2026 CVE Vulnerabilities
59,458 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-13889 | MEDIUM | 6.5 | 0.2% | Jun 30, 2026 | Side-channel information leakage in WebAuthentication in Google Chrome on iOS prior to 150.0.7871.47 allowed a remote at... |
| CVE-2026-13888 | HIGH | 8.8 | 0.3% | Jun 30, 2026 | Use after free in Extensions in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to execute arbitrary code... |
| CVE-2026-13887 | MEDIUM | 6.5 | 0.2% | Jun 30, 2026 | Inappropriate implementation in NFC in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker who had... |
| CVE-2026-13886 | MEDIUM | 6.5 | 0.2% | Jun 30, 2026 | Insufficient policy enforcement in Isolated Web Apps in Google Chrome prior to 150.0.7871.47 allowed a remote attacker t... |
| CVE-2026-13885 | HIGH | 8.8 | 0.3% | Jun 30, 2026 | Use after free in Skia in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker to execute arbitrary... |
| CVE-2026-13884 | HIGH | 8.8 | 0.2% | Jun 30, 2026 | Integer overflow in Chromecast in Google Chrome prior to 150.0.7871.47 allowed a local attacker to execute arbitrary cod... |
| CVE-2026-13883 | CRITICAL | 9.6 | 0.2% | Jun 30, 2026 | Type Confusion in ANGLE in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to potentially perform a sandb... |
| CVE-2026-13882 | CRITICAL | 9.6 | 0.2% | Jun 30, 2026 | Race in USB in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process t... |
| CVE-2026-13881 | MEDIUM | 6.5 | 0.2% | Jun 30, 2026 | Inappropriate implementation in WebAppInstalls in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to bypa... |
| CVE-2026-13880 | CRITICAL | 9.6 | 0.2% | Jun 30, 2026 | Use after free in USB in Google Chrome on Mac prior to 150.0.7871.47 allowed a remote attacker who had compromised the r... |
| CVE-2026-13879 | MEDIUM | 6.5 | 0.1% | Jun 30, 2026 | Use after free in Bluetooth in Google Chrome prior to 150.0.7871.47 allowed an attacker on the local network segment to ... |
| CVE-2026-13878 | CRITICAL | 9.6 | 0.2% | Jun 30, 2026 | Use after free in Bluetooth in Google Chrome on Mac prior to 150.0.7871.47 allowed a remote attacker who had compromised... |
| CVE-2026-13877 | MEDIUM | 5.3 | 0.3% | Jun 30, 2026 | Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 150.0.7871.47 allowed a remote attacker wh... |
| CVE-2026-13876 | MEDIUM | 6.5 | 0.2% | Jun 30, 2026 | Inappropriate implementation in Network in Google Chrome prior to 150.0.7871.47 allowed an attacker in a privileged netw... |
| CVE-2026-13875 | MEDIUM | 5.3 | 0.3% | Jun 30, 2026 | Insufficient validation of untrusted input in GPU in Google Chrome on Windows prior to 150.0.7871.47 allowed a remote at... |
| CVE-2026-13874 | MEDIUM | 5.3 | 0.2% | Jun 30, 2026 | Race in DataTransfer in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to obtain potentially sensitive i... |
| CVE-2026-13873 | MEDIUM | 6.5 | 0.3% | Jun 30, 2026 | Out of bounds read in Layout in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to obtain potentially sen... |
| CVE-2026-13872 | CRITICAL | 9.1 | 0.2% | Jun 30, 2026 | Insufficient validation of untrusted input in WebAppInstalls in Google Chrome on Android prior to 150.0.7871.47 allowed ... |
| CVE-2026-13871 | MEDIUM | 6.5 | 0.3% | Jun 30, 2026 | Insufficient policy enforcement in GuestView in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had c... |
| CVE-2026-13870 | HIGH | 8.8 | 0.3% | Jun 30, 2026 | Use after free in WebView in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker to execute arbitr... |
| CVE-2026-13869 | CRITICAL | 9.6 | 0.3% | Jun 30, 2026 | Use after free in Device in Google Chrome on Windows prior to 150.0.7871.47 allowed a remote attacker who had compromise... |
| CVE-2026-13868 | MEDIUM | 6.5 | 0.2% | Jun 30, 2026 | Inappropriate implementation in Network in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker who... |
| CVE-2026-13867 | MEDIUM | 4.3 | 0.2% | Jun 30, 2026 | Inappropriate implementation in Geolocation in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to perform... |
| CVE-2026-13866 | MEDIUM | 6.5 | 0.3% | Jun 30, 2026 | Inappropriate implementation in Input in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker who h... |
| CVE-2026-13865 | MEDIUM | 4.3 | 0.2% | Jun 30, 2026 | Insufficient validation of untrusted input in Enterprise in Google Chrome prior to 150.0.7871.47 allowed a remote attack... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now