2026 CVE Vulnerabilities

57,111 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-57991HIGH7.4Improper link resolution before file access ('link following') in Microsoft Edge (Chromium-based) allows an unauthorized...
CVE-2026-57988HIGH7.1Relative path traversal in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a networ...
CVE-2026-57987MEDIUM6.5Server-side request forgery (ssrf) in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofin...
CVE-2026-57986HIGH7.5Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
CVE-2026-57985HIGH8.8Improper input validation in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a netw...
CVE-2026-57984HIGH7.5Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
CVE-2026-57983CRITICAL10Improper authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to bypass a security feature o...
CVE-2026-57981HIGH8.8Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
CVE-2026-57977HIGH7.1Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Edge (Chromium-based) ...
CVE-2026-57975HIGH7.5Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized ...
CVE-2026-57974HIGH8.8Integer overflow or wraparound in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a...
CVE-2026-56646MEDIUM6.5Exposure of sensitive information to an unauthorized actor in Microsoft Edge (Chromium-based) allows an unauthorized att...
CVE-2026-56645HIGH8.8Heap-based buffer overflow in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a net...
CVE-2026-55945MEDIUM4.2Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Edge (Chromium-...
CVE-2026-45489MEDIUM6.5Microsoft Edge (Chromium-based) Spoofing Vulnerability
CVE-2026-45488MEDIUM5.9User interface (ui) misrepresentation of critical information in Microsoft Edge (Chromium-based) allows an unauthorized ...
CVE-2026-28744HIGH8.1Gitea versions up to and including 1.26.1 allow Git smart HTTP requests authenticated with bearer tokens to bypass repos...
CVE-2026-28740HIGH7.1Gitea versions up to and including 1.26.2 allow Git LFS object reuse to authorize private source objects for users who h...
CVE-2026-28737HIGH8.7Gitea versions from 1.25.0 before 1.26.0 allow stored cross-site scripting through the extensionsRequired field in glTF ...
CVE-2026-28705MEDIUM5.3Gitea versions before 1.25.5 use release tag names and asset names as filesystem path components when dumping release as...
CVE-2026-28699HIGH8.1Gitea versions up to and including 1.26.1 allow OAuth2 access token scope enforcement to be bypassed through HTTP Basic ...
CVE-2026-27783MEDIUM4.3Gitea versions up to and including 1.26.1 do not enforce repository-unit authorization on issue-template API endpoints.
CVE-2026-27780CRITICAL9.8Gitea versions before 1.26.0 do not fail closed on bufio.Scanner errors while processing pre-receive hook input, allowin...
CVE-2026-27779HIGH7.5Gitea versions before 1.25.5 accept malformed or injected forwarded-proto values when detecting public URLs, allowing sp...
CVE-2026-27775HIGH8.8Gitea 1.25.5 caches a branch-specific write-permission result across multiple refs in one pre-receive hook session, allo...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now