2026 CVE Vulnerabilities
61,720 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-45497 | HIGH | 8.8 | 0.5% | Jun 4, 2026 | Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an autho... |
| CVE-2026-42824 | HIGH | 7.5 | 7.6% | Jun 4, 2026 | Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unauthoriz... |
| CVE-2026-20245 | HIGH | 7.8 | 25.3% | Jun 4, 2026 | A vulnerability in the CLI of Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, Cisco Catalyst SD-WAN Manager, f... |
| CVE-2026-11237 | HIGH | 8.3 | 0.2% | Jun 4, 2026 | Insufficient validation of untrusted input in Media in Google Chrome prior to 149.0.7827.53 allowed a remote attacker wh... |
| CVE-2026-11236 | HIGH | 8.3 | 0.2% | Jun 4, 2026 | Insufficient policy enforcement in Web Bluetooth in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who h... |
| CVE-2026-11235 | HIGH | 8.8 | 0.2% | Jun 4, 2026 | Insufficient policy enforcement in Compositing in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had... |
| CVE-2026-11234 | MEDIUM | 4.3 | 0.2% | Jun 4, 2026 | Inappropriate implementation in FoldableAPIs in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had c... |
| CVE-2026-11233 | MEDIUM | 4.7 | 0.2% | Jun 4, 2026 | Insufficient policy enforcement in FoldableAPIs in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who ha... |
| CVE-2026-11232 | MEDIUM | 5.4 | 0.1% | Jun 4, 2026 | Inappropriate implementation in TabGroups in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to perform U... |
| CVE-2026-11231 | HIGH | 8.1 | 0.2% | Jun 4, 2026 | Inappropriate implementation in Safe Browsing in Google Chrome on Mac prior to 149.0.7827.53 allowed a remote attacker t... |
| CVE-2026-11230 | HIGH | 8.8 | 0.2% | Jun 4, 2026 | Use after free in Extensions in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code... |
| CVE-2026-11229 | MEDIUM | 6.1 | 0.1% | Jun 4, 2026 | Inappropriate implementation in Enterprise in Google Chrome prior to 149.0.7827.53 allowed a local attacker to perform p... |
| CVE-2026-11228 | MEDIUM | 4.3 | 0.2% | Jun 4, 2026 | Inappropriate implementation in File Input in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who convinc... |
| CVE-2026-11227 | MEDIUM | 6.5 | 0.2% | Jun 4, 2026 | Incorrect security UI in Tab Hover Cards in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to perform do... |
| CVE-2026-11226 | MEDIUM | 6.5 | 0.2% | Jun 4, 2026 | Insufficient policy enforcement in PreviewTab in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attack... |
| CVE-2026-11225 | MEDIUM | 6.5 | 0.2% | Jun 4, 2026 | Inappropriate implementation in WebUI in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to perform domai... |
| CVE-2026-11224 | HIGH | 8.1 | 0.2% | Jun 4, 2026 | Use after free in Chromoting in Google Chrome on Linux prior to 149.0.7827.53 allowed a remote attacker to execute arbit... |
| CVE-2026-11223 | MEDIUM | 6.5 | 0.2% | Jun 4, 2026 | Insufficient validation of untrusted input in Network in Google Chrome prior to 149.0.7827.53 allowed a remote attacker ... |
| CVE-2026-11222 | MEDIUM | 6.5 | 0.2% | Jun 4, 2026 | Incorrect security UI in Tab Strip in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to perform domain s... |
| CVE-2026-11221 | MEDIUM | 4.3 | 0.1% | Jun 4, 2026 | Insufficient validation of untrusted input in PointerLock in Google Chrome prior to 149.0.7827.53 allowed a remote attac... |
| CVE-2026-11220 | MEDIUM | 6.5 | 0.2% | Jun 4, 2026 | Insufficient validation of untrusted input in Navigation in Google Chrome prior to 149.0.7827.53 allowed a remote attack... |
| CVE-2026-11219 | MEDIUM | 4.3 | 0.2% | Jun 4, 2026 | Inappropriate implementation in Navigation in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to bypass n... |
| CVE-2026-11218 | MEDIUM | 6.8 | 0.2% | Jun 4, 2026 | Inappropriate implementation in PlatformIntegration in Google Chrome on Windows prior to 149.0.7827.53 allowed a remote ... |
| CVE-2026-11217 | MEDIUM | 6.5 | 0.1% | Jun 4, 2026 | Inappropriate implementation in Fenced Frames in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had ... |
| CVE-2026-11216 | MEDIUM | 4.3 | 0.1% | Jun 4, 2026 | Incorrect security UI in File Input in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who convinced a us... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now