2026 CVE Vulnerabilities

64,824 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-7910CRITICAL9.6Use after free in Views in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the render...
CVE-2026-7909LOW3.1Inappropriate implementation in ServiceWorker in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had ...
CVE-2026-7908CRITICAL9.6Use after free in Fullscreen in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to potentially perform a ...
CVE-2026-7907HIGH8.8Use after free in DOM in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to execute arbitrary code inside...
CVE-2026-7906HIGH8.8Use after free in SVG in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to execute arbitrary code inside...
CVE-2026-7905HIGH8.3Insufficient validation of untrusted input in Media in Google Chrome on Android prior to 148.0.7778.96 allowed a remote ...
CVE-2026-7904MEDIUM4.3Out of bounds read in Fonts in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to perform an out of bound...
CVE-2026-7903HIGH8.8Integer overflow in ANGLE in Google Chrome on Mac,Windows prior to 148.0.7778.96 allowed a remote attacker to potentiall...
CVE-2026-7902HIGH8.8Out of bounds memory access in V8 in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to execute arbitrary...
CVE-2026-7901HIGH8.8Use after free in ANGLE in Google Chrome on Mac prior to 148.0.7778.96 allowed a remote attacker to execute arbitrary co...
CVE-2026-7900HIGH8.3Heap buffer overflow in ANGLE in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the ...
CVE-2026-7899HIGH8.8Out of bounds read and write in V8 in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to execute arbitrar...
CVE-2026-7898HIGH8.8Use after free in Chromoting in Google Chrome on Linux prior to 148.0.7778.96 allowed a remote attacker to execute arbit...
CVE-2026-7897HIGH7.5Use after free in Mobile in Google Chrome on iOS prior to 148.0.7778.96 allowed a remote attacker who convinced a user t...
CVE-2026-7896HIGH8.8Integer overflow in Blink in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to potentially exploit heap ...
CVE-2026-41938HIGH8.8Vvveb before version 1.0.8.2 contains an unrestricted file upload vulnerability in the media upload handler that allows ...
CVE-2026-41936HIGH8.6Vvveb before version 1.0.8.2 contains an XML external entity (XXE) injection vulnerability in the admin Tools/Import fea...
CVE-2026-41934HIGH8.8Vvveb before version 1.0.8.2 contains an authenticated remote code execution vulnerability in the admin code editor that...
CVE-2026-41931MEDIUM6.9Vvveb before version 1.0.8.2 contains an information disclosure vulnerability that allows unauthenticated attackers to o...
CVE-2026-41930CRITICAL9.8Vvveb before version 1.0.8.2 contains a hard-coded credentials vulnerability in its docker-compose-apache.yaml configura...
CVE-2026-34474HIGH7.5Sensitive data exposure leading to admin/WLAN credential leak in ZTE ZXHN H298A 1.1 and H108N 2.6. A crafted request to ...
CVE-2026-34473HIGH7.5Unauthenticated DoS in ZTE H8102E, H168N, H167A, H199A, H288A, H198A, H267A, H267N, H268A, H388X, H196A, H369A, H268N, H...
CVE-2026-0300CRITICAL9.8A buffer overflow vulnerability in the User-ID™ Authentication Portal (aka Captive Portal) service of Palo Alto Networks...
CVE-2026-33079HIGH7.5In versions 3.0.0a1 through 3.2.0 of Mistune, there is a ReDoS (Regular Expression Denial of Service) vulnerability in `...
CVE-2026-29090HIGH8.8### Summary A SQL injection vulnerability exists in Rucio versions 1.30.0 and later before 35.8.5, 38.5.5, 39.4.2, and ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now