2026 CVE Vulnerabilities
45,004 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-14028 | MEDIUM | 4.2 | 0.2% | Jun 30, 2026 | Incorrect security UI in Chrome for iOS in Google Chrome on iOS prior to 150.0.7871.47 allowed a remote attacker who con... |
| CVE-2026-14026 | MEDIUM | 4.2 | 0.2% | Jun 30, 2026 | Incorrect security UI in SplitView in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who convinced a use... |
| CVE-2026-14023 | MEDIUM | 6.5 | 0.2% | Jun 30, 2026 | Insufficient validation of untrusted input in SanitizerAPI in Google Chrome prior to 150.0.7871.47 allowed a remote atta... |
| CVE-2026-14022 | MEDIUM | 6.5 | 0.2% | Jun 30, 2026 | Insufficient validation of untrusted input in Network in Google Chrome prior to 150.0.7871.47 allowed a remote attacker ... |
| CVE-2026-14021 | MEDIUM | 6.5 | 0.2% | Jun 30, 2026 | Insufficient policy enforcement in StorageAccessAPI in Google Chrome prior to 150.0.7871.47 allowed a remote attacker wh... |
| CVE-2026-14020 | MEDIUM | 4.3 | 0.2% | Jun 30, 2026 | Insufficient validation of untrusted input in WebXR in Google Chrome prior to 150.0.7871.47 allowed a remote attacker wh... |
| CVE-2026-14019 | MEDIUM | 6.5 | 0.2% | Jun 30, 2026 | Inappropriate implementation in Passwords in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to leak cros... |
| CVE-2026-14016 | MEDIUM | 6.5 | 0.2% | Jun 30, 2026 | Inappropriate implementation in SVG in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to leak cross-orig... |
| CVE-2026-14015 | MEDIUM | 6.5 | 0.2% | Jun 30, 2026 | Race in WebRTC in Google Chrome on Windows prior to 150.0.7871.47 allowed a remote attacker to leak cross-origin data vi... |
| CVE-2026-14014 | MEDIUM | 6.5 | 0.2% | Jun 30, 2026 | Inappropriate implementation in Paint in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to perform UI sp... |
| CVE-2026-14013 | MEDIUM | 4.3 | 0.2% | Jun 30, 2026 | Inappropriate implementation in SVG in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to perform UI spoo... |
| CVE-2026-14012 | MEDIUM | 5.3 | 0.2% | Jun 30, 2026 | Side-channel information leakage in CSS in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to obtain pote... |
| CVE-2026-14010 | MEDIUM | 6.5 | 0.3% | Jun 30, 2026 | Uninitialized Use in Codecs in Google Chrome on Windows prior to 150.0.7871.47 allowed a remote attacker to obtain poten... |
| CVE-2026-14008 | MEDIUM | 6.5 | 0.2% | Jun 30, 2026 | Uninitialized Use in WebXR in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker to obtain potent... |
| CVE-2026-14007 | MEDIUM | 6.5 | 0.2% | Jun 30, 2026 | Insufficient policy enforcement in PermissionsPolicy in Google Chrome prior to 150.0.7871.47 allowed a remote attacker t... |
| CVE-2026-14004 | MEDIUM | 6.5 | 0.2% | Jun 30, 2026 | Inappropriate implementation in CSS in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to leak cross-orig... |
| CVE-2026-14003 | MEDIUM | 4.3 | 0.1% | Jun 30, 2026 | Insufficient policy enforcement in Extensions in Google Chrome prior to 150.0.7871.47 allowed an attacker who convinced ... |
| CVE-2026-14002 | MEDIUM | 6.5 | 0.2% | Jun 30, 2026 | Inappropriate implementation in Geolocation in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had co... |
| CVE-2026-14001 | MEDIUM | 6.1 | 0.2% | Jun 30, 2026 | Inappropriate implementation in Network in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to inject arbi... |
| CVE-2026-14000 | MEDIUM | 6.1 | 0.2% | Jun 30, 2026 | Inappropriate implementation in XML in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to inject arbitrar... |
| CVE-2026-13999 | MEDIUM | 4.3 | 0.1% | Jun 30, 2026 | Insufficient validation of untrusted input in Extensions in Google Chrome prior to 150.0.7871.47 allowed an attacker who... |
| CVE-2026-13998 | MEDIUM | 4.2 | 0.2% | Jun 30, 2026 | Incorrect security UI in File Input in Google Chrome on Mac prior to 150.0.7871.47 allowed a remote attacker who convinc... |
| CVE-2026-13997 | MEDIUM | 4.2 | 0.2% | Jun 30, 2026 | Incorrect security UI in Extensions in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker who con... |
| CVE-2026-13996 | MEDIUM | 6.5 | 0.2% | Jun 30, 2026 | Inappropriate implementation in Permissions in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to perform... |
| CVE-2026-13995 | MEDIUM | 4.3 | 0.2% | Jun 30, 2026 | Insufficient validation of untrusted input in Autofill in Google Chrome on Android prior to 150.0.7871.47 allowed a remo... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now