2026 CVE Vulnerabilities

65,063 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-40176HIGH7.8Composer is a dependency manager for PHP. Versions 1.0 through 2.2.26 and 2.3 through 2.9.5 contain a command injection ...
CVE-2026-40173CRITICAL9.4Dgraph is an open source distributed GraphQL database. Versions 25.3.1 and prior contain an unauthenticated credential d...
CVE-2026-22676HIGH8.5Barracuda RMM versions prior to 2025.2.2 contain a privilege escalation vulnerability that allows local attackers to gai...
CVE-2026-6385MEDIUM6.5A flaw was found in FFmpeg. A remote attacker could exploit this vulnerability by providing a specially crafted MPEG-PS/...
CVE-2026-6384HIGH7.8A flaw was found in gimp. This buffer overflow vulnerability in the GIF image loading component's `ReadJeffsImage` funct...
CVE-2026-6364MEDIUM6.5Out of bounds read in Skia in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to obtain potentially sens...
CVE-2026-6363HIGH8.8Type Confusion in V8 in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to potentially perform out of bo...
CVE-2026-6362MEDIUM4.3Use after free in Codecs in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to potentially perform out o...
CVE-2026-6361HIGH8.3Heap buffer overflow in PDFium in Google Chrome on Windows prior to 147.0.7727.101 allowed a remote attacker who convinc...
CVE-2026-6360HIGH8.8Use after free in FileSystem in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to potentially exploit o...
CVE-2026-6359HIGH8.8Use after free in Video in Google Chrome on Windows prior to 147.0.7727.101 allowed a remote attacker who had compromise...
CVE-2026-6358HIGH8.8Use after free in XR in Google Chrome on Android prior to 147.0.7727.101 allowed a remote attacker to perform an out of ...
CVE-2026-6319HIGH7.5Use after free in Payments in Google Chrome on Android prior to 147.0.7727.101 allowed a remote attacker who convinced a...
CVE-2026-6318HIGH8.8Use after free in Codecs in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to execute arbitrary code in...
CVE-2026-6317HIGH8.8Use after free in Cast in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to execute arbitrary code via ...
CVE-2026-6316HIGH8.8Use after free in Forms in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to execute arbitrary code ins...
CVE-2026-6315HIGH8.8Use after free in Permissions in Google Chrome on Android prior to 147.0.7727.101 allowed a remote attacker who convince...
CVE-2026-6314HIGH8.3Out of bounds write in GPU in Google Chrome prior to 147.0.7727.101 allowed a remote attacker who had compromised the GP...
CVE-2026-6313LOW3.1Insufficient policy enforcement in CORS in Google Chrome prior to 147.0.7727.101 allowed a remote attacker who had compr...
CVE-2026-6312LOW3.1Insufficient policy enforcement in Passwords in Google Chrome prior to 147.0.7727.101 allowed a remote attacker who had ...
CVE-2026-6311HIGH8.3Uninitialized Use in Accessibility in Google Chrome on Windows prior to 147.0.7727.101 allowed a remote attacker who had...
CVE-2026-6310HIGH8.3Use after free in Dawn in Google Chrome prior to 147.0.7727.101 allowed a remote attacker who had compromised the render...
CVE-2026-6309HIGH8.3Use after free in Viz in Google Chrome prior to 147.0.7727.101 allowed a remote attacker who had compromised the rendere...
CVE-2026-6308HIGH7.5Out of bounds read in Media in Google Chrome prior to 147.0.7727.101 allowed a remote attacker who convinced a user to e...
CVE-2026-6307HIGH8.8Type Confusion in Turbofan in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to execute arbitrary code ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now