2026 CVE Vulnerabilities
61,327 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-12028 | HIGH | 8.3 | 0.2% | Jun 11, 2026 | Use after free in GPU in Google Chrome on Android prior to 149.0.7827.115 allowed a remote attacker who had compromised ... |
| CVE-2026-12027 | CRITICAL | 9.6 | 0.2% | Jun 11, 2026 | Inappropriate implementation in Headless in Google Chrome prior to 149.0.7827.115 allowed a remote attacker who had comp... |
| CVE-2026-12026 | MEDIUM | 6.5 | 0.2% | Jun 11, 2026 | Out of bounds read in Video in Google Chrome on ChromeOS prior to 149.0.7827.115 allowed a remote attacker who had compr... |
| CVE-2026-12025 | MEDIUM | 5.3 | 0.2% | Jun 11, 2026 | Insufficient validation of untrusted input in Network in Google Chrome prior to 149.0.7827.115 allowed a remote attacker... |
| CVE-2026-12024 | MEDIUM | 6.5 | 0.2% | Jun 11, 2026 | Insufficient policy enforcement in DevTools in Google Chrome prior to 149.0.7827.115 allowed a remote attacker to bypass... |
| CVE-2026-12023 | HIGH | 8.3 | 0.2% | Jun 11, 2026 | Use after free in GPU in Google Chrome on Mac prior to 149.0.7827.115 allowed a remote attacker who had compromised the ... |
| CVE-2026-12022 | HIGH | 8.3 | 0.2% | Jun 11, 2026 | Race in Safe Browsing in Google Chrome on Mac prior to 149.0.7827.115 allowed a remote attacker who had compromised the ... |
| CVE-2026-12020 | HIGH | 8.8 | 0.2% | Jun 11, 2026 | Use after free in Autofill in Google Chrome on Mac prior to 149.0.7827.115 allowed a remote attacker to potentially expl... |
| CVE-2026-12019 | HIGH | 8.3 | 0.3% | Jun 11, 2026 | Heap buffer overflow in Codecs in Google Chrome on Linux and ChromeOS prior to 149.0.7827.115 allowed a remote attacker ... |
| CVE-2026-12018 | HIGH | 8.8 | 0.2% | Jun 11, 2026 | Inappropriate implementation in Mojo in Google Chrome on Windows prior to 149.0.7827.115 allowed a local attacker to per... |
| CVE-2026-12017 | LOW | 3.1 | 0.2% | Jun 11, 2026 | Inappropriate implementation in Extensions in Google Chrome prior to 149.0.7827.115 allowed a remote attacker who had co... |
| CVE-2026-12016 | HIGH | 8.3 | 0.2% | Jun 11, 2026 | Inappropriate implementation in DevTools in Google Chrome prior to 149.0.7827.115 allowed a remote attacker who had comp... |
| CVE-2026-12015 | MEDIUM | 5.3 | 0.2% | Jun 11, 2026 | Use after free in Autofill in Google Chrome prior to 149.0.7827.115 allowed a remote attacker who had compromised the re... |
| CVE-2026-12014 | HIGH | 8.3 | 0.2% | Jun 11, 2026 | Use after free in Cast in Google Chrome prior to 149.0.7827.115 allowed an attacker on the local network segment to pote... |
| CVE-2026-12013 | — | — | — | Jun 11, 2026 | Rejected reason: Determined not a vulnerability |
| CVE-2026-12012 | HIGH | 8.1 | 0.2% | Jun 11, 2026 | Use after free in Network in Google Chrome prior to 149.0.7827.115 allowed an attacker in a privileged network position ... |
| CVE-2026-12011 | HIGH | 8.3 | 0.2% | Jun 11, 2026 | Use after free in WebMIDI in Google Chrome on Windows prior to 149.0.7827.115 allowed a remote attacker who had compromi... |
| CVE-2026-12010 | HIGH | 8.3 | 0.3% | Jun 11, 2026 | Heap buffer overflow in GPU in Google Chrome on Android prior to 149.0.7827.115 allowed a remote attacker who had compro... |
| CVE-2026-12009 | HIGH | 8.3 | 0.2% | Jun 11, 2026 | Insufficient validation of untrusted input in Accessibility in Google Chrome on Mac prior to 149.0.7827.115 allowed a re... |
| CVE-2026-12008 | HIGH | 8.3 | 0.2% | Jun 11, 2026 | Use after free in DigitalCredentials in Google Chrome prior to 149.0.7827.115 allowed a remote attacker who had compromi... |
| CVE-2026-12007 | HIGH | 8.8 | 0.3% | Jun 11, 2026 | Use after free in Core in Google Chrome on Windows prior to 149.0.7827.115 allowed a remote attacker to execute arbitrar... |
| CVE-2026-53819 | HIGH | 7.8 | 0.3% | Jun 11, 2026 | OpenClaw before 2026.5.27 contains an arbitrary code execution vulnerability in skill install flows where workspace .env... |
| CVE-2026-53818 | MEDIUM | 6.9 | 0.1% | Jun 11, 2026 | OpenClaw before 2026.4.24 contains an authorization bypass vulnerability in the MCP loopback feature that allows non-own... |
| CVE-2026-53817 | HIGH | 8.8 | 0.3% | Jun 11, 2026 | OpenClaw before 2026.5.22 contains a locality validation vulnerability in Control UI pairing that allows attackers with ... |
| CVE-2026-53816 | HIGH | 8.6 | 0.3% | Jun 11, 2026 | OpenClaw before 2026.5.18 contains an insufficient provenance validation vulnerability in node event handling that allow... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now