2026 CVE Vulnerabilities
66,719 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-5284 | HIGH | 7.5 | 0.3% | Apr 1, 2026 | Use after free in Dawn in Google Chrome prior to 146.0.7680.178 allowed a remote attacker who had compromised the render... |
| CVE-2026-5283 | MEDIUM | 6.5 | 0.2% | Apr 1, 2026 | Inappropriate implementation in ANGLE in Google Chrome prior to 146.0.7680.178 allowed a remote attacker to leak cross-o... |
| CVE-2026-5282 | HIGH | 8.1 | 0.2% | Apr 1, 2026 | Out of bounds read in WebCodecs in Google Chrome prior to 146.0.7680.178 allowed a remote attacker to perform an out of ... |
| CVE-2026-5281 | HIGH | 8.8 | 5.0% | Apr 1, 2026 | Use after free in Dawn in Google Chrome prior to 146.0.7680.178 allowed a remote attacker who had compromised the render... |
| CVE-2026-5280 | HIGH | 8.8 | 0.4% | Apr 1, 2026 | Use after free in WebCodecs in Google Chrome prior to 146.0.7680.178 allowed a remote attacker to execute arbitrary code... |
| CVE-2026-5279 | HIGH | 8.8 | 0.3% | Apr 1, 2026 | Object corruption in V8 in Google Chrome prior to 146.0.7680.178 allowed a remote attacker to execute arbitrary code ins... |
| CVE-2026-5278 | HIGH | 8.8 | 0.4% | Apr 1, 2026 | Use after free in Web MIDI in Google Chrome on Android prior to 146.0.7680.178 allowed a remote attacker to execute arbi... |
| CVE-2026-5277 | HIGH | 7.5 | 0.3% | Apr 1, 2026 | Integer overflow in ANGLE in Google Chrome on Windows prior to 146.0.7680.178 allowed a remote attacker who had compromi... |
| CVE-2026-5276 | MEDIUM | 6.5 | 0.2% | Apr 1, 2026 | Insufficient policy enforcement in WebUSB in Google Chrome prior to 146.0.7680.178 allowed a remote attacker to obtain p... |
| CVE-2026-5275 | HIGH | 8.8 | 0.4% | Apr 1, 2026 | Heap buffer overflow in ANGLE in Google Chrome on Mac prior to 146.0.7680.178 allowed a remote attacker to execute arbit... |
| CVE-2026-5274 | HIGH | 8.8 | 0.3% | Apr 1, 2026 | Integer overflow in Codecs in Google Chrome prior to 146.0.7680.178 allowed a remote attacker to perform arbitrary read/... |
| CVE-2026-5273 | MEDIUM | 6.3 | 0.3% | Apr 1, 2026 | Use after free in CSS in Google Chrome prior to 146.0.7680.178 allowed a remote attacker to execute arbitrary code insid... |
| CVE-2026-5272 | HIGH | 8.8 | 0.4% | Apr 1, 2026 | Heap buffer overflow in GPU in Google Chrome prior to 146.0.7680.178 allowed a remote attacker to execute arbitrary code... |
| CVE-2026-5254 | LOW | 3.5 | 0.2% | Apr 1, 2026 | A security vulnerability has been detected in welovemedia FFmate up to 2.0.15. Affected by this issue is some unknown fu... |
| CVE-2026-5253 | LOW | 3.5 | 0.2% | Apr 1, 2026 | A weakness has been identified in bufanyun HotGo 1.0/2.0. Affected by this vulnerability is an unknown functionality of ... |
| CVE-2026-5252 | LOW | 3.5 | 0.3% | Apr 1, 2026 | A security flaw has been discovered in z-9527 admin 1.0/2.0. Affected is an unknown function of the file /server/routes/... |
| CVE-2026-5251 | MEDIUM | 6.3 | 0.2% | Apr 1, 2026 | A vulnerability was identified in z-9527 admin 1.0/2.0. This impacts an unknown function of the file /server/routes/user... |
| CVE-2026-5249 | LOW | 3.5 | 0.2% | Apr 1, 2026 | A vulnerability was found in gougucms 4.08.18. This impacts an unknown function of the file \gougucms-master\app\admin\v... |
| CVE-2026-4947 | HIGH | 7.1 | 0.2% | Apr 1, 2026 | Addressed a potential insecure direct object reference (IDOR) vulnerability in the signing invitation acceptance process... |
| CVE-2026-4374 | CRITICAL | 9.1 | 0.2% | Apr 1, 2026 | Improper Restriction of XML External Entity Reference vulnerability in RTI Connext Professional (Recording Service,Routi... |
| CVE-2026-3831 | MEDIUM | 4.3 | 0.2% | Apr 1, 2026 | The Database for Contact Form 7, WPforms, Elementor forms plugin for WordPress is vulnerable to unauthorized access of d... |
| CVE-2026-3780 | HIGH | 7.8 | 0.1% | Apr 1, 2026 | The application's installer runs with elevated privileges but resolves system executables and DLLs using untrusted searc... |
| CVE-2026-3779 | HIGH | 7.8 | 0.3% | Apr 1, 2026 | The application's list box calculate array logic keeps stale references to page or form objects after they are deleted o... |
| CVE-2026-3778 | MEDIUM | 5.5 | 0.1% | Apr 1, 2026 | The application does not detect or guard against cyclic PDF object references while handling JavaScript in PDF. When pag... |
| CVE-2026-3777 | HIGH | 7.8 | 0.1% | Apr 1, 2026 | The application does not properly validate the lifetime and validity of internal view cache pointers after JavaScript ch... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now