2026 CVE Vulnerabilities
56,980 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-48359 | CRITICAL | 9.6 | 1.0% | Jul 14, 2026 | Adobe Experience Manager is affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability t... |
| CVE-2026-48358 | CRITICAL | 9.1 | 1.5% | Jul 14, 2026 | Adobe Commerce is affected by an Improper Encoding or Escaping of Output vulnerability that could result in arbitrary co... |
| CVE-2026-48356 | CRITICAL | 9.3 | 1.0% | Jul 14, 2026 | Adobe Commerce is affected by an Unrestricted Upload of File with Dangerous Type vulnerability that could result in arbi... |
| CVE-2026-48355 | MEDIUM | 5.4 | 0.4% | Jul 14, 2026 | Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-... |
| CVE-2026-48350 | HIGH | 8.6 | 0.3% | Jul 14, 2026 | Animate is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability t... |
| CVE-2026-48349 | HIGH | 8.1 | 0.2% | Jul 14, 2026 | Animate is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the con... |
| CVE-2026-48348 | HIGH | 7.7 | 0.2% | Jul 14, 2026 | Animate is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the con... |
| CVE-2026-48347 | HIGH | 7.7 | 0.7% | Jul 14, 2026 | Animate is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vul... |
| CVE-2026-48346 | HIGH | 7.9 | 0.3% | Jul 14, 2026 | Animate is affected by an Untrusted Search Path vulnerability that could result in arbitrary code execution in the conte... |
| CVE-2026-48345 | HIGH | 8.2 | 0.9% | Jul 14, 2026 | Animate is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vul... |
| CVE-2026-48310 | HIGH | 8.6 | 1.0% | Jul 14, 2026 | Adobe Experience Manager is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'... |
| CVE-2026-48263 | MEDIUM | 5.4 | 0.4% | Jul 14, 2026 | Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-... |
| CVE-2026-48262 | MEDIUM | 5.4 | 0.4% | Jul 14, 2026 | Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit ... |
| CVE-2026-48261 | MEDIUM | 5.4 | 0.4% | Jul 14, 2026 | Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit ... |
| CVE-2026-48260 | MEDIUM | 5.4 | 0.4% | Jul 14, 2026 | Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit ... |
| CVE-2026-48259 | CRITICAL | 9.6 | 0.9% | Jul 14, 2026 | Adobe Experience Manager is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in arbitrar... |
| CVE-2026-48257 | MEDIUM | 5.4 | 0.4% | Jul 14, 2026 | Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit ... |
| CVE-2026-48255 | MEDIUM | 5.4 | 0.4% | Jul 14, 2026 | Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit ... |
| CVE-2026-48254 | MEDIUM | 5.4 | 0.4% | Jul 14, 2026 | Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit ... |
| CVE-2026-48253 | MEDIUM | 5.4 | 0.4% | Jul 14, 2026 | Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit ... |
| CVE-2026-48252 | HIGH | 8.6 | 0.9% | Jul 14, 2026 | Adobe Experience Manager is affected by a Missing Authentication for Critical Function vulnerability that could result i... |
| CVE-2026-48069 | HIGH | 7.5 | 0.6% | Jul 14, 2026 | @grpc/grps-js implements the core functionality of gRPC purely in JavaScript, without a C++ addon. Prior to 1.9.16, 1.10... |
| CVE-2026-48068 | HIGH | 7.5 | 0.6% | Jul 14, 2026 | @grpc/grps-js implements the core functionality of gRPC purely in JavaScript, without a C++ addon. Prior to 1.9.16, 1.10... |
| CVE-2026-48038 | MEDIUM | 5.3 | 0.3% | Jul 14, 2026 | joi is a schema description language and data validator for JavaScript. Prior to 17.13.4 and 18.2.1, denial of service i... |
| CVE-2026-48001 | LOW | 3.7 | 0.5% | Jul 14, 2026 | Adobe Commerce is affected by an Information Exposure vulnerability that could lead to a limited disclosure of sensitive... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now