2026 CVE Vulnerabilities
44,807 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-11052 | CRITICAL | 9.6 | 0.3% | Jun 4, 2026 | Type Confusion in GPU in Google Chrome on Windows prior to 149.0.7827.53 allowed a remote attacker who had compromised t... |
| CVE-2026-11047 | CRITICAL | 9.6 | 0.3% | Jun 4, 2026 | Inappropriate implementation in Base in Google Chrome on Windows prior to 149.0.7827.53 allowed a remote attacker who ha... |
| CVE-2026-11043 | CRITICAL | 9.6 | 0.3% | Jun 4, 2026 | Out of bounds write in ANGLE in Google Chrome on Mac prior to 149.0.7827.53 allowed a remote attacker who had compromise... |
| CVE-2026-11037 | CRITICAL | 9.6 | 0.3% | Jun 4, 2026 | Out of bounds write in Codecs in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially perform a... |
| CVE-2026-11029 | CRITICAL | 9.6 | 0.2% | Jun 4, 2026 | Insufficient validation of untrusted input in Drag and Drop in Google Chrome on Android prior to 149.0.7827.53 allowed a... |
| CVE-2026-11021 | CRITICAL | 9.6 | 0.3% | Jun 4, 2026 | Insufficient validation of untrusted input in GPU in Google Chrome on Windows prior to 149.0.7827.53 allowed a remote at... |
| CVE-2026-11009 | CRITICAL | 9.6 | 0.3% | Jun 4, 2026 | Use after free in USB in Google Chrome on Windows prior to 149.0.7827.53 allowed a remote attacker to potentially perfor... |
| CVE-2026-11002 | CRITICAL | 9.6 | 0.3% | Jun 4, 2026 | Use after free in Autofill in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the ren... |
| CVE-2026-10990 | CRITICAL | 9.6 | 0.3% | Jun 4, 2026 | Use after free in Glic in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the rendere... |
| CVE-2026-10983 | CRITICAL | 9.6 | 0.3% | Jun 4, 2026 | Insufficient validation of untrusted input in Dawn in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to ... |
| CVE-2026-10974 | CRITICAL | 9.6 | 0.3% | Jun 4, 2026 | Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to... |
| CVE-2026-10972 | CRITICAL | 9.6 | 0.3% | Jun 4, 2026 | Use after free in Ozone in Google Chrome on Linux prior to 149.0.7827.53 allowed a remote attacker to potentially perfor... |
| CVE-2026-10971 | CRITICAL | 9.6 | 0.3% | Jun 4, 2026 | Insufficient validation of untrusted input in Printing in Google Chrome on Windows prior to 149.0.7827.53 allowed a remo... |
| CVE-2026-10966 | CRITICAL | 9.6 | 0.3% | Jun 4, 2026 | Inappropriate implementation in Codecs in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially ... |
| CVE-2026-10931 | CRITICAL | 9.6 | 0.3% | Jun 4, 2026 | Use after free in FileSystem in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially perform a ... |
| CVE-2026-10892 | CRITICAL | 9.6 | 0.3% | Jun 4, 2026 | Out of bounds write in GPU in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker to potentially p... |
| CVE-2026-10886 | CRITICAL | 9.6 | 0.3% | Jun 4, 2026 | Use after free in FileSystem in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially perform a ... |
| CVE-2026-10881 | CRITICAL | 9.6 | 0.4% | Jun 4, 2026 | Out of bounds read and write in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially p... |
| CVE-2026-50292 | CRITICAL | 9.8 | 0.5% | Jun 4, 2026 | In libinput before 1.30.4 and 1.31.x before 1.31.3, libinput-device-group unescaped phys output can inject udev properti... |
| CVE-2026-48040 | CRITICAL | 9.1 | 0.2% | Jun 4, 2026 | The netty incubator codec.bhttp is a java language binary http parser. The library implements Oblivious HTTP (RFC 9458) ... |
| CVE-2026-25550 | CRITICAL | 9.8 | 0.7% | Jun 4, 2026 | Seagull Software BarTender 2010, 2016, and 2019 contain an unauthenticated remote code execution vulnerability in the .N... |
| CVE-2026-10880 | CRITICAL | 9.8 | 0.4% | Jun 4, 2026 | OSNexus QuantaStor SDS Manager is vulnerable to SQL injection in the login endpoint. The username field is not properly ... |
| CVE-2026-50076 | CRITICAL | 9.1 | 0.5% | Jun 4, 2026 | Deserialization of Untrusted Data in the Java replace-resolve path in Apache Fory fory-core Java SDK before 1.1.0 on Jav... |
| CVE-2026-43986 | CRITICAL | 9.9 | 0.3% | Jun 4, 2026 | Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Versions prior to 2.17.1 expose a public ... |
| CVE-2026-36182 | CRITICAL | 9.8 | 0.2% | Jun 4, 2026 | GNCC GP5 v7.1.76 was discovered to utilize a weak hashing algorithm to protect the root password, possibly allowing atta... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now