2026 CVE Vulnerabilities
65,063 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-6306 | HIGH | 8.8 | 0.3% | Apr 15, 2026 | Heap buffer overflow in PDFium in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to execute arbitrary c... |
| CVE-2026-6305 | HIGH | 8.8 | 0.3% | Apr 15, 2026 | Heap buffer overflow in PDFium in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to execute arbitrary c... |
| CVE-2026-6304 | HIGH | 8.3 | 0.3% | Apr 15, 2026 | Use after free in Graphite in Google Chrome prior to 147.0.7727.101 allowed a remote attacker who had compromised the re... |
| CVE-2026-6303 | HIGH | 8.8 | 0.4% | Apr 15, 2026 | Use after free in Codecs in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to execute arbitrary code in... |
| CVE-2026-6302 | HIGH | 8.8 | 0.3% | Apr 15, 2026 | Use after free in Video in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to execute arbitrary code ins... |
| CVE-2026-6301 | HIGH | 8.8 | 0.4% | Apr 15, 2026 | Type Confusion in Turbofan in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to execute arbitrary code ... |
| CVE-2026-6300 | HIGH | 8.8 | 0.3% | Apr 15, 2026 | Use after free in CSS in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to execute arbitrary code insid... |
| CVE-2026-6299 | HIGH | 8.8 | 0.3% | Apr 15, 2026 | Use after free in Prerender in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to execute arbitrary code... |
| CVE-2026-6298 | MEDIUM | 4.3 | 0.3% | Apr 15, 2026 | Heap buffer overflow in Skia in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to obtain potentially se... |
| CVE-2026-6297 | HIGH | 8.3 | 0.2% | Apr 15, 2026 | Use after free in Proxy in Google Chrome prior to 147.0.7727.101 allowed an attacker in a privileged network position to... |
| CVE-2026-6296 | CRITICAL | 9.6 | 0.3% | Apr 15, 2026 | Heap buffer overflow in ANGLE in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to potentially perform ... |
| CVE-2026-40919 | MEDIUM | 5.5 | 0.3% | Apr 15, 2026 | A flaw was found in GIMP. This vulnerability, a buffer overflow in the `file-seattle-filmworks` plugin, can be exploited... |
| CVE-2026-40918 | MEDIUM | 5.5 | 0.2% | Apr 15, 2026 | A flaw was found in GIMP. Processing a specially crafted PVR image file with large dimensions can lead to a denial of se... |
| CVE-2026-40917 | HIGH | 7.1 | 0.2% | Apr 15, 2026 | A flaw was found in GIMP. This vulnerability, a heap buffer over-read in the `icns_slurp()` function, occurs when proces... |
| CVE-2026-40916 | MEDIUM | 5.5 | 0.2% | Apr 15, 2026 | A flaw was found in GIMP. A stack buffer overflow vulnerability in the TIM image loader's 4BPP decoding path allows a lo... |
| CVE-2026-40915 | HIGH | 7.8 | 0.4% | Apr 15, 2026 | A flaw was found in GIMP. A remote attacker could exploit an integer overflow vulnerability in the FITS image loader by ... |
| CVE-2026-39857 | MEDIUM | 5.3 | 0.4% | Apr 15, 2026 | ApostropheCMS is an open-source Node.js content management system. Versions 4.28.0 and prior contain an authorization by... |
| CVE-2026-35569 | HIGH | 8.7 | 0.3% | Apr 15, 2026 | ApostropheCMS is an open-source Node.js content management system. Versions 4.28.0 and prior contain a stored cross-site... |
| CVE-2026-33889 | MEDIUM | 5.4 | 0.2% | Apr 15, 2026 | ApostropheCMS is an open-source Node.js content management system. Versions 4.28.0 and prior contain a stored cross-site... |
| CVE-2026-33888 | MEDIUM | 5.3 | 0.5% | Apr 15, 2026 | ApostropheCMS is an open-source Node.js content management system. Versions 4.28.0 and prior contain an authorization by... |
| CVE-2026-33877 | LOW | 3.7 | 0.4% | Apr 15, 2026 | ApostropheCMS is an open-source Node.js content management system. Versions 4.28.0 and prior contain a timing side-chann... |
| CVE-2026-21727 | LOW | 3.3 | 0.2% | Apr 15, 2026 | A cross-tenant isolation vulnerability was found in Grafana’s Correlations feature affecting legacy correlation records.... |
| CVE-2026-21726 | MEDIUM | 5.3 | 0.4% | Apr 15, 2026 | The CVE-2021-36156 fix validates the namespace parameter for path traversal sequences after a single URL decode, by doub... |
| CVE-2026-6383 | MEDIUM | 5.4 | 0.1% | Apr 15, 2026 | A flaw was found in KubeVirt's Role-Based Access Control (RBAC) evaluation logic. The authorization mechanism improperly... |
| CVE-2026-6245 | MEDIUM | 5.5 | 0.1% | Apr 15, 2026 | A flaw was found in the System Security Services Daemon (SSSD). The pam_passkey_child_read_data() function within the PA... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now