2026 CVE Vulnerabilities

65,063 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-6306HIGH8.8Heap buffer overflow in PDFium in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to execute arbitrary c...
CVE-2026-6305HIGH8.8Heap buffer overflow in PDFium in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to execute arbitrary c...
CVE-2026-6304HIGH8.3Use after free in Graphite in Google Chrome prior to 147.0.7727.101 allowed a remote attacker who had compromised the re...
CVE-2026-6303HIGH8.8Use after free in Codecs in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to execute arbitrary code in...
CVE-2026-6302HIGH8.8Use after free in Video in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to execute arbitrary code ins...
CVE-2026-6301HIGH8.8Type Confusion in Turbofan in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to execute arbitrary code ...
CVE-2026-6300HIGH8.8Use after free in CSS in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to execute arbitrary code insid...
CVE-2026-6299HIGH8.8Use after free in Prerender in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to execute arbitrary code...
CVE-2026-6298MEDIUM4.3Heap buffer overflow in Skia in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to obtain potentially se...
CVE-2026-6297HIGH8.3Use after free in Proxy in Google Chrome prior to 147.0.7727.101 allowed an attacker in a privileged network position to...
CVE-2026-6296CRITICAL9.6Heap buffer overflow in ANGLE in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to potentially perform ...
CVE-2026-40919MEDIUM5.5A flaw was found in GIMP. This vulnerability, a buffer overflow in the `file-seattle-filmworks` plugin, can be exploited...
CVE-2026-40918MEDIUM5.5A flaw was found in GIMP. Processing a specially crafted PVR image file with large dimensions can lead to a denial of se...
CVE-2026-40917HIGH7.1A flaw was found in GIMP. This vulnerability, a heap buffer over-read in the `icns_slurp()` function, occurs when proces...
CVE-2026-40916MEDIUM5.5A flaw was found in GIMP. A stack buffer overflow vulnerability in the TIM image loader's 4BPP decoding path allows a lo...
CVE-2026-40915HIGH7.8A flaw was found in GIMP. A remote attacker could exploit an integer overflow vulnerability in the FITS image loader by ...
CVE-2026-39857MEDIUM5.3ApostropheCMS is an open-source Node.js content management system. Versions 4.28.0 and prior contain an authorization by...
CVE-2026-35569HIGH8.7ApostropheCMS is an open-source Node.js content management system. Versions 4.28.0 and prior contain a stored cross-site...
CVE-2026-33889MEDIUM5.4ApostropheCMS is an open-source Node.js content management system. Versions 4.28.0 and prior contain a stored cross-site...
CVE-2026-33888MEDIUM5.3ApostropheCMS is an open-source Node.js content management system. Versions 4.28.0 and prior contain an authorization by...
CVE-2026-33877LOW3.7ApostropheCMS is an open-source Node.js content management system. Versions 4.28.0 and prior contain a timing side-chann...
CVE-2026-21727LOW3.3A cross-tenant isolation vulnerability was found in Grafana’s Correlations feature affecting legacy correlation records....
CVE-2026-21726MEDIUM5.3The CVE-2021-36156 fix validates the namespace parameter for path traversal sequences after a single URL decode, by doub...
CVE-2026-6383MEDIUM5.4A flaw was found in KubeVirt's Role-Based Access Control (RBAC) evaluation logic. The authorization mechanism improperly...
CVE-2026-6245MEDIUM5.5A flaw was found in the System Security Services Daemon (SSSD). The pam_passkey_child_read_data() function within the PA...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now