2026 CVE Vulnerabilities

61,767 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-10885HIGH8.8Use after free in Chrome for iOS in Google Chrome on iOS prior to 149.0.7827.53 allowed a remote attacker to execute arb...
CVE-2026-10884HIGH8.3Use after free in Chromecast in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the r...
CVE-2026-10883HIGH8.8Type Confusion in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially exploit heap co...
CVE-2026-10882HIGH8.8Use after free in Network in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code vi...
CVE-2026-10881CRITICAL9.6Out of bounds read and write in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially p...
CVE-2026-10875MEDIUM6.3A security flaw has been discovered in projectworlds Online Art Gallery Shop Project 1.0. The impacted element is an unk...
CVE-2026-10874MEDIUM6.3A vulnerability was identified in projectworlds Online Art Gallery Shop Project 1.0. The affected element is an unknown ...
CVE-2026-10873HIGH7.3A vulnerability was determined in Shibby Tomato 1.28.0000. Impacted is the function rstats_path of the file /bin/rstats ...
CVE-2026-10872HIGH7.3A vulnerability was found in Shibby Tomato 1.28.0000. This issue affects the function start_vpnserver of the file /sbin/...
CVE-2026-42547MEDIUM5.4IRIS is a web collaborative platform that helps incident responders share technical details during investigations. In ve...
CVE-2026-42543MEDIUM4.3IRIS is a web collaborative platform that helps incident responders share technical details during investigations. Versi...
CVE-2026-42540MEDIUM4.3IRIS is a web collaborative platform that helps incident responders share technical details during investigations. Versi...
CVE-2026-42539MEDIUM6.5IRIS is a web collaborative platform that helps incident responders share technical details during investigations. Versi...
CVE-2026-11322HIGH7.1Hermes WebUI prior to v0.51.221 contains a path traversal vulnerability that allows attackers to escape the workspace bo...
CVE-2026-10871HIGH7.3A vulnerability has been found in Shibby Tomato 1.28.0000. This vulnerability affects the function start_6rd_tunnel of t...
CVE-2026-5066HIGH8.8A potential out-of-bounds write/read exists in the TLS socket connect path of the network sockets subsystem (subsys/net/...
CVE-2026-42538MEDIUM6.3IRIS is a web collaborative platform that helps incident responders share technical details during investigations. Versi...
CVE-2026-42329MEDIUM4.7Iris is a web collaborative platform that helps incident responders share technical details during investigations. Versi...
CVE-2026-10870HIGH7.3A flaw has been found in Shibby Tomato 1.28.0000. This affects the function start_dhcpc of the file /sbin/rc of the comp...
CVE-2026-5589MEDIUM6.3An integer underflow in bt_mesh_sol_recv() in the Bluetooth Mesh solicitation handling (subsys/bluetooth/mesh/solicitati...
CVE-2026-41522HIGH7.1Iris is a web collaborative platform that helps incident responders share technical details during investigations. Prior...
CVE-2026-41518HIGH7.6Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create c...
CVE-2026-41249HIGH8.2CoreShop is a Pimcore enhanced eCommerce solution. In versions 5.0.1 through 5.1.0-beta.1,, the GitHub Actions workflow ...
CVE-2026-21404MEDIUM6.3NAVTOR NavBox through version 4.16.1.20 contains hard-coded credentials within its Windows Communication Foundation (SOA...
CVE-2026-48480MEDIUM6.6The netty incubator codec.bhttp is a java language binary http parser. Prior to version 0.0.22.FInal, the codec-ohttp im...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now