2026 CVE Vulnerabilities
65,537 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-5871 | HIGH | 8.8 | 0.3% | Apr 8, 2026 | Type Confusion in V8 in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to execute arbitrary code inside ... |
| CVE-2026-5870 | HIGH | 8.8 | 0.3% | Apr 8, 2026 | Integer overflow in Skia in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to execute arbitrary code ins... |
| CVE-2026-5869 | MEDIUM | 4.3 | 0.2% | Apr 8, 2026 | Heap buffer overflow in WebML in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to obtain potentially se... |
| CVE-2026-5868 | HIGH | 8.8 | 0.3% | Apr 8, 2026 | Heap buffer overflow in ANGLE in Google Chrome on Mac prior to 147.0.7727.55 allowed a remote attacker to execute arbitr... |
| CVE-2026-5867 | MEDIUM | 4.3 | 0.3% | Apr 8, 2026 | Heap buffer overflow in WebML in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to obtain potentially se... |
| CVE-2026-5866 | HIGH | 8.8 | 0.3% | Apr 8, 2026 | Use after free in Media in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to execute arbitrary code insi... |
| CVE-2026-5865 | HIGH | 8.8 | 0.4% | Apr 8, 2026 | Type Confusion in V8 in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to execute arbitrary code inside ... |
| CVE-2026-5864 | MEDIUM | 4.3 | 0.2% | Apr 8, 2026 | Heap buffer overflow in WebAudio in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to obtain potentially... |
| CVE-2026-5863 | HIGH | 8.8 | 0.3% | Apr 8, 2026 | Inappropriate implementation in V8 in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to execute arbitrar... |
| CVE-2026-5862 | HIGH | 8.8 | 0.3% | Apr 8, 2026 | Inappropriate implementation in V8 in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to execute arbitrar... |
| CVE-2026-5861 | HIGH | 8.8 | 0.3% | Apr 8, 2026 | Use after free in V8 in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to execute arbitrary code inside ... |
| CVE-2026-5860 | HIGH | 8.8 | 0.5% | Apr 8, 2026 | Use after free in WebRTC in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to execute arbitrary code ins... |
| CVE-2026-5859 | HIGH | 8.8 | 0.4% | Apr 8, 2026 | Integer overflow in WebML in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to potentially exploit heap ... |
| CVE-2026-5858 | HIGH | 8.8 | 0.6% | Apr 8, 2026 | Heap buffer overflow in WebML in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to execute arbitrary cod... |
| CVE-2026-5810 | LOW | 3.5 | 0.2% | Apr 8, 2026 | A flaw has been found in SourceCodester Sales and Inventory System 1.0. Affected is an unknown function of the file /del... |
| CVE-2026-5808 | MEDIUM | 5.3 | 0.3% | Apr 8, 2026 | A vulnerability was detected in openstatusHQ openstatus up to 1b678e71a85961ae319cbb214a8eae634059330c. This impacts an ... |
| CVE-2026-5806 | LOW | 3.5 | 0.2% | Apr 8, 2026 | A security vulnerability has been detected in code-projects Easy Blog Site 1.0. This affects an unknown function of the ... |
| CVE-2026-5711 | MEDIUM | 6.4 | 0.2% | Apr 8, 2026 | The Post Blocks & Tools plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'sliderStyle' block at... |
| CVE-2026-40037 | HIGH | 7.1 | 0.2% | Apr 8, 2026 | OpenClaw before 2026.3.31 (patched in 2026.4.8) contains a request body replay vulnerability in fetchWithSsrFGuard that ... |
| CVE-2026-40036 | HIGH | 8.7 | 0.5% | Apr 8, 2026 | Unfurl before 2026.04 contains an unbounded zlib decompression vulnerability in parse_compressed.py that allows remote a... |
| CVE-2026-40035 | CRITICAL | 9.3 | 0.6% | Apr 8, 2026 | Unfurl through 2025.08 contains an improper input validation vulnerability in config parsing that enables Flask debug mo... |
| CVE-2026-40032 | HIGH | 8.5 | 0.7% | Apr 8, 2026 | UAC (Unix-like Artifacts Collector) before 3.3.0-rc1 contains a command injection vulnerability in the placeholder subst... |
| CVE-2026-40031 | HIGH | 8.5 | 0.1% | Apr 8, 2026 | MemProcFS before 5.17 contains multiple unsafe library-loading patterns that enable DLL and shared-library hijacking acr... |
| CVE-2026-40030 | HIGH | 8.4 | 0.8% | Apr 8, 2026 | parseusbs before 1.9 contains an OS command injection vulnerability where the volume listing path argument (-v flag) is ... |
| CVE-2026-40029 | HIGH | 7.8 | 0.8% | Apr 8, 2026 | parseusbs before 1.9 contains an OS command injection vulnerability in parseUSBs.py where LNK file paths are passed unsa... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now