2026 CVE Vulnerabilities
63,678 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-10020 | HIGH | 8.3 | 0.2% | May 28, 2026 | Insufficient validation of untrusted input in Skia in Google Chrome on Android prior to 148.0.7778.216 allowed a remote ... |
| CVE-2026-10019 | HIGH | 8.8 | 0.2% | May 28, 2026 | Integer overflow in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to leak cross-origin data v... |
| CVE-2026-10018 | MEDIUM | 6.5 | 0.2% | May 28, 2026 | Integer overflow in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to obtain potentially sensi... |
| CVE-2026-10017 | HIGH | 8.3 | 0.2% | May 28, 2026 | Out of bounds read in Headless in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised th... |
| CVE-2026-10016 | HIGH | 8.8 | 0.3% | May 28, 2026 | Use after free in DOM in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code insid... |
| CVE-2026-10015 | HIGH | 8.8 | 0.3% | May 28, 2026 | Integer overflow in WTF in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code ins... |
| CVE-2026-10014 | HIGH | 8.3 | 0.2% | May 28, 2026 | Use after free in WebMIDI in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attacker who had compromi... |
| CVE-2026-10013 | HIGH | 8.8 | 0.3% | May 28, 2026 | Use after free in WebCodecs in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code... |
| CVE-2026-10012 | HIGH | 8.3 | 0.2% | May 28, 2026 | Use after free in Skia in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the render... |
| CVE-2026-10011 | LOW | 3.1 | 0.2% | May 28, 2026 | Inappropriate implementation in Skia in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromi... |
| CVE-2026-10010 | MEDIUM | 5 | 0.1% | May 28, 2026 | Inappropriate implementation in Input in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attacker who ... |
| CVE-2026-10009 | HIGH | 7.5 | 0.2% | May 28, 2026 | Integer overflow in Skia in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the rend... |
| CVE-2026-10008 | MEDIUM | 6.5 | 0.2% | May 28, 2026 | Uninitialized Use in GPU in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attacker to obtain potenti... |
| CVE-2026-10007 | HIGH | 8.8 | 0.3% | May 28, 2026 | Use after free in SVG in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code insid... |
| CVE-2026-10006 | HIGH | 7.5 | 0.2% | May 28, 2026 | Race in WebAudio in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a s... |
| CVE-2026-10005 | HIGH | 7.5 | 0.3% | May 28, 2026 | Use after free in WebAppInstalls in Google Chrome on Mac prior to 148.0.7778.216 allowed a remote attacker who convinced... |
| CVE-2026-10004 | MEDIUM | 6.5 | 0.2% | May 28, 2026 | Insufficient validation of untrusted input in Passwords in Google Chrome prior to 148.0.7778.216 allowed a remote attack... |
| CVE-2026-10003 | HIGH | 7.5 | 0.2% | May 28, 2026 | Use after free in Views in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who convinced a user to engag... |
| CVE-2026-10002 | HIGH | 8.8 | 0.2% | May 28, 2026 | Use after free in PDFium in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to potentially exploit heap ... |
| CVE-2026-10001 | HIGH | 8.3 | 0.2% | May 28, 2026 | Use after free in PerformanceManager in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromi... |
| CVE-2026-10000 | HIGH | 8.3 | 0.2% | May 28, 2026 | Use after free in Passwords in Google Chrome on Windows prior to 148.0.7778.216 allowed a remote attacker who had compro... |
| CVE-2026-49299 | MEDIUM | 5.3 | 0.3% | May 28, 2026 | In OpenStack Neutron before 28.0.1, the tagging controller enforces plural policy action names on single-tag write opera... |
| CVE-2026-48116 | HIGH | 8.8 | 0.4% | May 28, 2026 | AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatti... |
| CVE-2026-47713 | MEDIUM | 4.3 | 0.2% | May 28, 2026 | AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatti... |
| CVE-2026-45410 | MEDIUM | 5.3 | 0.2% | May 28, 2026 | TREK is a collaborative travel planner. Prior to 3.0.18, early return on missing user during login flow allowed an attac... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now