2026 CVE Vulnerabilities

56,980 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-48359CRITICAL9.6Adobe Experience Manager is affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability t...
CVE-2026-48358CRITICAL9.1Adobe Commerce is affected by an Improper Encoding or Escaping of Output vulnerability that could result in arbitrary co...
CVE-2026-48356CRITICAL9.3Adobe Commerce is affected by an Unrestricted Upload of File with Dangerous Type vulnerability that could result in arbi...
CVE-2026-48355MEDIUM5.4Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-...
CVE-2026-48350HIGH8.6Animate is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability t...
CVE-2026-48349HIGH8.1Animate is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the con...
CVE-2026-48348HIGH7.7Animate is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the con...
CVE-2026-48347HIGH7.7Animate is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vul...
CVE-2026-48346HIGH7.9Animate is affected by an Untrusted Search Path vulnerability that could result in arbitrary code execution in the conte...
CVE-2026-48345HIGH8.2Animate is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vul...
CVE-2026-48310HIGH8.6Adobe Experience Manager is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'...
CVE-2026-48263MEDIUM5.4Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-...
CVE-2026-48262MEDIUM5.4Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit ...
CVE-2026-48261MEDIUM5.4Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit ...
CVE-2026-48260MEDIUM5.4Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit ...
CVE-2026-48259CRITICAL9.6Adobe Experience Manager is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in arbitrar...
CVE-2026-48257MEDIUM5.4Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit ...
CVE-2026-48255MEDIUM5.4Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit ...
CVE-2026-48254MEDIUM5.4Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit ...
CVE-2026-48253MEDIUM5.4Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit ...
CVE-2026-48252HIGH8.6Adobe Experience Manager is affected by a Missing Authentication for Critical Function vulnerability that could result i...
CVE-2026-48069HIGH7.5@grpc/grps-js implements the core functionality of gRPC purely in JavaScript, without a C++ addon. Prior to 1.9.16, 1.10...
CVE-2026-48068HIGH7.5@grpc/grps-js implements the core functionality of gRPC purely in JavaScript, without a C++ addon. Prior to 1.9.16, 1.10...
CVE-2026-48038MEDIUM5.3joi is a schema description language and data validator for JavaScript. Prior to 17.13.4 and 18.2.1, denial of service i...
CVE-2026-48001LOW3.7Adobe Commerce is affected by an Information Exposure vulnerability that could lead to a limited disclosure of sensitive...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now