2026 CVE Vulnerabilities
57,138 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-50280 | MEDIUM | 6 | 0.3% | Jul 2, 2026 | Craft CMS is a content management system (CMS). In versions 5.0.0-RC1 and above prior to 5.9.21, the EntriesController::... |
| CVE-2026-50279 | HIGH | 7.6 | 0.2% | Jul 2, 2026 | Craft CMS is a content management system (CMS). IN versions 5.0.0-RC1 and above prior to 5.9.21, theEntriesController::a... |
| CVE-2026-55790 | HIGH | 7.4 | 0.3% | Jul 1, 2026 | Craft CMS is a content management system (CMS). In versions 5.0.0-RC1 through 5.9.22 and 4.0.0-RC1 through 4.17.15, an a... |
| CVE-2026-50284 | HIGH | 7.1 | 0.2% | Jul 1, 2026 | Craft CMS is a content management system (CMS). In versions 5.0.0-RC1 through 5.9.21 and 4.0.0-RC1 through 4.17.14, theA... |
| CVE-2026-50283 | MEDIUM | 5.3 | 0.3% | Jul 1, 2026 | Craft CMS is a content management system (CMS). Versions 5.0.0-RC1 through 5.9.20, and 4.0.0-RC1 through 4.17.13 contain... |
| CVE-2026-14440 | HIGH | 7.6 | 0.1% | Jul 1, 2026 | Description: To issue and renew TLS certificates on behalf of customers, Cloudflare's Universal SSL feature automati... |
| CVE-2026-14439 | CRITICAL | 9.4 | 0.6% | Jul 1, 2026 | A path traversal vulnerability exists in the Git Service component shared by Altium Enterprise Server and Altium 365. Th... |
| CVE-2026-14432 | HIGH | 8.8 | 0.2% | Jul 1, 2026 | Use after free in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to execute arbitrary code inside ... |
| CVE-2026-14431 | HIGH | 8.8 | 0.2% | Jul 1, 2026 | Type Confusion in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to execute arbitrary code inside ... |
| CVE-2026-14430 | HIGH | 8.8 | 0.3% | Jul 1, 2026 | Integer overflow in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to execute arbitrary code insid... |
| CVE-2026-14429 | HIGH | 8.3 | 0.2% | Jul 1, 2026 | Insufficient validation of untrusted input in Skia in Google Chrome prior to 150.0.7871.46 allowed a remote attacker who... |
| CVE-2026-14428 | HIGH | 8.3 | 0.2% | Jul 1, 2026 | Insufficient validation of untrusted input in Dawn in Google Chrome on Android prior to 150.0.7871.46 allowed a remote a... |
| CVE-2026-14427 | HIGH | 8.3 | 0.2% | Jul 1, 2026 | Heap buffer overflow in Skia in Google Chrome prior to 150.0.7871.46 allowed a remote attacker who had compromised the r... |
| CVE-2026-14426 | HIGH | 7.5 | 0.2% | Jul 1, 2026 | Use after free in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker who convinced a user to engage in... |
| CVE-2026-14425 | CRITICAL | 9.6 | 0.2% | Jul 1, 2026 | Use after free in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandb... |
| CVE-2026-14424 | CRITICAL | 9.6 | 0.2% | Jul 1, 2026 | Use after free in Dawn in Google Chrome on Mac prior to 150.0.7871.46 allowed a remote attacker to potentially perform a... |
| CVE-2026-14423 | CRITICAL | 9.6 | 0.2% | Jul 1, 2026 | Type Confusion in Tint in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbo... |
| CVE-2026-14422 | HIGH | 8.8 | 0.2% | Jul 1, 2026 | Out of bounds read and write in Tint in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially pe... |
| CVE-2026-14421 | MEDIUM | 6.5 | 0.2% | Jul 1, 2026 | Uninitialized Use in Dawn in Google Chrome on ChromeOS prior to 150.0.7871.46 allowed a remote attacker to obtain potent... |
| CVE-2026-14420 | CRITICAL | 9.6 | 0.2% | Jul 1, 2026 | Out of bounds read and write in Dawn in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially pe... |
| CVE-2026-14419 | CRITICAL | 9.6 | 0.2% | Jul 1, 2026 | Use after free in Skia in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbo... |
| CVE-2026-14418 | MEDIUM | 4.3 | 0.2% | Jul 1, 2026 | Uninitialized Use in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to leak cross-origin data v... |
| CVE-2026-14417 | CRITICAL | 9.6 | 0.2% | Jul 1, 2026 | Use after free in Dawn in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbo... |
| CVE-2026-14416 | CRITICAL | 9.6 | 0.2% | Jul 1, 2026 | Out of bounds read in Dawn in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sa... |
| CVE-2026-14415 | HIGH | 8.8 | 0.2% | Jul 1, 2026 | Inappropriate implementation in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker who convinced a use... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now