2026 CVE Vulnerabilities

66,714 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-23403MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: apparmor: fix memory leak in verify_header The fun...
CVE-2026-23402MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: KVM: x86/mmu: Only WARN in direct MMUs when overwri...
CVE-2026-23401MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: KVM: x86/mmu: Drop/zap existing present SPTE even w...
CVE-2026-5259MEDIUM6.3A vulnerability was determined in AutohomeCorp frostmourne up to 1.0. The affected element is an unknown function of the...
CVE-2026-28265HIGH7.1PowerStore, contains a Path Traversal vulnerability in the Service user. A low privileged attacker with local access cou...
CVE-2026-27101HIGH7.2Dell Secure Connect Gateway (SCG) 5.0 Appliance and Application version(s) 5.28.00.xx to 5.32.00.xx, contain(s) an Impro...
CVE-2026-5258HIGH7.3A vulnerability was found in Sanster IOPaint 1.5.3. Impacted is the function _get_file of the file iopaint/file_manager/...
CVE-2026-4748HIGH7.5A regression in the way hashes were calculated caused rules containing the address range syntax (x.x.x.x - y.y.y.y) that...
CVE-2026-5257CRITICAL9.8A vulnerability has been found in code-projects Simple Laundry System 1.0. This issue affects some unknown processing of...
CVE-2026-5256CRITICAL9.8A flaw has been found in code-projects Simple Laundry System 1.0. This vulnerability affects unknown code of the file /m...
CVE-2026-5255MEDIUM6.1A vulnerability was detected in code-projects Simple Laundry System 1.0. This affects an unknown part of the file /delst...
CVE-2026-2696MEDIUM5.3The Export All URLs WordPress plugin before 5.1 generates CSV filenames containing posts URLS (including private posts) ...
CVE-2026-5292HIGH8.8Out of bounds read in WebCodecs in Google Chrome prior to 146.0.7680.178 allowed a remote attacker to perform an out of ...
CVE-2026-5291MEDIUM6.5Inappropriate implementation in WebGL in Google Chrome prior to 146.0.7680.178 allowed a remote attacker to obtain poten...
CVE-2026-5290CRITICAL9.6Use after free in Compositing in Google Chrome prior to 146.0.7680.178 allowed a remote attacker who had compromised the...
CVE-2026-5289CRITICAL9.6Use after free in Navigation in Google Chrome prior to 146.0.7680.178 allowed a remote attacker who had compromised the ...
CVE-2026-5288CRITICAL9.6Use after free in WebView in Google Chrome on Android prior to 146.0.7680.178 allowed a remote attacker who had compromi...
CVE-2026-5287HIGH8.8Use after free in PDF in Google Chrome prior to 146.0.7680.178 allowed a remote attacker to execute arbitrary code insid...
CVE-2026-5286HIGH8.8Use after free in Dawn in Google Chrome prior to 146.0.7680.178 allowed a remote attacker to execute arbitrary code via ...
CVE-2026-5285HIGH8.8Use after free in WebGL in Google Chrome prior to 146.0.7680.178 allowed a remote attacker to execute arbitrary code ins...
CVE-2026-5284HIGH7.5Use after free in Dawn in Google Chrome prior to 146.0.7680.178 allowed a remote attacker who had compromised the render...
CVE-2026-5283MEDIUM6.5Inappropriate implementation in ANGLE in Google Chrome prior to 146.0.7680.178 allowed a remote attacker to leak cross-o...
CVE-2026-5282HIGH8.1Out of bounds read in WebCodecs in Google Chrome prior to 146.0.7680.178 allowed a remote attacker to perform an out of ...
CVE-2026-5281HIGH8.8Use after free in Dawn in Google Chrome prior to 146.0.7680.178 allowed a remote attacker who had compromised the render...
CVE-2026-5280HIGH8.8Use after free in WebCodecs in Google Chrome prior to 146.0.7680.178 allowed a remote attacker to execute arbitrary code...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now