2026 CVE Vulnerabilities
57,111 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-57991 | HIGH | 7.4 | 0.8% | Jul 3, 2026 | Improper link resolution before file access ('link following') in Microsoft Edge (Chromium-based) allows an unauthorized... |
| CVE-2026-57988 | HIGH | 7.1 | 0.5% | Jul 3, 2026 | Relative path traversal in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a networ... |
| CVE-2026-57987 | MEDIUM | 6.5 | 0.6% | Jul 3, 2026 | Server-side request forgery (ssrf) in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofin... |
| CVE-2026-57986 | HIGH | 7.5 | 0.4% | Jul 3, 2026 | Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. |
| CVE-2026-57985 | HIGH | 8.8 | 0.4% | Jul 3, 2026 | Improper input validation in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a netw... |
| CVE-2026-57984 | HIGH | 7.5 | 0.4% | Jul 3, 2026 | Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. |
| CVE-2026-57983 | CRITICAL | 10 | 0.5% | Jul 3, 2026 | Improper authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to bypass a security feature o... |
| CVE-2026-57981 | HIGH | 8.8 | 0.6% | Jul 3, 2026 | Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. |
| CVE-2026-57977 | HIGH | 7.1 | 0.4% | Jul 3, 2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Edge (Chromium-based) ... |
| CVE-2026-57975 | HIGH | 7.5 | 0.4% | Jul 3, 2026 | Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized ... |
| CVE-2026-57974 | HIGH | 8.8 | 0.6% | Jul 3, 2026 | Integer overflow or wraparound in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a... |
| CVE-2026-56646 | MEDIUM | 6.5 | 0.7% | Jul 3, 2026 | Exposure of sensitive information to an unauthorized actor in Microsoft Edge (Chromium-based) allows an unauthorized att... |
| CVE-2026-56645 | HIGH | 8.8 | 0.6% | Jul 3, 2026 | Heap-based buffer overflow in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a net... |
| CVE-2026-55945 | MEDIUM | 4.2 | 0.1% | Jul 3, 2026 | Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Edge (Chromium-... |
| CVE-2026-45489 | MEDIUM | 6.5 | 0.5% | Jul 3, 2026 | Microsoft Edge (Chromium-based) Spoofing Vulnerability |
| CVE-2026-45488 | MEDIUM | 5.9 | 0.3% | Jul 3, 2026 | User interface (ui) misrepresentation of critical information in Microsoft Edge (Chromium-based) allows an unauthorized ... |
| CVE-2026-28744 | HIGH | 8.1 | 0.3% | Jul 3, 2026 | Gitea versions up to and including 1.26.1 allow Git smart HTTP requests authenticated with bearer tokens to bypass repos... |
| CVE-2026-28740 | HIGH | 7.1 | 0.3% | Jul 3, 2026 | Gitea versions up to and including 1.26.2 allow Git LFS object reuse to authorize private source objects for users who h... |
| CVE-2026-28737 | HIGH | 8.7 | 0.3% | Jul 3, 2026 | Gitea versions from 1.25.0 before 1.26.0 allow stored cross-site scripting through the extensionsRequired field in glTF ... |
| CVE-2026-28705 | MEDIUM | 5.3 | 0.2% | Jul 3, 2026 | Gitea versions before 1.25.5 use release tag names and asset names as filesystem path components when dumping release as... |
| CVE-2026-28699 | HIGH | 8.1 | 0.6% | Jul 3, 2026 | Gitea versions up to and including 1.26.1 allow OAuth2 access token scope enforcement to be bypassed through HTTP Basic ... |
| CVE-2026-27783 | MEDIUM | 4.3 | 0.3% | Jul 3, 2026 | Gitea versions up to and including 1.26.1 do not enforce repository-unit authorization on issue-template API endpoints. |
| CVE-2026-27780 | CRITICAL | 9.8 | 0.2% | Jul 3, 2026 | Gitea versions before 1.26.0 do not fail closed on bufio.Scanner errors while processing pre-receive hook input, allowin... |
| CVE-2026-27779 | HIGH | 7.5 | 0.2% | Jul 3, 2026 | Gitea versions before 1.25.5 accept malformed or injected forwarded-proto values when detecting public URLs, allowing sp... |
| CVE-2026-27775 | HIGH | 8.8 | 0.2% | Jul 3, 2026 | Gitea 1.25.5 caches a branch-specific write-permission result across multiple refs in one pre-receive hook session, allo... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now