2026 CVE Vulnerabilities

56,980 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-52100HIGH7.5Cross Site Request Forgery vulnerability in andreimarcu linux-server v.1.0 through v.2.3.8 allows a remote attacker to e...
CVE-2026-49978MEDIUM6.1DOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathML, and SVG. Prior to 3.4.7, DOMPurify IN_PLACE san...
CVE-2026-49855HIGH7.5Tornado is a Python web framework and asynchronous networking library. Prior to 6.5.6, Tornado gzip decompression routin...
CVE-2026-49854MEDIUM5.3Tornado is a Python web framework and asynchronous networking library. Prior to 6.5.6, the optional native extension tor...
CVE-2026-49853HIGH7.7Tornado is a Python web framework and asynchronous networking library. Prior to 6.5.6, SimpleAsyncHTTPClient shallow-cop...
CVE-2026-49477HIGH7.5Soup Sieve is a CSS selector library designed to be used with Beautiful Soup 4. Prior to 2.8.4, the CSS selector parser ...
CVE-2026-49476HIGH7.5Soup Sieve is a CSS selector library designed to be used with Beautiful Soup 4. Prior to 2.8.4, the CSS selector parser ...
CVE-2026-49459MEDIUM6.1DOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathML, and SVG. Prior to 3.4.6, DOMPurify.sanitize(roo...
CVE-2026-49458MEDIUM6.1DOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathML, and SVG. Prior to 3.4.6, DOMPurify.sanitize(nod...
CVE-2026-48816MEDIUM6.5sigstore-js provides JavaScript libraries for interacting with Sigstore services. Prior to 3.1.1, @sigstore/verify deriv...
CVE-2026-48815HIGH7.5sigstore-js provides JavaScript libraries for interacting with Sigstore services. Prior to 4.1.1, the documented certifi...
CVE-2026-48801HIGH7.5linkify-it is a links recognition library with full Unicode support. Prior to 5.0.1, LinkifyIt.prototype.match, the pack...
CVE-2026-48758MEDIUM5.4sigstore-js provides JavaScript libraries for interacting with Sigstore services. Prior to 3.2.1, the preAuthEncoding fu...
CVE-2026-48370HIGH7.8Media Encoder is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the c...
CVE-2026-48369HIGH7.8Premiere Pro is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the co...
CVE-2026-48367HIGH7.8After Effects is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the c...
CVE-2026-48366HIGH7.8Media Encoder is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the c...
CVE-2026-48344HIGH7.8Creative Cloud Desktop is affected by a Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability that could resul...
CVE-2026-48343HIGH7.8Bridge is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context ...
CVE-2026-48342HIGH7.8Bridge is affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code execution in t...
CVE-2026-48341HIGH7.8Bridge is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context ...
CVE-2026-48340HIGH7.8Bridge is affected by an Untrusted Pointer Dereference vulnerability that could result in arbitrary code execution in th...
CVE-2026-48339HIGH7.8Bridge is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the co...
CVE-2026-48338MEDIUM6.8ColdFusion is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerabilit...
CVE-2026-48332HIGH7.7ColdFusion is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in a Security feature byp...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now