2026 CVE Vulnerabilities
64,704 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-9141 | CRITICAL | 9.8 | 0.5% | May 20, 2026 | Taiko AG1000-01A SMS Alert Gateway Rev 7.3 and Rev 8 contains an authentication bypass vulnerability in the embedded web... |
| CVE-2026-9139 | CRITICAL | 9.8 | 0.5% | May 20, 2026 | Taiko AG1000-01A SMS Alert Gateway Rev 7.3 and Rev 8 contains a hard-coded credential vulnerability in the embedded web ... |
| CVE-2026-9137 | HIGH | 7.5 | 0.4% | May 20, 2026 | The CSP report endpoint in MISP intended to limit logged CSP reports to 1 KB but incorrectly allowed reports up to 1 MB ... |
| CVE-2026-9136 | MEDIUM | 6.5 | 0.2% | May 20, 2026 | A vulnerability was identified in the ShadowAttribute proposal creation workflow. The add action accepted user-controlle... |
| CVE-2026-9133 | HIGH | 8.3 | 0.3% | May 20, 2026 | Active debug code exists in the ARN resolver of amazon-mq rabbitmq-aws before version 0.2.1. A debug ARN scheme (arn:aws... |
| CVE-2026-9129 | CRITICAL | 9.4 | 0.2% | May 20, 2026 | A path traversal vulnerability exists in the Altium Enterprise Server Viewer StorageController due to improper handling ... |
| CVE-2026-9126 | HIGH | 8.8 | 0.4% | May 20, 2026 | Use after free in DOM in Google Chrome on prior to 148.0.7778.179 allowed a remote attacker to execute arbitrary code in... |
| CVE-2026-9124 | MEDIUM | 5.3 | 0.3% | May 20, 2026 | Insufficient validation of untrusted input in Input in Google Chrome on prior to 148.0.7778.179 allowed a remote attacke... |
| CVE-2026-9123 | HIGH | 7.5 | 0.2% | May 20, 2026 | Heap buffer overflow in Chromecast in Google Chrome on Android, Linux, ChromeOS prior to 148.0.7778.179 allowed a local ... |
| CVE-2026-9122 | MEDIUM | 6.5 | 0.3% | May 20, 2026 | Out of bounds read in GPU in Google Chrome on Mac prior to 148.0.7778.179 allowed a remote attacker to obtain potentiall... |
| CVE-2026-9121 | HIGH | 8.8 | 0.3% | May 20, 2026 | Out of bounds read in GPU in Google Chrome on prior to 148.0.7778.179 allowed a remote attacker to potentially exploit h... |
| CVE-2026-9120 | HIGH | 8.8 | 0.5% | May 20, 2026 | Use after free in WebRTC in Google Chrome prior to 148.0.7778.179 allowed a remote attacker to execute arbitrary code vi... |
| CVE-2026-9119 | HIGH | 8.8 | 0.5% | May 20, 2026 | Heap buffer overflow in WebRTC in Google Chrome on prior to 148.0.7778.179 allowed a remote attacker to execute arbitrar... |
| CVE-2026-9118 | HIGH | 8.8 | 0.4% | May 20, 2026 | Use after free in XR in Google Chrome on Windows prior to 148.0.7778.179 allowed a remote attacker to execute arbitrary ... |
| CVE-2026-9117 | HIGH | 7.5 | 0.3% | May 20, 2026 | Type Confusion in GFX in Google Chrome on Linux, ChromeOS prior to 148.0.7778.179 allowed a remote attacker who had comp... |
| CVE-2026-9116 | MEDIUM | 4.3 | 0.2% | May 20, 2026 | Insufficient policy enforcement in ServiceWorker in Google Chrome on prior to 148.0.7778.179 allowed a remote attacker t... |
| CVE-2026-9115 | MEDIUM | 4.3 | 0.2% | May 20, 2026 | Insufficient policy enforcement in Service Worker in Google Chrome on prior to 148.0.7778.179 allowed a remote attacker ... |
| CVE-2026-9114 | HIGH | 8.8 | 0.4% | May 20, 2026 | Use after free in QUIC in Google Chrome on prior to 148.0.7778.179 allowed a remote attacker to execute arbitrary code i... |
| CVE-2026-9113 | MEDIUM | 4.3 | 0.2% | May 20, 2026 | Out of bounds read in GPU in Google Chrome on Mac prior to 148.0.7778.179 allowed a remote attacker to perform an out of... |
| CVE-2026-9112 | HIGH | 8.8 | 0.4% | May 20, 2026 | Use after free in GPU in Google Chrome on Windows prior to 148.0.7778.179 allowed a remote attacker to execute arbitrary... |
| CVE-2026-9111 | HIGH | 8.8 | 0.8% | May 20, 2026 | Use after free in WebRTC in Google Chrome on Linux prior to 148.0.7778.179 allowed a remote attacker to execute arbitrar... |
| CVE-2026-9110 | MEDIUM | 4.2 | 0.3% | May 20, 2026 | Inappropriate implementation in UI in Google Chrome on Windows prior to 148.0.7778.179 allowed a remote attacker who had... |
| CVE-2026-9102 | CRITICAL | 9.4 | 0.6% | May 20, 2026 | A path traversal vulnerability exists in the Altium Enterprise Server ComparisonService due to missing filename sanitiza... |
| CVE-2026-9082 | CRITICAL | 9.8 | 84.6% | May 20, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Drupal Drupal core... |
| CVE-2026-47099 | MEDIUM | 6.1 | 0.4% | May 20, 2026 | TeleJSON prior to 6.0.0 contains a DOM-based cross-site scripting vulnerability in the parse() function that allows atta... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now