2026 CVE Vulnerabilities

60,152 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-53944MEDIUM5.8Ghost is a Node.js content management system. From 6.0.9 until 6.21.1, when making an external request, it is possible t...
CVE-2026-53943CRITICAL9.6Ghost is a Node.js content management system. From until 6.37.0, when Ghost is behind a shared caching layer that resul...
CVE-2026-49980CRITICAL9.8Rclone is a command-line program to sync files and directories to and from different cloud storage providers. From 1.46....
CVE-2026-49247HIGH8.8Jellyfin is an open source self hosted media server. From 10.9.0 until 10.11.10, the POST /ClientLog/Document endpoint a...
CVE-2026-49246LOW1.7Jellyfin is an open source self hosted media server. Prior to 10.11.10, a specifically crafted MKV file containing forge...
CVE-2026-49220MEDIUM5.7Jellyfin is an open source self hosted media server. Prior to 10.11.9, a potential XSS attack exists in Jellyfin which c...
CVE-2026-48793HIGH8.8Jellyfin is an open source self hosted media server. Prior to 10.11.10, a potential FFmpeg argument injection vulnerabil...
CVE-2026-13038HIGH8.8Use after free in Autofill in Google Chrome on Windows prior to 149.0.7827.197 allowed a remote attacker to execute arbi...
CVE-2026-13037HIGH7.8Use after free in WebView in Google Chrome on Android prior to 149.0.7827.197 allowed a local attacker to execute arbitr...
CVE-2026-13036HIGH8.8Use after free in Blink in Google Chrome prior to 149.0.7827.197 allowed a remote attacker to execute arbitrary code ins...
CVE-2026-13035HIGH8.8Use after free in Bluetooth in Google Chrome on Mac prior to 149.0.7827.197 allowed a remote attacker to execute arbitra...
CVE-2026-13034MEDIUM4.7Inappropriate implementation in Passwords in Google Chrome prior to 149.0.7827.197 allowed a remote attacker who had com...
CVE-2026-13033HIGH8.8Out of bounds read and write in Blink>InterestGroups in Google Chrome prior to 149.0.7827.197 allowed a remote attacker ...
CVE-2026-13032CRITICAL9.6Use after free in WebGL in Google Chrome on Android prior to 149.0.7827.197 allowed a remote attacker to potentially per...
CVE-2026-13031HIGH8.8Use after free in Blink in Google Chrome prior to 149.0.7827.197 allowed a remote attacker to execute arbitrary code ins...
CVE-2026-13030MEDIUM5.3Uninitialized Use in GPU in Google Chrome on Android prior to 149.0.7827.197 allowed a remote attacker to obtain potenti...
CVE-2026-13029HIGH7.5Use after free in Web Authentication in Google Chrome prior to 149.0.7827.197 allowed an attacker who convinced a user t...
CVE-2026-13028CRITICAL9.6Use after free in WebGL in Google Chrome on Android prior to 149.0.7827.197 allowed a remote attacker to potentially per...
CVE-2026-13027HIGH8.8Use after free in FileSystem in Google Chrome prior to 149.0.7827.197 allowed a remote attacker to potentially exploit h...
CVE-2026-13026HIGH8.8Use after free in Digital Credentials in Google Chrome on Mac prior to 149.0.7827.197 allowed a remote attacker to poten...
CVE-2026-13025HIGH8.3Race in DevTools in Google Chrome prior to 149.0.7827.197 allowed a remote attacker who had compromised the renderer pro...
CVE-2026-13024MEDIUM4.2Insufficient validation of untrusted input in Navigation in Google Chrome prior to 149.0.7827.197 allowed a remote attac...
CVE-2026-13023MEDIUM5.3Uninitialized Use in GPU in Google Chrome prior to 149.0.7827.197 allowed a remote attacker who had compromised the rend...
CVE-2026-13022MEDIUM6.5Inappropriate implementation in Autofill in Google Chrome prior to 149.0.7827.197 allowed a remote attacker who had comp...
CVE-2026-13021MEDIUM4.3Inappropriate implementation in DeviceBoundSessionCredentials in Google Chrome prior to 149.0.7827.197 allowed a remote ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now