2026 CVE Vulnerabilities
44,088 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-43632 | CRITICAL | 9.2 | 0.3% | Aug 6, 2026 | llama.cpp builds b7492 through the latest b9060 contains a use-after-free vulnerability in llama-server affecting six to... |
| CVE-2026-43631 | CRITICAL | 9.2 | 0.4% | Aug 6, 2026 | llama.cpp builds b7492 through the latest b9060 contains a use-after-free vulnerability in the vocab pointer of llama-se... |
| CVE-2026-43630 | MEDIUM | 6.5 | 0.4% | Aug 6, 2026 | llama.cpp builds b5702 through b7653 contain an out-of-bounds read vulnerability in the recurrent memory state restore p... |
| CVE-2026-43629 | CRITICAL | 9.2 | 0.5% | Aug 6, 2026 | llama.cpp builds b4882 through b9058 contain a heap buffer overflow vulnerability in the KV cache state restore path whe... |
| CVE-2026-43628 | HIGH | 8.5 | 0.2% | Aug 6, 2026 | llama.cpp builds b3978 through b9058 contain an integer underflow and out-of-bounds read vulnerability in the DRY sample... |
| CVE-2026-43627 | HIGH | 8.5 | 0.1% | Aug 6, 2026 | llama.cpp builds b1283 through b9058 contain an integer overflow vulnerability in the llama_batch_init() function where ... |
| CVE-2026-41861 | MEDIUM | 4.2 | — | Aug 6, 2026 | Path Traversal in BOSH-Ecosystem / BOSH allows an IaaS-metadata attacker to make the agent write a root-owned file with ... |
| CVE-2026-3418 | CRITICAL | 9.1 | 0.5% | Aug 6, 2026 | The System REST API accepts user-supplied file uploads without enforcing sufficient validation on the file type or desti... |
| CVE-2026-3415 | HIGH | 8.7 | 0.3% | Aug 6, 2026 | The XML and schema validation functionalities within the SchemaValidator Mediator process XML input as part of validatio... |
| CVE-2026-33181 | — | — | — | Aug 6, 2026 | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-33942. Reason: This candidate is a ... |
| CVE-2026-1289 | HIGH | 7.8 | 0.1% | Aug 6, 2026 | A maliciously crafted PDF file, when parsed through Autodesk Revit, can force a Use-After-Free vulnerability. A maliciou... |
| CVE-2026-19177 | HIGH | 8.3 | 0.4% | Aug 6, 2026 | Insufficient validation of untrusted input in UI in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who ... |
| CVE-2026-19176 | HIGH | 7.5 | 0.4% | Aug 6, 2026 | Use after free in Skia in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the render... |
| CVE-2026-19175 | CRITICAL | 9.6 | 0.2% | Aug 6, 2026 | Use after free in Payments in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to potentially perform a s... |
| CVE-2026-19174 | HIGH | 8.8 | 0.4% | Aug 6, 2026 | Integer overflow in V8 in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to execute arbitrary code insi... |
| CVE-2026-19173 | HIGH | 8.3 | 0.2% | Aug 6, 2026 | Out of bounds write in Skia in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the r... |
| CVE-2026-19172 | HIGH | 8.3 | 0.3% | Aug 6, 2026 | Use after free in Views in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the rende... |
| CVE-2026-19171 | CRITICAL | 9.6 | 0.2% | Aug 6, 2026 | Use after free in Media in Google Chrome on Windows prior to 151.0.7922.109 allowed a remote attacker to potentially per... |
| CVE-2026-19170 | CRITICAL | 9.6 | 0.3% | Aug 6, 2026 | Use after free in WebGL in Google Chrome on Android prior to 151.0.7922.109 allowed a remote attacker to potentially per... |
| CVE-2026-19169 | HIGH | 8.8 | 0.3% | Aug 6, 2026 | Insufficient validation of untrusted input in Contextual Tasks in Google Chrome prior to 151.0.7922.109 allowed a remote... |
| CVE-2026-19168 | HIGH | 8.8 | 0.5% | Aug 6, 2026 | Inappropriate implementation in V8 in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to execute arbitra... |
| CVE-2026-19167 | LOW | 3.1 | 0.3% | Aug 6, 2026 | Integer overflow in GPU in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the rende... |
| CVE-2026-19166 | CRITICAL | 9.6 | 0.3% | Aug 6, 2026 | Use after free in Web Authentication in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to potentially p... |
| CVE-2026-19165 | HIGH | 7.5 | 0.3% | Aug 6, 2026 | Use after free in Extensions in Google Chrome prior to 151.0.7922.109 allowed an attacker who convinced a user to instal... |
| CVE-2026-19164 | CRITICAL | 9.6 | 0.2% | Aug 6, 2026 | Insufficient validation of untrusted input in Codecs in Google Chrome prior to 151.0.7922.109 allowed a remote attacker ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now