2026 CVE Vulnerabilities

64,909 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-87453MEDIUM5.3Confused deputy in BackgroundFetch in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised...
CVE-2026-87449MEDIUM4.3Cross-site request forgery in DeviceBoundSessionCredentials in Google Chrome prior to 153.0.8010.36 allowed a remote att...
CVE-2026-87447MEDIUM6.5Incorrect authorization in Network in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social e...
CVE-2026-87446MEDIUM6.5Incomplete cleanup in Extensions in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social eng...
CVE-2026-87445MEDIUM5.4UI misrepresentation in Session in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to spoof UI elements v...
CVE-2026-87443MEDIUM6.5Missing authorization in Actor in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to obtain sensitive inf...
CVE-2026-87441MEDIUM6.5Missing authorization in Downloads in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass system ac...
CVE-2026-87439MEDIUM5.3Information leak in ServiceWorker in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised ...
CVE-2026-87437MEDIUM6.5Information leak in Frames in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to leak sensitive informati...
CVE-2026-87436MEDIUM6.5Incomplete cleanup in Browser in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engine...
CVE-2026-87435MEDIUM5.3Information leak in ControlledFrame in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromise...
CVE-2026-87432MEDIUM4.2Incorrect authorization in Navigation in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromi...
CVE-2026-87429MEDIUM6.5Missing authorization in ServiceWorker in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had comprom...
CVE-2026-53937MEDIUM6.2MCP Kotlin SDK is the Kotlin Multiplatform software development kit for the Model Context Protocol. In versions 0.7.0 th...
CVE-2026-53639MEDIUM6.3Sylius is an Open Source eCommerce Framework on Symfony. Starting in version 2.0.0 and prior to version 2.0.18, 2.1.15, ...
CVE-2026-53638MEDIUM4.3Sylius is an Open Source eCommerce Framework on Symfony. Starting in version 2.0.0 and prior to version 2.0.18, 2.1.15, ...
CVE-2026-53637MEDIUM6.5Sylius is an Open Source eCommerce Framework on Symfony. Versions 2.0.0 through 2.0.17, 2.1.0 through 2.1.14, and 2.2.0 ...
CVE-2026-47680MEDIUM5.3The source-controller is a Kubernetes operator, specialised in artifacts acquisition from external sources such as Git, ...
CVE-2026-18090MEDIUM6.1A flaw was found in gdk-pixbuf. This vulnerability allows a remote attacker to cause a heap out-of-bounds read by provid...
CVE-2026-86996MEDIUM5.4n8n is an open source workflow automation platform. Prior to 2.37.7 and 2.38.2, the workflow setting named This workflow...
CVE-2026-86995MEDIUM4.3n8n is an open source workflow automation platform. Prior to 1.123.76, 2.37.7, and 2.38.2, the Git node validated the re...
CVE-2026-86994MEDIUM4.3n8n is an open source workflow automation platform. Prior to 1.123.76, 2.37.7, and 2.38.2, the /rest/active-workflows en...
CVE-2026-86993MEDIUM4.9n8n is an open source workflow automation platform. Prior to 1.123.76, 2.37.7, and 2.38.2, a Log Streaming event destina...
CVE-2026-86085MEDIUM4.9n8n is an open source workflow automation platform. Prior to 2.37.7 and 2.38.2, the /rest/roles/:slug/assignments and /r...
CVE-2026-86084MEDIUM5.5n8n is an open source workflow automation platform. Prior to 1.123.76, 2.37.7, and 2.38.2, the public OIDC login and cal...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now