2026 CVE Vulnerabilities
59,432 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-14013 | MEDIUM | 4.3 | 0.2% | Jun 30, 2026 | Inappropriate implementation in SVG in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to perform UI spoo... |
| CVE-2026-14012 | MEDIUM | 5.3 | 0.2% | Jun 30, 2026 | Side-channel information leakage in CSS in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to obtain pote... |
| CVE-2026-14011 | HIGH | 8.1 | 0.2% | Jun 30, 2026 | Out of bounds read in SurfaceCapture in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to perform an out... |
| CVE-2026-14010 | MEDIUM | 6.5 | 0.3% | Jun 30, 2026 | Uninitialized Use in Codecs in Google Chrome on Windows prior to 150.0.7871.47 allowed a remote attacker to obtain poten... |
| CVE-2026-14009 | HIGH | 8.8 | 0.2% | Jun 30, 2026 | Inappropriate implementation in Passwords in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to potential... |
| CVE-2026-14008 | MEDIUM | 6.5 | 0.2% | Jun 30, 2026 | Uninitialized Use in WebXR in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker to obtain potent... |
| CVE-2026-14007 | MEDIUM | 6.5 | 0.2% | Jun 30, 2026 | Insufficient policy enforcement in PermissionsPolicy in Google Chrome prior to 150.0.7871.47 allowed a remote attacker t... |
| CVE-2026-14006 | HIGH | 8.8 | 0.2% | Jun 30, 2026 | Use after free in Navigation in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to execute arbitrary code... |
| CVE-2026-14005 | HIGH | 8.8 | 0.2% | Jun 30, 2026 | Use after free in Omnibox in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker who convinced a u... |
| CVE-2026-14004 | MEDIUM | 6.5 | 0.2% | Jun 30, 2026 | Inappropriate implementation in CSS in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to leak cross-orig... |
| CVE-2026-14003 | MEDIUM | 4.3 | 0.1% | Jun 30, 2026 | Insufficient policy enforcement in Extensions in Google Chrome prior to 150.0.7871.47 allowed an attacker who convinced ... |
| CVE-2026-14002 | MEDIUM | 6.5 | 0.2% | Jun 30, 2026 | Inappropriate implementation in Geolocation in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had co... |
| CVE-2026-14001 | MEDIUM | 6.1 | 0.2% | Jun 30, 2026 | Inappropriate implementation in Network in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to inject arbi... |
| CVE-2026-14000 | MEDIUM | 6.1 | 0.2% | Jun 30, 2026 | Inappropriate implementation in XML in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to inject arbitrar... |
| CVE-2026-13999 | MEDIUM | 4.3 | 0.1% | Jun 30, 2026 | Insufficient validation of untrusted input in Extensions in Google Chrome prior to 150.0.7871.47 allowed an attacker who... |
| CVE-2026-13998 | MEDIUM | 4.2 | 0.2% | Jun 30, 2026 | Incorrect security UI in File Input in Google Chrome on Mac prior to 150.0.7871.47 allowed a remote attacker who convinc... |
| CVE-2026-13997 | MEDIUM | 4.2 | 0.2% | Jun 30, 2026 | Incorrect security UI in Extensions in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker who con... |
| CVE-2026-13996 | MEDIUM | 6.5 | 0.2% | Jun 30, 2026 | Inappropriate implementation in Permissions in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to perform... |
| CVE-2026-13995 | MEDIUM | 4.3 | 0.2% | Jun 30, 2026 | Insufficient validation of untrusted input in Autofill in Google Chrome on Android prior to 150.0.7871.47 allowed a remo... |
| CVE-2026-13994 | MEDIUM | 4.3 | 0.2% | Jun 30, 2026 | Inappropriate implementation in Credential Management in Google Chrome on Android prior to 150.0.7871.47 allowed a remot... |
| CVE-2026-13993 | MEDIUM | 4.2 | 0.2% | Jun 30, 2026 | Incorrect security UI in WebAppInstalls in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who convinced ... |
| CVE-2026-13992 | MEDIUM | 4.2 | 0.2% | Jun 30, 2026 | Inappropriate implementation in UI in Google Chrome on Mac prior to 150.0.7871.47 allowed a remote attacker who convince... |
| CVE-2026-13991 | MEDIUM | 4.3 | 0.2% | Jun 30, 2026 | Insufficient validation of untrusted input in Chrome for iOS in Google Chrome on iOS prior to 150.0.7871.47 allowed a re... |
| CVE-2026-13990 | MEDIUM | 6.5 | 0.2% | Jun 30, 2026 | Insufficient validation of untrusted input in DataTransfer in Google Chrome on Windows prior to 150.0.7871.47 allowed a ... |
| CVE-2026-13989 | MEDIUM | 5.3 | 0.2% | Jun 30, 2026 | Inappropriate implementation in PageInfo in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compr... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now