2026 CVE Vulnerabilities
59,800 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-13781 | CRITICAL | 9.6 | 0.2% | Jun 30, 2026 | Insufficient validation of untrusted input in Skia in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who... |
| CVE-2026-13780 | CRITICAL | 9.6 | 0.2% | Jun 30, 2026 | Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 150.0.7871.47 allowed a remote attacker wh... |
| CVE-2026-13779 | HIGH | 8.1 | 0.2% | Jun 30, 2026 | Use after free in Chromoting in Google Chrome on ChromeOS prior to 150.0.7871.47 allowed a remote attacker to execute ar... |
| CVE-2026-13778 | HIGH | 7.8 | 0.2% | Jun 30, 2026 | Use after free in WebUSB in Google Chrome on Mac prior to 150.0.7871.47 allowed a local attacker to execute arbitrary co... |
| CVE-2026-13777 | HIGH | 8.8 | 0.2% | Jun 30, 2026 | Insufficient validation of untrusted input in iOSWeb in Google Chrome on iOS prior to 150.0.7871.47 allowed a remote att... |
| CVE-2026-13776 | CRITICAL | 9.8 | 0.2% | Jun 30, 2026 | Type Confusion in Dawn in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the rendere... |
| CVE-2026-13775 | CRITICAL | 9.8 | 0.2% | Jun 30, 2026 | Use after free in GPU in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer... |
| CVE-2026-13774 | HIGH | 8.1 | 0.2% | Jun 30, 2026 | Use after free in Extensions in Google Chrome prior to 150.0.7871.47 allowed an attacker who convinced a user to install... |
| CVE-2026-58450 | MEDIUM | 5.3 | 0.2% | Jun 30, 2026 | Invoice Ninja through 5.13.26 contains an open redirect vulnerability in the client portal login that allows unauthentic... |
| CVE-2026-58449 | CRITICAL | 9.8 | 0.7% | Jun 30, 2026 | txtai through 9.10.0, fixed in commit 11b32da, exposes an API /reindex endpoint whose function body parameter is resolve... |
| CVE-2026-58448 | HIGH | 7.1 | 0.2% | Jun 30, 2026 | yudao-cloud before 2026.06 contains a broken access control vulnerability in the BPM module that allows any authenticate... |
| CVE-2026-58447 | HIGH | 7.1 | 0.2% | Jun 30, 2026 | Invidious through 2.20260626.0, fixed in commit 77ad416, contains a broken object level authorization vulnerability that... |
| CVE-2026-58446 | MEDIUM | 6.9 | 0.4% | Jun 30, 2026 | Presenton before 0.8.8-beta bundles an MCP server that, on server/Docker deployments configured with session authenticat... |
| CVE-2026-57585 | HIGH | 7.5 | 0.3% | Jun 30, 2026 | MessagePack is the serializer implementation for Python msgpack.org. Prior to 1.2.1, there is an Out-of-bounds read/cras... |
| CVE-2026-57204 | MEDIUM | 6.5 | 0.3% | Jun 30, 2026 | pypdf is a free and open-source pure-python PDF library. Prior to 6.13.3, a maliciously crafted PDF can cause DoS. An at... |
| CVE-2026-52868 | HIGH | 8.8 | 0.4% | Jun 30, 2026 | An unauthenticated attacker can read worklist records from a directory outside the intended per-AE worklist storage area... |
| CVE-2026-52196 | HIGH | 7.5 | 0.5% | Jun 30, 2026 | Buffer Overflow vulnerability in UTT nv518G nv518GV3v3.2.7-210919-161313 allows a remote attacker to cause a denial of s... |
| CVE-2026-50254 | HIGH | 8.7 | 0.4% | Jun 30, 2026 | An unauthenticated remote attacker can repeatedly send a single crafted connection request to leak memory. Against store... |
| CVE-2026-50003 | CRITICAL | 9.8 | 0.4% | Jun 30, 2026 | A malicious or compromised server can make a DCMTK client using bit-preserving C-GET storage mode write files outside th... |
| CVE-2026-37106 | CRITICAL | 9.8 | 0.5% | Jun 30, 2026 | An issue in DokuWiki 2025-05-14b "Librarian" 56.2 allows a remote attacker to create an account via the register functio... |
| CVE-2026-35505 | HIGH | 8.7 | 0.4% | Jun 30, 2026 | An unauthenticated remote attacker can repeatedly send crafted connection requests to leak memory. In single-process dep... |
| CVE-2026-11541 | CRITICAL | 9.8 | 0.3% | Jun 30, 2026 | IBM CICS Transaction Gateway for Multiplatforms 9.1, 9.2, 9.3, and 10.1 IBM WebSphere Application Server 9.0, and 8.5 an... |
| CVE-2026-10585 | MEDIUM | 5.4 | 0.3% | Jun 30, 2026 | A stored cross-site scripting vulnerability was identified in GitHub Enterprise Server that allowed an authenticated att... |
| CVE-2026-9132 | MEDIUM | 6.5 | 0.3% | Jun 30, 2026 | A missing authorization vulnerability was identified in GitHub Enterprise Server that allowed an authenticated user to r... |
| CVE-2026-9106 | MEDIUM | 5.5 | 0.3% | Jun 30, 2026 | A UI misrepresentation vulnerability was identified in GitHub Enterprise Server that allowed an OAuth application to gai... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now