2026 CVE Vulnerabilities

44,088 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-43632CRITICAL9.2llama.cpp builds b7492 through the latest b9060 contains a use-after-free vulnerability in llama-server affecting six to...
CVE-2026-43631CRITICAL9.2llama.cpp builds b7492 through the latest b9060 contains a use-after-free vulnerability in the vocab pointer of llama-se...
CVE-2026-43630MEDIUM6.5llama.cpp builds b5702 through b7653 contain an out-of-bounds read vulnerability in the recurrent memory state restore p...
CVE-2026-43629CRITICAL9.2llama.cpp builds b4882 through b9058 contain a heap buffer overflow vulnerability in the KV cache state restore path whe...
CVE-2026-43628HIGH8.5llama.cpp builds b3978 through b9058 contain an integer underflow and out-of-bounds read vulnerability in the DRY sample...
CVE-2026-43627HIGH8.5llama.cpp builds b1283 through b9058 contain an integer overflow vulnerability in the llama_batch_init() function where ...
CVE-2026-41861MEDIUM4.2Path Traversal in BOSH-Ecosystem / BOSH allows an IaaS-metadata attacker to make the agent write a root-owned file with ...
CVE-2026-3418CRITICAL9.1The System REST API accepts user-supplied file uploads without enforcing sufficient validation on the file type or desti...
CVE-2026-3415HIGH8.7The XML and schema validation functionalities within the SchemaValidator Mediator process XML input as part of validatio...
CVE-2026-33181Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-33942. Reason: This candidate is a ...
CVE-2026-1289HIGH7.8A maliciously crafted PDF file, when parsed through Autodesk Revit, can force a Use-After-Free vulnerability. A maliciou...
CVE-2026-19177HIGH8.3Insufficient validation of untrusted input in UI in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who ...
CVE-2026-19176HIGH7.5Use after free in Skia in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the render...
CVE-2026-19175CRITICAL9.6Use after free in Payments in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to potentially perform a s...
CVE-2026-19174HIGH8.8Integer overflow in V8 in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to execute arbitrary code insi...
CVE-2026-19173HIGH8.3Out of bounds write in Skia in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the r...
CVE-2026-19172HIGH8.3Use after free in Views in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the rende...
CVE-2026-19171CRITICAL9.6Use after free in Media in Google Chrome on Windows prior to 151.0.7922.109 allowed a remote attacker to potentially per...
CVE-2026-19170CRITICAL9.6Use after free in WebGL in Google Chrome on Android prior to 151.0.7922.109 allowed a remote attacker to potentially per...
CVE-2026-19169HIGH8.8Insufficient validation of untrusted input in Contextual Tasks in Google Chrome prior to 151.0.7922.109 allowed a remote...
CVE-2026-19168HIGH8.8Inappropriate implementation in V8 in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to execute arbitra...
CVE-2026-19167LOW3.1Integer overflow in GPU in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the rende...
CVE-2026-19166CRITICAL9.6Use after free in Web Authentication in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to potentially p...
CVE-2026-19165HIGH7.5Use after free in Extensions in Google Chrome prior to 151.0.7922.109 allowed an attacker who convinced a user to instal...
CVE-2026-19164CRITICAL9.6Insufficient validation of untrusted input in Codecs in Google Chrome prior to 151.0.7922.109 allowed a remote attacker ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now