2026 CVE Vulnerabilities
56,980 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-48000 | MEDIUM | 6.1 | 0.5% | Jul 14, 2026 | Adobe Commerce is affected by an Improper Redirect (Open Redirect) vulnerability that could result in a Security feature... |
| CVE-2026-47999 | MEDIUM | 4.8 | 0.4% | Jul 14, 2026 | Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a high-privilege... |
| CVE-2026-47998 | MEDIUM | 5.9 | 0.7% | Jul 14, 2026 | Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. A... |
| CVE-2026-47997 | MEDIUM | 5.9 | 0.7% | Jul 14, 2026 | Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. A... |
| CVE-2026-47996 | MEDIUM | 6.8 | 0.9% | Jul 14, 2026 | Adobe Commerce is affected by an Incorrect Authorization vulnerability that could lead to arbitrary file system read. A ... |
| CVE-2026-47995 | HIGH | 8.1 | 0.4% | Jul 14, 2026 | Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a high-privilege... |
| CVE-2026-47994 | HIGH | 8.7 | 0.6% | Jul 14, 2026 | Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged... |
| CVE-2026-47992 | HIGH | 7.2 | 1.0% | Jul 14, 2026 | Adobe Commerce is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vu... |
| CVE-2026-47988 | HIGH | 8.6 | 0.7% | Jul 14, 2026 | Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. A... |
| CVE-2026-47984 | HIGH | 8.2 | 0.6% | Jul 14, 2026 | Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. A... |
| CVE-2026-47737 | HIGH | 7.5 | 0.2% | Jul 14, 2026 | Puma is a Ruby/Rack web server built for parallelism. From 5.5.0 until 7.2.1 and 8.0.2, Puma is vulnerable to source IP ... |
| CVE-2026-47736 | HIGH | 7.5 | 0.4% | Jul 14, 2026 | Puma is a Ruby/Rack web server built for parallelism. From 5.5.0 until 7.2.1 and 8.0.2, when PROXY protocol v1 support i... |
| CVE-2026-47482 | HIGH | 7.5 | 0.3% | Jul 14, 2026 | NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause missing release of memory ... |
| CVE-2026-47481 | MEDIUM | 6.5 | 0.3% | Jul 14, 2026 | NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause an authentication bypass t... |
| CVE-2026-47480 | HIGH | 7.5 | 0.3% | Jul 14, 2026 | NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause an uncaught exception. A s... |
| CVE-2026-47479 | HIGH | 7.5 | 0.3% | Jul 14, 2026 | NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause uncontrolled resource cons... |
| CVE-2026-47478 | HIGH | 7.5 | 0.3% | Jul 14, 2026 | NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause the use of an expired file... |
| CVE-2026-47477 | HIGH | 7.5 | 0.3% | Jul 14, 2026 | NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause a stack-based buffer overf... |
| CVE-2026-47476 | HIGH | 7.5 | 0.5% | Jul 14, 2026 | NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause uncontrolled resource cons... |
| CVE-2026-47429 | MEDIUM | 5.9 | 1.0% | Jul 14, 2026 | Vitest is a testing framework powered by Vite. Prior to 3.2.5 and 4.1.0, the Vitest UI/API server on Windows used isFile... |
| CVE-2026-47428 | CRITICAL | 9.6 | 0.4% | Jul 14, 2026 | Vitest is a testing framework powered by Vite. From 4.0.17 until 4.1.6 and 5.0.0-beta.3, Vitest Browser Mode served /__v... |
| CVE-2026-47423 | HIGH | 8.2 | 0.3% | Jul 14, 2026 | DOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathML, and SVG. In 3.4.4, DOMPurify allowed selectedco... |
| CVE-2026-47212 | MEDIUM | 5.3 | 0.3% | Jul 14, 2026 | Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 6.4.40, 7.4.1... |
| CVE-2026-45071 | HIGH | 7.5 | 0.5% | Jul 14, 2026 | Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.4... |
| CVE-2026-45068 | HIGH | 7.5 | 0.5% | Jul 14, 2026 | Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.4... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now