2026 CVE Vulnerabilities

44,817 CVEs published in 2026.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2026-8732CRITICAL9.8The WP Maps Pro plugin for WordPress is vulnerable to Privilege Escalation via Administrator Account Creation in all ver...
CVE-2026-9967CRITICAL9.6Out of bounds write in GPU in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to potentially perform a s...
CVE-2026-9918CRITICAL9.6Inappropriate implementation in Tint in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to potentially p...
CVE-2026-9891CRITICAL9Use after free in Extensions in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the ...
CVE-2026-9886CRITICAL9.6Use after free in Base in Google Chrome on Mac prior to 148.0.7778.216 allowed a remote attacker to potentially perform ...
CVE-2026-9881CRITICAL9Use after free in Bluetooth in Google Chrome on Mac prior to 148.0.7778.216 allowed an attacker who convinced a user to ...
CVE-2026-9876CRITICAL9.6Use after free in WebGL in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attacker to potentially per...
CVE-2026-9875CRITICAL9.6Out of bounds read in WebGL in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attacker to potentially...
CVE-2026-9874CRITICAL9.6Use after free in Dawn in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to potentially perform a sandb...
CVE-2026-9872CRITICAL9.6Out of bounds write in GPU in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attacker to potentially ...
CVE-2026-8809CRITICAL9.8The Advanced Custom Fields: Extended plugin for WordPress is vulnerable to Privilege Escalation via Validation Bypass in...
CVE-2026-44881CRITICAL9.9Portainer Community Edition is a lightweight service delivery platform for containerized applications that can be used t...
CVE-2026-9645CRITICAL9.9Exposed methods allow authenticated users to create and execute arbitrary JavaScript code on the server. The scripts exe...
CVE-2026-46840CRITICAL10Vulnerability in Oracle REST Data Services (component: Backend-as-a-Service). Supported versions that are affected are ...
CVE-2026-46839CRITICAL9.9Vulnerability in Oracle REST Data Services (component: Core). Supported versions that are affected are 24.2.0-26.1.0. E...
CVE-2026-46833CRITICAL9Vulnerability in the Net Service component of Oracle Database Server. Supported versions that are affected are 23.4.0-2...
CVE-2026-46824CRITICAL9.9Vulnerability in the Oracle Universal Work Queue product of Oracle E-Business Suite (component: Work Provider Site Level...
CVE-2026-46822CRITICAL9.9Vulnerability in the Oracle iAssets product of Oracle E-Business Suite (component: Internal Operations). Supported vers...
CVE-2026-46819CRITICAL9.1Vulnerability in the Oracle Internet Procurement Connector product of Oracle E-Business Suite (component: Internal Opera...
CVE-2026-46817CRITICAL9.8Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission). Supported versi...
CVE-2026-46775CRITICAL9.9Vulnerability in Oracle REST Data Services (component: Core). Supported versions that are affected are 24.2.0-26.1.0. E...
CVE-2026-45288CRITICAL9.8Marten is a .NET Transactional Document DB and Event Store on PostgreSQL. Prior to 8.36.1, Marten's full-text search API...
CVE-2026-34311CRITICAL9.8Vulnerability in the Oracle Hospitality OPERA 5 Property Services product of Oracle Hospitality Applications (component:...
CVE-2026-9037CRITICAL9.3A firmware update mechanism in the affected charging controller fails to validate the authenticity of firmware packages ...
CVE-2026-45039CRITICAL9.8RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.2, the internode RPC layer authenticate...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now