2026 CVE Vulnerabilities

57,138 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-50280MEDIUM6Craft CMS is a content management system (CMS). In versions 5.0.0-RC1 and above prior to 5.9.21, the EntriesController::...
CVE-2026-50279HIGH7.6Craft CMS is a content management system (CMS). IN versions 5.0.0-RC1 and above prior to 5.9.21, theEntriesController::a...
CVE-2026-55790HIGH7.4Craft CMS is a content management system (CMS). In versions 5.0.0-RC1 through 5.9.22 and 4.0.0-RC1 through 4.17.15, an a...
CVE-2026-50284HIGH7.1Craft CMS is a content management system (CMS). In versions 5.0.0-RC1 through 5.9.21 and 4.0.0-RC1 through 4.17.14, theA...
CVE-2026-50283MEDIUM5.3Craft CMS is a content management system (CMS). Versions 5.0.0-RC1 through 5.9.20, and 4.0.0-RC1 through 4.17.13 contain...
CVE-2026-14440HIGH7.6Description: To issue and renew TLS certificates on behalf of customers, Cloudflare's Universal SSL feature automati...
CVE-2026-14439CRITICAL9.4A path traversal vulnerability exists in the Git Service component shared by Altium Enterprise Server and Altium 365. Th...
CVE-2026-14432HIGH8.8Use after free in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to execute arbitrary code inside ...
CVE-2026-14431HIGH8.8Type Confusion in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to execute arbitrary code inside ...
CVE-2026-14430HIGH8.8Integer overflow in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to execute arbitrary code insid...
CVE-2026-14429HIGH8.3Insufficient validation of untrusted input in Skia in Google Chrome prior to 150.0.7871.46 allowed a remote attacker who...
CVE-2026-14428HIGH8.3Insufficient validation of untrusted input in Dawn in Google Chrome on Android prior to 150.0.7871.46 allowed a remote a...
CVE-2026-14427HIGH8.3Heap buffer overflow in Skia in Google Chrome prior to 150.0.7871.46 allowed a remote attacker who had compromised the r...
CVE-2026-14426HIGH7.5Use after free in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker who convinced a user to engage in...
CVE-2026-14425CRITICAL9.6Use after free in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandb...
CVE-2026-14424CRITICAL9.6Use after free in Dawn in Google Chrome on Mac prior to 150.0.7871.46 allowed a remote attacker to potentially perform a...
CVE-2026-14423CRITICAL9.6Type Confusion in Tint in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbo...
CVE-2026-14422HIGH8.8Out of bounds read and write in Tint in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially pe...
CVE-2026-14421MEDIUM6.5Uninitialized Use in Dawn in Google Chrome on ChromeOS prior to 150.0.7871.46 allowed a remote attacker to obtain potent...
CVE-2026-14420CRITICAL9.6Out of bounds read and write in Dawn in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially pe...
CVE-2026-14419CRITICAL9.6Use after free in Skia in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbo...
CVE-2026-14418MEDIUM4.3Uninitialized Use in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to leak cross-origin data v...
CVE-2026-14417CRITICAL9.6Use after free in Dawn in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbo...
CVE-2026-14416CRITICAL9.6Out of bounds read in Dawn in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sa...
CVE-2026-14415HIGH8.8Inappropriate implementation in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker who convinced a use...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now