2026 CVE Vulnerabilities

44,973 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-14402MEDIUM6.5Uninitialized Use in ANGLE in Google Chrome on Windows prior to 150.0.7871.46 allowed a remote attacker to obtain potent...
CVE-2026-14399MEDIUM6.5Uninitialized Use in Dawn in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to obtain potentially sensit...
CVE-2026-14396MEDIUM6.5Out of bounds read in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to leak cross-origin data ...
CVE-2026-14391MEDIUM5.3Integer overflow in ANGLE in Google Chrome on Windows prior to 150.0.7871.46 allowed a remote attacker who had compromis...
CVE-2026-14388MEDIUM6.5Out of bounds read in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to obtain potentially sens...
CVE-2026-14386MEDIUM6.5Out of bounds read in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to obtain potentially sens...
CVE-2026-14384MEDIUM6.5Out of bounds read in ANGLE in Google Chrome on Windows prior to 150.0.7871.46 allowed a remote attacker to leak cross-o...
CVE-2026-14381MEDIUM6.5Incorrect security UI in WebAppInstalls in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to perform UI ...
CVE-2026-55793MEDIUM5.9Craft CMS is a content management system (CMS). In versions 5.0.0-RC1 through 5.9.22, an author-level control panel user...
CVE-2026-54704MEDIUM6.5OpenTelemetry Java Instrumentation provides OpenTelemetry auto-instrumentation and instrumentation libraries for Java. I...
CVE-2026-54262MEDIUM4.3Wagtail is an open source content management system built on Django. In versions prior to 7.0.8, 7.3.3 and 7.4.2, a low-...
CVE-2026-54261MEDIUM6.5Wagtail is an open source content management system built on Django. In versions prior to 7.0.8, 7.3.3 and 7.4.2, due to...
CVE-2026-54259MEDIUM4.3Wagtail is an open source content management system built on Django. In versions prior to 7.0.8, 7.3.3 and 7.4.2, the Do...
CVE-2026-36911MEDIUM5.5A division-by-zero vulnerability in the CStreamSwitcherOutputPin::DecideBufferSize function of Aleksoid1978 MPC-BE befor...
CVE-2026-36910MEDIUM5.5An access violation in the BaseSplitterFile::Read function of Aleksoid1978 MPC-BE before commit 4341cb3 allows attackers...
CVE-2026-36909MEDIUM6.2A NULL pointer dereference in the AP4_TkhdAtom::GetTrackId() function of Aleksoid1978 MPC-BE before commit 4341cb3 allow...
CVE-2026-55886MEDIUM6.3Jodit Editor is a WYSIWYG editor with written in pure TypeScript file and image editing capabilities. Versions prior to ...
CVE-2026-55661MEDIUM4.8Tina is a headless content management system. In versions prior to @tinacms/mdx 2.1.7 and tinacms 3.9.3, rich-text par...
CVE-2026-54786MEDIUM5Wasmtime is a runtime for WebAssembly. All versions prior to 24.0.10; versions 25.0.0 through those before 36.0.11; ver...
CVE-2026-54756MEDIUM6.3Jodit Editor is a WYSIWYG editor with written in pure TypeScript file and image editing capabilities. In versions prior ...
CVE-2026-54720MEDIUM5.4Silverstripe Framework is a PHP framework which powers the Silverstripe CMS. In versions prior to 6.2.2, the "Insert med...
CVE-2026-14340MEDIUM5An incorrect authorization vulnerability was identified in GitHub Enterprise Server that allowed a user-to-server token ...
CVE-2026-55688MEDIUM4The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HT...
CVE-2026-54908MEDIUM6.3Pion DTLS is a Go implementation of Datagram Transport Layer Security. Versions prior to 3.1.4 are vulnerable to Remote ...
CVE-2026-54164MEDIUM6.5API Platform Core is a system to create hypermedia-driven REST and GraphQL APIs. In versions prior to 4.1.30, 4.2.26 and...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now