2026 CVE Vulnerabilities

62,196 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-6324MEDIUM4.8A flaw was found in libsoup. A remote attacker could exploit an unsigned to signed conversion error in the `soup_body_in...
CVE-2026-6275MEDIUM6.4The StatCounter – Free Real Time Visitor Stats plugin for WordPress is vulnerable to Stored Cross-Site Scripting in vers...
CVE-2026-2128MEDIUM5.3The Breeze plugin for WordPress is vulnerable to Exposure of Sensitive Information to an Unauthorized Actor in all versi...
CVE-2026-8995MEDIUM4.3The Poll Maker – Versus Polls, Anonymous Polls, Image Polls plugin for WordPress is vulnerable to Sensitive Information ...
CVE-2026-7430MEDIUM4.4The Post Snippets plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including...
CVE-2026-8070HIGH7.3Incorrect permission assignment for a critical resource in Armoury Crate allows a local user to bypass the driver’s vali...
CVE-2026-7480HIGH7.3An Incorrect Permission Assignment for Critical Resource vulnerability in ASUS System Control Interface allows a local u...
CVE-2026-6892MEDIUM5.1Improper handling of symbolic links in the installer of CUPS Printer Driver for macOS(*) may allow a local attacker with...
CVE-2026-6891MEDIUM5.1Improper handling of symbolic links in the installer of My Image Garden for macOS Version 3.6.8 or earlier may allow a l...
CVE-2026-9999HIGH8.8Inappropriate implementation in ANGLE in Google Chrome on Mac prior to 148.0.7778.216 allowed a remote attacker to execu...
CVE-2026-9998HIGH8.3Integer overflow in Skia in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the rend...
CVE-2026-9997HIGH8.3Use after free in Input in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the rende...
CVE-2026-9996MEDIUM6.5Out of bounds read in WebRTC in Google Chrome on Mac prior to 148.0.7778.216 allowed a remote attacker to obtain potenti...
CVE-2026-9995HIGH8.8Use after free in WebXR in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code ins...
CVE-2026-9994HIGH8.3Use after free in Core in Google Chrome on Windows prior to 148.0.7778.216 allowed a remote attacker who had compromised...
CVE-2026-9993HIGH8.3Use after free in Views in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the rende...
CVE-2026-9992HIGH8.8Use after free in Network in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code i...
CVE-2026-9991LOW3.1Inappropriate implementation in Media in Google Chrome on Windows prior to 148.0.7778.216 allowed a remote attacker who ...
CVE-2026-9990HIGH7.5Use after free in WebAppInstalls in Google Chrome on Mac prior to 148.0.7778.216 allowed a remote attacker who convinced...
CVE-2026-9989MEDIUM6.3Inappropriate implementation in Media in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to bypass same ...
CVE-2026-9988HIGH8.3Use after free in WebRTC in Google Chrome on Linux prior to 148.0.7778.216 allowed a remote attacker to potentially perf...
CVE-2026-9987HIGH7.8Insufficient validation of untrusted input in WebAppInstalls in Google Chrome on Android prior to 148.0.7778.216 allowed...
CVE-2026-9986MEDIUM4.2Insufficient validation of untrusted input in OptimizationGuide in Google Chrome prior to 148.0.7778.216 allowed a remot...
CVE-2026-9985MEDIUM5.3Insufficient validation of untrusted input in Media in Google Chrome on ChromeOS prior to 148.0.7778.216 allowed a remot...
CVE-2026-9984HIGH8.8Use after free in UI in Google Chrome on Windows prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now