2026 CVE Vulnerabilities

57,060 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-15111HIGH7.5Use after free in Views in Google Chrome prior to 150.0.7871.115 allowed a remote attacker who convinced a user to engag...
CVE-2026-15110HIGH8.8Use after free in Extensions in Google Chrome prior to 150.0.7871.115 allowed an attacker who convinced a user to instal...
CVE-2026-15109MEDIUM6.5Uninitialized Use in ANGLE in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to obtain potentially sens...
CVE-2026-15108MEDIUM4.3Integer overflow in Extensions API in Google Chrome prior to 150.0.7871.115 allowed an attacker who convinced a user to ...
CVE-2026-15107HIGH8.8Use after free in IndexedDB in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to execute arbitrary code...
CVE-2026-15105MEDIUM6.3A flaw has been found in davenardella snap7 up to 1.4.3. This affects the function TS7Worker::PerformFunctionRead of the...
CVE-2026-5923MEDIUM6Malicious use of a stolen cookie might allow modifications to the contents of the IP phone’s webpage.
CVE-2026-5922MEDIUM5.9The IP phone might use malicious input stored in configuration parameters and render it as content for the WebUI’s webpa...
CVE-2026-55878HIGH7.8Symfony UX is a JavaScript ecosystem for Symfony. From 2.32.0 before 2.36.1 and from 3.0.0 before 3.2.0, the ux:install ...
CVE-2026-55877MEDIUM6.1Symfony UX is a JavaScript ecosystem for Symfony. From 2.17.0 before 2.36.1 and from 3.0.0 before 3.2.0, the ux_icon() T...
CVE-2026-55849HIGH8.5@cyclonedx/cyclonedx-npm creates CycloneDX Software Bill of Materials from npm projects. From 2.1.0 before 5.0.0, the CL...
CVE-2026-55830HIGH8.3RestrictedPython is a tool that helps to define a subset of the Python language which allows to provide a program input ...
CVE-2026-55471CRITICAL9.1HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to 6.9.10...
CVE-2026-55470HIGH7.5HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to 6.9.10...
CVE-2026-54777MEDIUM6.5CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1, ...
CVE-2026-52200CRITICAL9.8An issue in Generic OEM UZ801_v2.1 4G LTE Router V3.4.3 allows a remote attacker to execute arbitrary code via the /ajax...
CVE-2026-51535HIGH7.5In OpENer 2.3.0 (commit 76b95cf), a resource exhaustion (Denial of Service) vulnerability exists in its network processi...
CVE-2026-48492MEDIUM6.5Snipe-IT is an IT asset/license management system. Prior to version 8.6.1, the GET /api/v1/{object}/selectlist API endpo...
CVE-2026-44161HIGH7.2Fluentd collects events from various data sources and writes them to files, RDBMS, NoSQL, IaaS, SaaS, Hadoop and so on. ...
CVE-2026-44160HIGH7.5Fluentd collects events from various data sources and writes them to files, RDBMS, NoSQL, IaaS, SaaS, Hadoop and so on. ...
CVE-2026-44025HIGH7.5Fluentd collects events from various data sources and writes them to files, RDBMS, NoSQL, IaaS, SaaS, Hadoop and so on. ...
CVE-2026-44024CRITICAL9.8Fluentd collects events from various data sources and writes them to files, RDBMS, NoSQL, IaaS, SaaS, Hadoop and so on. ...
CVE-2026-39179MEDIUM6.3A SQL injection vulnerability in SOGo before 5.12.7 allows authenticated users to execute arbitrary SQL statements via t...
CVE-2026-39178MEDIUM6.3A SQL injection vulnerability in SOGo before 5.12.7 allows authenticated users to execute arbitrary SQL statements via t...
CVE-2026-35552HIGH8.1In CAXperts UPVWebServices 2.4.2212.603 through 2.7.6 and UDiTH Portal 2026.0.0 through 2026.2.0, an authenticated remot...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now