2026 CVE Vulnerabilities
56,979 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-48287 | HIGH | 7.4 | 0.2% | Jul 14, 2026 | CAI Content Credentials is affected by an Untrusted Search Path vulnerability that could result in arbitrary code execut... |
| CVE-2026-48275 | HIGH | 8.6 | 0.3% | Jul 14, 2026 | Illustrator is affected by an Untrusted Search Path vulnerability that could result in arbitrary code execution in the c... |
| CVE-2026-47732 | MEDIUM | 6.5 | 0.4% | Jul 14, 2026 | Twig is a template language for PHP. Prior to 3.26.0, several Twig language constructs trigger PHP string coercion on a ... |
| CVE-2026-47730 | MEDIUM | 5.4 | 0.2% | Jul 14, 2026 | Twig is a template language for PHP. From 3.0.0 until 3.26.0, Twig\Profiler\Dumper\HtmlDumper writes Profile::getTemplat... |
| CVE-2026-46640 | HIGH | 8.8 | 0.3% | Jul 14, 2026 | Twig is a template language for PHP. From 3.15.0 until 3.26.0, _self.(<string>) and import-alias dynamic attribute synta... |
| CVE-2026-46639 | MEDIUM | 6.5 | 0.4% | Jul 14, 2026 | Twig is a template language for PHP. From 3.24.0 until 3.26.0, object-destructuring assignment compiles CoreExtension::g... |
| CVE-2026-46638 | HIGH | 8.1 | 0.3% | Jul 14, 2026 | Twig is a template language for PHP. Prior to 3.26.0, {% sandbox %}{% include %} can include a template that was previou... |
| CVE-2026-46637 | MEDIUM | 5.4 | 0.2% | Jul 14, 2026 | Twig is a template language for PHP. Prior to 3.26.0, several filters in twig/markdown-extra and twig/cssinliner-extra a... |
| CVE-2026-46635 | MEDIUM | 4.3 | 0.4% | Jul 14, 2026 | Twig is a template language for PHP. Prior to 3.26.0, the column filter passes object arrays to PHP array_column(), whic... |
| CVE-2026-46634 | CRITICAL | 9.8 | 0.4% | Jul 14, 2026 | Twig is a template language for PHP. From 3.9.0 until 3.26.0, template_from_string() compiles an inner template under a ... |
| CVE-2026-46633 | CRITICAL | 9.8 | 0.5% | Jul 14, 2026 | Twig is a template language for PHP. Prior to 3.26.0, Compiler::string() does not escape single quotes when a template n... |
| CVE-2026-46629 | MEDIUM | 6.5 | 0.3% | Jul 14, 2026 | Twig is a template language for PHP. Prior to 3.26.0, twig/intl-extra memoises IntlDateFormatter and NumberFormatter ins... |
| CVE-2026-46628 | MEDIUM | 5.4 | 0.3% | Jul 14, 2026 | Twig is a template language for PHP. Prior to 3.26.0, the deprecated spaceless filter is registered as safe for HTML, ca... |
| CVE-2026-46627 | MEDIUM | 6.5 | 0.4% | Jul 14, 2026 | Twig is a template language for PHP. Prior to 3.26.0, the Twig sandbox does not prevent a template from consuming CPU, m... |
| CVE-2026-45363 | CRITICAL | 9.1 | 0.2% | Jul 14, 2026 | ruby-jwt is a Ruby implementation of the RFC 7519 OAuth JSON Web Token standard. Prior to 2.10.3 and 3.2.0, JWT.decode(t... |
| CVE-2026-42447 | MEDIUM | 5 | 0.1% | Jul 14, 2026 | jadx is a Dex to Java decompiler. Prior to 1.5.6, jadx-gui is affected by an HTML injection vulnerability in the Summary... |
| CVE-2026-42049 | HIGH | 8.4 | 0.2% | Jul 14, 2026 | jadx is a Dex to Java decompiler. Prior to 1.5.6, jadx inserts the android:versionName value from an AndroidManifest int... |
| CVE-2026-38450 | CRITICAL | 9.8 | 0.3% | Jul 14, 2026 | An issue in Aetopia Digital Asset Management DAM v.1.0.0 allows a remote attacker to execute arbitrary code via the name... |
| CVE-2026-21840 | LOW | 3.1 | 0.2% | Jul 14, 2026 | HCL BigFix Platform is affected by a user enumeration vulnerability which might allow an attacker, through careful syste... |
| CVE-2026-15750 | MEDIUM | 6.3 | — | Jul 14, 2026 | A weakness has been identified in mastergo-design mastergo-magic-mcp up to 0.2.0. Impacted is the function z.string of t... |
| CVE-2026-61520 | HIGH | 7.7 | 0.3% | Jul 14, 2026 | Simple Machines Forum 2.1 prior to commit 4bf35cf and 3.0 prior to commit b4d23df contains a server-side request forgery... |
| CVE-2026-59889 | MEDIUM | 6.5 | 0.4% | Jul 14, 2026 | jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From... |
| CVE-2026-53486 | CRITICAL | 9.1 | 0.6% | Jul 14, 2026 | The decompress package for Node.js extracts archives. Prior to 10.2.1 and 11.1.3, archive extraction can create files an... |
| CVE-2026-52101 | CRITICAL | 9.1 | 0.2% | Jul 14, 2026 | An issue in andreimarcu linux-server v.1.0 through v.2.3.8 allows a remote attacker to obtain sensitive information via ... |
| CVE-2026-52100 | HIGH | 7.5 | 0.5% | Jul 14, 2026 | Cross Site Request Forgery vulnerability in andreimarcu linux-server v.1.0 through v.2.3.8 allows a remote attacker to e... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now