2026 CVE Vulnerabilities

61,192 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-22325HIGH8.1Unauthenticated Local File Inclusion in Promo <= 1.3.0 versions.
CVE-2026-12491MEDIUM4.8A flaw was found in vLLM, an open-source library for large language model inference. This vulnerability arises from impr...
CVE-2026-12469MEDIUM4.3Uninitialized Use in GPU in Google Chrome on Android prior to 149.0.7827.155 allowed a remote attacker to leak cross-ori...
CVE-2026-12468HIGH8.3Race in Updater in Google Chrome on Mac prior to 149.0.7827.155 allowed a remote attacker who had compromised the render...
CVE-2026-12467HIGH8.3Use after free in Extensions in Google Chrome prior to 149.0.7827.155 allowed a remote attacker who had compromised the ...
CVE-2026-12466HIGH8.8Heap buffer overflow in WebRTC in Google Chrome on Windows prior to 149.0.7827.155 allowed a remote attacker to execute ...
CVE-2026-12465HIGH8.3Object lifecycle issue in Metrics in Google Chrome prior to 149.0.7827.155 allowed a remote attacker who had compromised...
CVE-2026-12464HIGH8.3Use after free in Browser in Google Chrome prior to 149.0.7827.155 allowed a remote attacker who had compromised the ren...
CVE-2026-12463MEDIUM4.7Inappropriate implementation in Views in Google Chrome on Linux prior to 149.0.7827.155 allowed a remote attacker who ha...
CVE-2026-12462HIGH7.5Use after free in Media in Google Chrome prior to 149.0.7827.155 allowed a remote attacker who had compromised the rende...
CVE-2026-12461MEDIUM6.5Out of bounds read in WebRTC in Google Chrome on Windows prior to 149.0.7827.155 allowed a remote attacker to obtain pot...
CVE-2026-12460MEDIUM4.2Insufficient policy enforcement in File System Access in Google Chrome prior to 149.0.7827.155 allowed a remote attacker...
CVE-2026-12459MEDIUM6.1Inappropriate implementation in Serial in Google Chrome prior to 149.0.7827.155 allowed a remote attacker to inject arbi...
CVE-2026-12458LOW3.1Inappropriate implementation in Passwords in Google Chrome prior to 149.0.7827.155 allowed a remote attacker who convinc...
CVE-2026-12457MEDIUM4.2Inappropriate implementation in Extensions in Google Chrome prior to 149.0.7827.155 allowed a remote attacker who had co...
CVE-2026-12456MEDIUM4.2Inappropriate implementation in Extensions in Google Chrome prior to 149.0.7827.155 allowed an attacker who convinced a ...
CVE-2026-12455HIGH7.5Use after free in Tab Strip in Google Chrome prior to 149.0.7827.155 allowed a remote attacker who convinced a user to e...
CVE-2026-12454HIGH8.3Race in Safe Browsing in Google Chrome on Mac prior to 149.0.7827.155 allowed a remote attacker who had compromised the ...
CVE-2026-12453MEDIUM4.2Insufficient validation of untrusted input in Input in Google Chrome prior to 149.0.7827.155 allowed a remote attacker w...
CVE-2026-12452HIGH8.8Use after free in Downloads in Google Chrome on Android prior to 149.0.7827.155 allowed a remote attacker to potentially...
CVE-2026-12451HIGH8.3Use after free in DigitalCredentials in Google Chrome prior to 149.0.7827.155 allowed a remote attacker who had compromi...
CVE-2026-12450MEDIUM6.5Inappropriate implementation in Media in Google Chrome prior to 149.0.7827.155 allowed a remote attacker to obtain poten...
CVE-2026-12449HIGH7.8Use after free in Chromoting in Google Chrome on Windows prior to 149.0.7827.155 allowed a local attacker to perform OS-...
CVE-2026-12448HIGH8.8Inappropriate implementation in WebView in Google Chrome on Android prior to 149.0.7827.155 allowed a remote attacker to...
CVE-2026-12447HIGH8.8Heap buffer overflow in WebRTC in Google Chrome prior to 149.0.7827.155 allowed a remote attacker to execute arbitrary c...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now