2026 CVE Vulnerabilities

56,980 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-48000MEDIUM6.1Adobe Commerce is affected by an Improper Redirect (Open Redirect) vulnerability that could result in a Security feature...
CVE-2026-47999MEDIUM4.8Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a high-privilege...
CVE-2026-47998MEDIUM5.9Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. A...
CVE-2026-47997MEDIUM5.9Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. A...
CVE-2026-47996MEDIUM6.8Adobe Commerce is affected by an Incorrect Authorization vulnerability that could lead to arbitrary file system read. A ...
CVE-2026-47995HIGH8.1Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a high-privilege...
CVE-2026-47994HIGH8.7Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged...
CVE-2026-47992HIGH7.2Adobe Commerce is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vu...
CVE-2026-47988HIGH8.6Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. A...
CVE-2026-47984HIGH8.2Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. A...
CVE-2026-47737HIGH7.5Puma is a Ruby/Rack web server built for parallelism. From 5.5.0 until 7.2.1 and 8.0.2, Puma is vulnerable to source IP ...
CVE-2026-47736HIGH7.5Puma is a Ruby/Rack web server built for parallelism. From 5.5.0 until 7.2.1 and 8.0.2, when PROXY protocol v1 support i...
CVE-2026-47482HIGH7.5NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause missing release of memory ...
CVE-2026-47481MEDIUM6.5NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause an authentication bypass t...
CVE-2026-47480HIGH7.5NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause an uncaught exception. A s...
CVE-2026-47479HIGH7.5NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause uncontrolled resource cons...
CVE-2026-47478HIGH7.5NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause the use of an expired file...
CVE-2026-47477HIGH7.5NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause a stack-based buffer overf...
CVE-2026-47476HIGH7.5NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause uncontrolled resource cons...
CVE-2026-47429MEDIUM5.9Vitest is a testing framework powered by Vite. Prior to 3.2.5 and 4.1.0, the Vitest UI/API server on Windows used isFile...
CVE-2026-47428CRITICAL9.6Vitest is a testing framework powered by Vite. From 4.0.17 until 4.1.6 and 5.0.0-beta.3, Vitest Browser Mode served /__v...
CVE-2026-47423HIGH8.2DOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathML, and SVG. In 3.4.4, DOMPurify allowed selectedco...
CVE-2026-47212MEDIUM5.3Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 6.4.40, 7.4.1...
CVE-2026-45071HIGH7.5Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.4...
CVE-2026-45068HIGH7.5Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.4...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now