2026 CVE Vulnerabilities
44,996 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-56333 | MEDIUM | 5.3 | 0.2% | Jun 30, 2026 | Capgo before 12.128.2 contains a server-side validation bypass vulnerability in organization security settings that allo... |
| CVE-2026-56331 | MEDIUM | 6.9 | 0.3% | Jun 30, 2026 | Capgo before 12.128.2 contains improper error handling in the /private/accept_invitation endpoint that returns HTTP 500 ... |
| CVE-2026-56327 | MEDIUM | 6.9 | 0.3% | Jun 30, 2026 | Capgo before 12.128.2 contains an information disclosure vulnerability in the public.invite_user_to_org RPC function tha... |
| CVE-2026-56318 | MEDIUM | 6.9 | 0.3% | Jun 30, 2026 | Capgo before 12.128.2 contains an information disclosure vulnerability in the /private/validate_password_compliance endp... |
| CVE-2026-56277 | MEDIUM | 6.5 | 0.2% | Jun 30, 2026 | Flowise before 3.1.2 sets Access-Control-Allow-Origin to a hardcoded wildcard (*) on its text-to-speech (TTS) generation... |
| CVE-2026-56264 | MEDIUM | 6.1 | 0.5% | Jun 30, 2026 | Crawl4AI before 0.8.7 contains an arbitrary JavaScript execution vulnerability in the Docker API server's /execute_js en... |
| CVE-2026-56224 | MEDIUM | 5.4 | 0.2% | Jun 30, 2026 | Capgo console.capgo.app/login before 12.128.2 accepts access_token and refresh_token in URL query parameters, automatica... |
| CVE-2026-55223 | MEDIUM | 6.3 | 0.3% | Jun 30, 2026 | c3p0 is a JDBC Connection pooling library. In versions prior to 0.14.0, c3p0 in combination with other libraries, can c... |
| CVE-2026-50040 | MEDIUM | 6.1 | 0.2% | Jun 30, 2026 | Storage Concentrator (SC & SCVM) is vulnerable to reflected cross-site scripting due to unsanitized content being echoed... |
| CVE-2026-28322 | MEDIUM | 5.6 | 0.2% | Jun 30, 2026 | SolarWinds Database Performance Analyzer was found to be affected by a stored cross-site scripting vulnerability, which ... |
| CVE-2026-14156 | MEDIUM | 6.5 | 0.2% | Jun 30, 2026 | Insufficient policy enforcement in StorageAccessAPI in Google Chrome prior to 150.0.7871.47 allowed a remote attacker wh... |
| CVE-2026-14155 | MEDIUM | 6.5 | 0.2% | Jun 30, 2026 | Insufficient policy enforcement in StorageAccessAPI in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to... |
| CVE-2026-14154 | MEDIUM | 4.8 | 0.1% | Jun 30, 2026 | Inappropriate implementation in DevTools in Google Chrome prior to 150.0.7871.47 allowed an attacker who convinced a use... |
| CVE-2026-14153 | MEDIUM | 5.3 | 0.2% | Jun 30, 2026 | Inappropriate implementation in Glic in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who convinced a u... |
| CVE-2026-14150 | MEDIUM | 5.4 | 0.2% | Jun 30, 2026 | Insufficient validation of untrusted input in Speech in Google Chrome prior to 150.0.7871.47 allowed a remote attacker w... |
| CVE-2026-14148 | MEDIUM | 6.5 | 0.2% | Jun 30, 2026 | Type Confusion in CSS in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to obtain potentially sensitive ... |
| CVE-2026-14147 | MEDIUM | 6.1 | 0.2% | Jun 30, 2026 | Inappropriate implementation in CSS in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to inject arbitrar... |
| CVE-2026-14146 | MEDIUM | 6.5 | 0.2% | Jun 30, 2026 | Inappropriate implementation in CSS in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to leak cross-orig... |
| CVE-2026-14145 | MEDIUM | 6.1 | 0.2% | Jun 30, 2026 | Inappropriate implementation in CSS in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to inject arbitrar... |
| CVE-2026-14144 | MEDIUM | 4.2 | 0.1% | Jun 30, 2026 | Incorrect security UI in Views in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who convinced a user to... |
| CVE-2026-14143 | MEDIUM | 4.3 | 0.2% | Jun 30, 2026 | Incorrect security UI in Passwords in Google Chrome on iOS prior to 150.0.7871.47 allowed a remote attacker to perform U... |
| CVE-2026-14142 | MEDIUM | 5.4 | 0.2% | Jun 30, 2026 | Inappropriate implementation in Extensions in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had com... |
| CVE-2026-14141 | MEDIUM | 4.3 | 0.2% | Jun 30, 2026 | Incorrect security UI in Document Picture-in-Picture in Google Chrome on Android prior to 150.0.7871.47 allowed a remote... |
| CVE-2026-14140 | MEDIUM | 4.3 | 0.2% | Jun 30, 2026 | Insufficient validation of untrusted input in Input in Google Chrome on Android prior to 150.0.7871.47 allowed a remote ... |
| CVE-2026-14139 | MEDIUM | 4.2 | 0.2% | Jun 30, 2026 | Inappropriate implementation in TabStrip in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who convinced... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now