2026 CVE Vulnerabilities
61,192 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-12446 | MEDIUM | 4.3 | 0.2% | Jun 17, 2026 | Inappropriate implementation in Passwords in Google Chrome prior to 149.0.7827.155 allowed a remote attacker to leak cro... |
| CVE-2026-12445 | HIGH | 7.5 | 0.2% | Jun 17, 2026 | Use after free in Extensions in Google Chrome prior to 149.0.7827.155 allowed an attacker who convinced a user to instal... |
| CVE-2026-12444 | MEDIUM | 5.5 | 0.1% | Jun 17, 2026 | Out of bounds read in Chromoting in Google Chrome on Windows prior to 149.0.7827.155 allowed a local attacker to obtain ... |
| CVE-2026-12443 | HIGH | 8.8 | 0.6% | Jun 17, 2026 | Use after free in Web Authentication in Google Chrome prior to 149.0.7827.155 allowed a remote attacker to execute arbit... |
| CVE-2026-12442 | HIGH | 8.8 | 0.4% | Jun 17, 2026 | Use after free in Passwords in Google Chrome on Android prior to 149.0.7827.155 allowed a remote attacker to execute arb... |
| CVE-2026-12441 | HIGH | 8.8 | 0.3% | Jun 17, 2026 | Use after free in File Input in Google Chrome on Linux prior to 149.0.7827.155 allowed a remote attacker to potentially ... |
| CVE-2026-12440 | CRITICAL | 9.6 | 0.3% | Jun 17, 2026 | Use after free in DigitalCredentials in Google Chrome on Windows prior to 149.0.7827.155 allowed a remote attacker to po... |
| CVE-2026-12439 | HIGH | 8.8 | 0.3% | Jun 17, 2026 | Use after free in Digital Credentials in Google Chrome prior to 149.0.7827.155 allowed a remote attacker to potentially ... |
| CVE-2026-12438 | HIGH | 8.3 | 0.2% | Jun 17, 2026 | Inappropriate implementation in WebView in Google Chrome on Android prior to 149.0.7827.155 allowed a remote attacker wh... |
| CVE-2026-12437 | HIGH | 8.3 | 0.3% | Jun 17, 2026 | Use after free in WebShare in Google Chrome on Windows prior to 149.0.7827.155 allowed a remote attacker who had comprom... |
| CVE-2026-12360 | HIGH | 7.5 | 0.3% | Jun 17, 2026 | The JetEngine plugin for WordPress is vulnerable to SQL injection in all versions up to and including 3.8.10.1. The list... |
| CVE-2026-12256 | HIGH | 8.8 | 0.5% | Jun 17, 2026 | Contributor PHP Object Injection in Avada <= 3.15.3 versions. |
| CVE-2026-12199 | HIGH | 7.5 | 0.3% | Jun 17, 2026 | A vulnerability in `nltk.app.wordnet_app` up to version 3.9.3 allows unauthenticated remote shutdown of the local WordNe... |
| CVE-2026-12165 | HIGH | 8.8 | 0.4% | Jun 17, 2026 | The Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe plugin for WordPress is vulnerable to Privi... |
| CVE-2026-12115 | MEDIUM | 6.6 | 0.5% | Jun 17, 2026 | The Counter Box – Add Countdowns, Timers & Dynamic Counters to WordPress plugin for WordPress is vulnerable to PHP Objec... |
| CVE-2026-11975 | MEDIUM | 6.2 | 0.3% | Jun 17, 2026 | Stored cross-site scripting (XSS) in NewsItemApiController In SimplCommerce prior to commit 6142d3b5 allows an authentic... |
| CVE-2026-11858 | HIGH | 8.4 | 0.1% | Jun 17, 2026 | Quanos SCHEMA ST4 on-premises contains a local privilege escalation vulnerability in the Client Update Service. The upda... |
| CVE-2026-11857 | HIGH | 8.4 | 0.3% | Jun 17, 2026 | Quanos SCHEMA ST4 on-premises contains a local privilege escalation vulnerability in the Client Update Service due to in... |
| CVE-2026-11410 | HIGH | 7.2 | 2.8% | Jun 17, 2026 | An authenticated OS command injection vulnerability exists in the BigPond Cable (BPA) WAN configuration module in TL-WR9... |
| CVE-2026-11409 | HIGH | 7.2 | 2.8% | Jun 17, 2026 | An authenticated OS command injection vulnerability exists in the IPv6 PPPoE configuration handler in TL-WR940N v6 due t... |
| CVE-2026-10839 | MEDIUM | 5.1 | 0.4% | Jun 17, 2026 | Open redirection vulnerability in the authentication system allows an attacker to use manipulated values in the X-Forwar... |
| CVE-2026-10837 | MEDIUM | 5.1 | 0.3% | Jun 17, 2026 | Open redirection vulnerability due to insufficient validation of the X-Forwarded-Host HTTP header. An attacker could cre... |
| CVE-2026-10836 | MEDIUM | 5.1 | 0.3% | Jun 17, 2026 | Improper handling of HTTP headers that allows a remote attacker to manipulate the value of the Host header using special... |
| CVE-2026-10094 | CRITICAL | 9.8 | 0.4% | Jun 17, 2026 | A Path Traversal vulnerability affecting SOLIDWORKS Visualize from SOLIDWORKS Desktop Release 2024 through SOLIDWORKS De... |
| CVE-2026-0092 | CRITICAL | 10 | 0.2% | Jun 17, 2026 | In Package Manager, there is a possible device lock controller bypass due to a missing permission check. This could lead... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now