2026 CVE Vulnerabilities

59,800 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-13781CRITICAL9.6Insufficient validation of untrusted input in Skia in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who...
CVE-2026-13780CRITICAL9.6Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 150.0.7871.47 allowed a remote attacker wh...
CVE-2026-13779HIGH8.1Use after free in Chromoting in Google Chrome on ChromeOS prior to 150.0.7871.47 allowed a remote attacker to execute ar...
CVE-2026-13778HIGH7.8Use after free in WebUSB in Google Chrome on Mac prior to 150.0.7871.47 allowed a local attacker to execute arbitrary co...
CVE-2026-13777HIGH8.8Insufficient validation of untrusted input in iOSWeb in Google Chrome on iOS prior to 150.0.7871.47 allowed a remote att...
CVE-2026-13776CRITICAL9.8Type Confusion in Dawn in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the rendere...
CVE-2026-13775CRITICAL9.8Use after free in GPU in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer...
CVE-2026-13774HIGH8.1Use after free in Extensions in Google Chrome prior to 150.0.7871.47 allowed an attacker who convinced a user to install...
CVE-2026-58450MEDIUM5.3Invoice Ninja through 5.13.26 contains an open redirect vulnerability in the client portal login that allows unauthentic...
CVE-2026-58449CRITICAL9.8txtai through 9.10.0, fixed in commit 11b32da, exposes an API /reindex endpoint whose function body parameter is resolve...
CVE-2026-58448HIGH7.1yudao-cloud before 2026.06 contains a broken access control vulnerability in the BPM module that allows any authenticate...
CVE-2026-58447HIGH7.1Invidious through 2.20260626.0, fixed in commit 77ad416, contains a broken object level authorization vulnerability that...
CVE-2026-58446MEDIUM6.9Presenton before 0.8.8-beta bundles an MCP server that, on server/Docker deployments configured with session authenticat...
CVE-2026-57585HIGH7.5MessagePack is the serializer implementation for Python msgpack.org. Prior to 1.2.1, there is an Out-of-bounds read/cras...
CVE-2026-57204MEDIUM6.5pypdf is a free and open-source pure-python PDF library. Prior to 6.13.3, a maliciously crafted PDF can cause DoS. An at...
CVE-2026-52868HIGH8.8An unauthenticated attacker can read worklist records from a directory outside the intended per-AE worklist storage area...
CVE-2026-52196HIGH7.5Buffer Overflow vulnerability in UTT nv518G nv518GV3v3.2.7-210919-161313 allows a remote attacker to cause a denial of s...
CVE-2026-50254HIGH8.7An unauthenticated remote attacker can repeatedly send a single crafted connection request to leak memory. Against store...
CVE-2026-50003CRITICAL9.8A malicious or compromised server can make a DCMTK client using bit-preserving C-GET storage mode write files outside th...
CVE-2026-37106CRITICAL9.8An issue in DokuWiki 2025-05-14b "Librarian" 56.2 allows a remote attacker to create an account via the register functio...
CVE-2026-35505HIGH8.7An unauthenticated remote attacker can repeatedly send crafted connection requests to leak memory. In single-process dep...
CVE-2026-11541CRITICAL9.8IBM CICS Transaction Gateway for Multiplatforms 9.1, 9.2, 9.3, and 10.1 IBM WebSphere Application Server 9.0, and 8.5 an...
CVE-2026-10585MEDIUM5.4A stored cross-site scripting vulnerability was identified in GitHub Enterprise Server that allowed an authenticated att...
CVE-2026-9132MEDIUM6.5A missing authorization vulnerability was identified in GitHub Enterprise Server that allowed an authenticated user to r...
CVE-2026-9106MEDIUM5.5A UI misrepresentation vulnerability was identified in GitHub Enterprise Server that allowed an OAuth application to gai...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now