2026 CVE Vulnerabilities

53,619 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-21290HIGH8.7Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by a ...
CVE-2026-21289HIGH7.5Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by an...
CVE-2026-21284HIGH8.1Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by a ...
CVE-2026-27272HIGH7.8Illustrator versions 29.8.4, 30.1 and earlier are affected by an out-of-bounds write vulnerability that could result in ...
CVE-2026-27271HIGH7.8Illustrator versions 29.8.4, 30.1 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could resu...
CVE-2026-27267HIGH7.8Illustrator versions 29.8.4, 30.1 and earlier are affected by a Stack-based Buffer Overflow vulnerability that could res...
CVE-2026-21362HIGH7.8Illustrator versions 29.8.4, 30.1 and earlier are affected by an out-of-bounds write vulnerability that could result in ...
CVE-2026-21333HIGH8.6Illustrator versions 29.8.4, 30.1 and earlier are affected by an Untrusted Search Path vulnerability that might allow at...
CVE-2026-31837HIGH7.5Istio is an open platform to connect, manage, and secure microservices. Prior to 1.29.1, 1.28.5, and 1.27.8, a user of I...
CVE-2026-31834HIGH7.2Umbraco is an ASP.NET CMS. From 15.3.1 to before 16.5.1 and 17.2.2, A privilege escalation vulnerability has been identi...
CVE-2026-31830HIGH7.5sigstore-ruby is a pure Ruby implementation of the sigstore verify command from the sigstore/cosign project. Prior to 0....
CVE-2026-31829HIGH8.8Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.0.13, Flowise expose...
CVE-2026-31828HIGH8.8Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.5.2-a...
CVE-2026-31827HIGH7.1Alienbin is an anonymous code and text sharing web service. In 1.0.0 and earlier, the /save endpoint in server.js drops ...
CVE-2026-31817HIGH8.5OliveTin gives access to predefined shell commands from a web interface. Prior to 3000.11.2, when the saveLogs feature i...
CVE-2026-28807HIGH7.5Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in gleam-wisp wisp allows a...
CVE-2026-28806HIGH8.8Improper Authorization vulnerability in nerves-hub nerves_hub_web allows cross-organization device control via device bu...
CVE-2026-27278HIGH7.8Acrobat Reader versions 24.001.30307, 24.001.30308, 25.001.21265 and earlier are affected by a Use After Free vulnerabil...
CVE-2026-27220HIGH7.8Acrobat Reader versions 24.001.30307, 24.001.30308, 25.001.21265 and earlier are affected by a Use After Free vulnerabil...
CVE-2026-31801HIGH7.7zot is ancontainer image/artifact registry based on the Open Container Initiative Distribution Specification. From 1.3.0...
CVE-2026-30972HIGH7.5Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior o 9.5.2-al...
CVE-2026-30967HIGH8.8Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.5.2-a...
CVE-2026-30952HIGH7.5liquidjs is a Shopify / GitHub Pages compatible template engine in pure JavaScript. Prior to 10.25.0, the layout, render...
CVE-2026-30951HIGH7.5Sequelize is a Node.js ORM tool. Prior to 6.37.8, there is SQL injection via unescaped cast type in JSON/JSONB where cla...
CVE-2026-30949HIGH8.8Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.5.2-a...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now