2026 CVE Vulnerabilities

64,751 CVEs published in 2026.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2026-93374CRITICAL9.6Use after free in Dawn in Google Chrome on on Android prior to 153.0.8010.52 allowed a remote attacker to potentially ex...
CVE-2026-93373CRITICAL9.6Use after free in Extensions in Google Chrome prior to 153.0.8010.52 allowed a remote attacker to execute arbitrary code...
CVE-2026-93372CRITICAL9.6Buffer overflow in WebGL in Google Chrome on on Android prior to 153.0.8010.52 allowed a remote attacker to execute arbi...
CVE-2026-54501CRITICAL9.4Browsertrix is a high-fidelity, browser-based crawling service for web archiving that can be self-hosted or used through...
CVE-2026-54460CRITICAL9.8OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to 1.1...
CVE-2026-54237CRITICAL9.3Wavelog is web-based amateur radio logging software. From 1.8 until 2.4.2, Wavelog exposes /install/ajax.php and /instal...
CVE-2026-45143CRITICAL9Chamilo LMS is an open-source learning management system. From 2.0.0 through at least 2.1.0, Chamilo LMS stores private ...
CVE-2026-45140CRITICAL9.8Chamilo LMS is an open-source learning management system. Prior to 2.0.1, Chamilo LMS allows an unauthenticated remote a...
CVE-2026-54752CRITICAL9.6NetBox Device Type Library is a collection of community-sourced device type definitions for import into NetBox. The vali...
CVE-2026-54627CRITICAL9.8SAIL is a cross-platform library for loading and saving images with support for animation, metadata, and ICC profiles. I...
CVE-2026-54626CRITICAL9.8SAIL is a cross-platform library for loading and saving images with support for animation, metadata, and ICC profiles. I...
CVE-2026-54618CRITICAL9.4Obsidian Web MCP is a secure remote MCP server for Obsidian vaults. Prior to 0.2.0, /oauth/authorize issues an authoriza...
CVE-2026-54617CRITICAL9.8GravitLauncher is an open-source Minecraft launcher based on sashok724's v3. Prior to 5.7.12, an unauthenticated remote ...
CVE-2026-47252CRITICAL9Anyquery is an SQL query engine built on top of SQLite. Prior to 0.4.5, authenticated users with INSERT or UPDATE access...
CVE-2026-54053CRITICAL9.6Many Notes is a Markdown note-taking web application designed for simplicity. Prior to 0.16.0, the ZIP vault import impl...
CVE-2026-92489CRITICAL9.8In the Linux kernel, the following vulnerability has been resolved: xfrm: Fix skb double-free in xfrm_dev_direct_output...
CVE-2026-90414CRITICAL9.1In the Linux kernel, the following vulnerability has been resolved: IB/isert: reject PDUs declaring more data than was ...
CVE-2026-90413CRITICAL9.1In the Linux kernel, the following vulnerability has been resolved: IB/isert: reject login PDUs declaring more data tha...
CVE-2026-90235CRITICAL9.8In the Linux kernel, the following vulnerability has been resolved: sunrpc: xprtsock: annotate shared socket callbacks ...
CVE-2026-90230CRITICAL9.1In the Linux kernel, the following vulnerability has been resolved: nvmet: fix heap out-of-bounds read in nvmet_auth_ne...
CVE-2026-90173CRITICAL9.8In the Linux kernel, the following vulnerability has been resolved: smb: smbdirect: free completion queues with ib_free...
CVE-2026-90151CRITICAL9.8In the Linux kernel, the following vulnerability has been resolved: NFSv4: remove callback IDR entry on client allocati...
CVE-2026-90110CRITICAL9.4In the Linux kernel, the following vulnerability has been resolved: inetpeer: randomize RB-tree node comparison using S...
CVE-2026-90104CRITICAL9.8In the Linux kernel, the following vulnerability has been resolved: NFSv4.1: zero referring call lists before decoding ...
CVE-2026-91039CRITICAL9.1Authentication Bypass by Spoofing vulnerability in team-alembic ash_authentication allows an attacker who operates one i...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now