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Dir...
CVE-2026-27282HIGH7.5ColdFusion versions 2023.18, 2025.6 and earlier are affected by an Improper Input Validation vulnerability that could re...
CVE-2026-34160HIGH8.6Chamilo LMS is an open-source learning management system. In versions prior to 2.0.0-RC.3, the PENS (Package Exchange No...
CVE-2026-33715HIGH7.2Chamilo LMS is an open-source learning management system. In version 2.0-RC.2, the file public/main/inc/ajax/install.aja...
CVE-2026-33714HIGH7.2Chamilo is an open-source learning management system (LMS). Version 2.0.0-RC.2 contains a SQL Injection vulnerability in...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now