2026 CVE Vulnerabilities
44,973 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-14402 | MEDIUM | 6.5 | 0.2% | Jul 1, 2026 | Uninitialized Use in ANGLE in Google Chrome on Windows prior to 150.0.7871.46 allowed a remote attacker to obtain potent... |
| CVE-2026-14399 | MEDIUM | 6.5 | 0.2% | Jul 1, 2026 | Uninitialized Use in Dawn in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to obtain potentially sensit... |
| CVE-2026-14396 | MEDIUM | 6.5 | 0.2% | Jul 1, 2026 | Out of bounds read in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to leak cross-origin data ... |
| CVE-2026-14391 | MEDIUM | 5.3 | 0.2% | Jul 1, 2026 | Integer overflow in ANGLE in Google Chrome on Windows prior to 150.0.7871.46 allowed a remote attacker who had compromis... |
| CVE-2026-14388 | MEDIUM | 6.5 | 0.2% | Jul 1, 2026 | Out of bounds read in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to obtain potentially sens... |
| CVE-2026-14386 | MEDIUM | 6.5 | 0.2% | Jul 1, 2026 | Out of bounds read in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to obtain potentially sens... |
| CVE-2026-14384 | MEDIUM | 6.5 | 0.2% | Jul 1, 2026 | Out of bounds read in ANGLE in Google Chrome on Windows prior to 150.0.7871.46 allowed a remote attacker to leak cross-o... |
| CVE-2026-14381 | MEDIUM | 6.5 | 0.2% | Jul 1, 2026 | Incorrect security UI in WebAppInstalls in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to perform UI ... |
| CVE-2026-55793 | MEDIUM | 5.9 | 0.4% | Jul 1, 2026 | Craft CMS is a content management system (CMS). In versions 5.0.0-RC1 through 5.9.22, an author-level control panel user... |
| CVE-2026-54704 | MEDIUM | 6.5 | 0.2% | Jul 1, 2026 | OpenTelemetry Java Instrumentation provides OpenTelemetry auto-instrumentation and instrumentation libraries for Java. I... |
| CVE-2026-54262 | MEDIUM | 4.3 | 0.2% | Jul 1, 2026 | Wagtail is an open source content management system built on Django. In versions prior to 7.0.8, 7.3.3 and 7.4.2, a low-... |
| CVE-2026-54261 | MEDIUM | 6.5 | 0.2% | Jul 1, 2026 | Wagtail is an open source content management system built on Django. In versions prior to 7.0.8, 7.3.3 and 7.4.2, due to... |
| CVE-2026-54259 | MEDIUM | 4.3 | 0.2% | Jul 1, 2026 | Wagtail is an open source content management system built on Django. In versions prior to 7.0.8, 7.3.3 and 7.4.2, the Do... |
| CVE-2026-36911 | MEDIUM | 5.5 | 0.1% | Jul 1, 2026 | A division-by-zero vulnerability in the CStreamSwitcherOutputPin::DecideBufferSize function of Aleksoid1978 MPC-BE befor... |
| CVE-2026-36910 | MEDIUM | 5.5 | 0.2% | Jul 1, 2026 | An access violation in the BaseSplitterFile::Read function of Aleksoid1978 MPC-BE before commit 4341cb3 allows attackers... |
| CVE-2026-36909 | MEDIUM | 6.2 | 0.2% | Jul 1, 2026 | A NULL pointer dereference in the AP4_TkhdAtom::GetTrackId() function of Aleksoid1978 MPC-BE before commit 4341cb3 allow... |
| CVE-2026-55886 | MEDIUM | 6.3 | 0.3% | Jul 1, 2026 | Jodit Editor is a WYSIWYG editor with written in pure TypeScript file and image editing capabilities. Versions prior to ... |
| CVE-2026-55661 | MEDIUM | 4.8 | 0.2% | Jul 1, 2026 | Tina is a headless content management system. In versions prior to @tinacms/mdx 2.1.7 and tinacms 3.9.3, rich-text par... |
| CVE-2026-54786 | MEDIUM | 5 | 0.2% | Jul 1, 2026 | Wasmtime is a runtime for WebAssembly. All versions prior to 24.0.10; versions 25.0.0 through those before 36.0.11; ver... |
| CVE-2026-54756 | MEDIUM | 6.3 | 0.3% | Jul 1, 2026 | Jodit Editor is a WYSIWYG editor with written in pure TypeScript file and image editing capabilities. In versions prior ... |
| CVE-2026-54720 | MEDIUM | 5.4 | 0.3% | Jul 1, 2026 | Silverstripe Framework is a PHP framework which powers the Silverstripe CMS. In versions prior to 6.2.2, the "Insert med... |
| CVE-2026-14340 | MEDIUM | 5 | 0.3% | Jul 1, 2026 | An incorrect authorization vulnerability was identified in GitHub Enterprise Server that allowed a user-to-server token ... |
| CVE-2026-55688 | MEDIUM | 4 | 0.2% | Jul 1, 2026 | The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HT... |
| CVE-2026-54908 | MEDIUM | 6.3 | 0.3% | Jul 1, 2026 | Pion DTLS is a Go implementation of Datagram Transport Layer Security. Versions prior to 3.1.4 are vulnerable to Remote ... |
| CVE-2026-54164 | MEDIUM | 6.5 | 0.2% | Jul 1, 2026 | API Platform Core is a system to create hypermedia-driven REST and GraphQL APIs. In versions prior to 4.1.30, 4.2.26 and... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now