2026 CVE Vulnerabilities

65,537 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-5871HIGH8.8Type Confusion in V8 in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to execute arbitrary code inside ...
CVE-2026-5870HIGH8.8Integer overflow in Skia in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to execute arbitrary code ins...
CVE-2026-5869MEDIUM4.3Heap buffer overflow in WebML in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to obtain potentially se...
CVE-2026-5868HIGH8.8Heap buffer overflow in ANGLE in Google Chrome on Mac prior to 147.0.7727.55 allowed a remote attacker to execute arbitr...
CVE-2026-5867MEDIUM4.3Heap buffer overflow in WebML in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to obtain potentially se...
CVE-2026-5866HIGH8.8Use after free in Media in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to execute arbitrary code insi...
CVE-2026-5865HIGH8.8Type Confusion in V8 in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to execute arbitrary code inside ...
CVE-2026-5864MEDIUM4.3Heap buffer overflow in WebAudio in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to obtain potentially...
CVE-2026-5863HIGH8.8Inappropriate implementation in V8 in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to execute arbitrar...
CVE-2026-5862HIGH8.8Inappropriate implementation in V8 in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to execute arbitrar...
CVE-2026-5861HIGH8.8Use after free in V8 in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to execute arbitrary code inside ...
CVE-2026-5860HIGH8.8Use after free in WebRTC in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to execute arbitrary code ins...
CVE-2026-5859HIGH8.8Integer overflow in WebML in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to potentially exploit heap ...
CVE-2026-5858HIGH8.8Heap buffer overflow in WebML in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to execute arbitrary cod...
CVE-2026-5810LOW3.5A flaw has been found in SourceCodester Sales and Inventory System 1.0. Affected is an unknown function of the file /del...
CVE-2026-5808MEDIUM5.3A vulnerability was detected in openstatusHQ openstatus up to 1b678e71a85961ae319cbb214a8eae634059330c. This impacts an ...
CVE-2026-5806LOW3.5A security vulnerability has been detected in code-projects Easy Blog Site 1.0. This affects an unknown function of the ...
CVE-2026-5711MEDIUM6.4The Post Blocks & Tools plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'sliderStyle' block at...
CVE-2026-40037HIGH7.1OpenClaw before 2026.3.31 (patched in 2026.4.8) contains a request body replay vulnerability in fetchWithSsrFGuard that ...
CVE-2026-40036HIGH8.7Unfurl before 2026.04 contains an unbounded zlib decompression vulnerability in parse_compressed.py that allows remote a...
CVE-2026-40035CRITICAL9.3Unfurl through 2025.08 contains an improper input validation vulnerability in config parsing that enables Flask debug mo...
CVE-2026-40032HIGH8.5UAC (Unix-like Artifacts Collector) before 3.3.0-rc1 contains a command injection vulnerability in the placeholder subst...
CVE-2026-40031HIGH8.5MemProcFS before 5.17 contains multiple unsafe library-loading patterns that enable DLL and shared-library hijacking acr...
CVE-2026-40030HIGH8.4parseusbs before 1.9 contains an OS command injection vulnerability where the volume listing path argument (-v flag) is ...
CVE-2026-40029HIGH7.8parseusbs before 1.9 contains an OS command injection vulnerability in parseUSBs.py where LNK file paths are passed unsa...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now