2026 CVE Vulnerabilities

67,228 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-33307HIGH7.5Mod_gnutls is a TLS module for Apache HTTPD based on GnuTLS. In versions prior to 0.12.3 and 0.13.0, code for client cer...
CVE-2026-4680HIGH8.8Use after free in FedCM in Google Chrome prior to 146.0.7680.165 allowed a remote attacker to execute arbitrary code ins...
CVE-2026-4679HIGH8.8Integer overflow in Fonts in Google Chrome prior to 146.0.7680.165 allowed a remote attacker to perform an out of bounds...
CVE-2026-4678HIGH8.8Use after free in WebGPU in Google Chrome prior to 146.0.7680.165 allowed a remote attacker to execute arbitrary code in...
CVE-2026-4677HIGH8.8Inappropriate implementation in WebAudio in Google Chrome prior to 146.0.7680.165 allowed a remote attacker to perform a...
CVE-2026-4676HIGH8.8Use after free in Dawn in Google Chrome prior to 146.0.7680.165 allowed a remote attacker to potentially perform a sandb...
CVE-2026-4675HIGH8.8Heap buffer overflow in WebGL in Google Chrome prior to 146.0.7680.165 allowed a remote attacker to perform an out of bo...
CVE-2026-4674HIGH8.8Out of bounds read in CSS in Google Chrome prior to 146.0.7680.165 allowed a remote attacker to perform out of bounds me...
CVE-2026-4673HIGH8.8Heap buffer overflow in WebAudio in Google Chrome prior to 146.0.7680.165 allowed a remote attacker to perform an out of...
CVE-2026-4617HIGH7.3A weakness has been identified in SourceCodester Patients Waiting Area Queue Management System 1.0. The impacted element...
CVE-2026-4616LOW2.4A security flaw has been discovered in bolo-blog up to 2.6.4. The affected element is an unknown function of the file /c...
CVE-2026-33320MEDIUM6.2Dasel is a command-line tool and library for querying, modifying, and transforming data structures. Starting in version ...
CVE-2026-33306HIGH7.5bcrypt-ruby is a Ruby binding for the OpenBSD bcrypt() password hashing algorithm. Prior to version 3.1.22, an integer o...
CVE-2026-33298HIGH7.8llama.cpp is an inference of several LLM models in C/C++. Prior to b7824, an integer overflow vulnerability in the `ggml...
CVE-2026-33290MEDIUM4.3WPGraphQL provides a GraphQL API for WordPress sites. Prior to version 2.10.0, an authorization flaw in updateComment al...
CVE-2026-22739HIGH8.6Vulnerability in Spring Cloud when substituting the profile parameter from a request made to the Spring Cloud Config Ser...
CVE-2026-4615HIGH7.3A vulnerability was identified in SourceCodester Online Catering Reservation 1.0. Impacted is an unknown function of the...
CVE-2026-4614MEDIUM6.3A vulnerability was determined in itsourcecode sanitize or validate this input 1.0. This issue affects some unknown proc...
CVE-2026-4613HIGH7.3A vulnerability was found in SourceCodester E-Commerce Site 1.0. This vulnerability affects unknown code of the file /pr...
CVE-2026-4056MEDIUM5.4The User Registration & Membership plugin for WordPress is vulnerable to unauthorized modification of data due to a miss...
CVE-2026-4021HIGH8.1The Contest Gallery plugin for WordPress is vulnerable to an authentication bypass leading to admin account takeover in ...
CVE-2026-4001CRITICAL9.8The Woocommerce Custom Product Addons Pro plugin for WordPress is vulnerable to Remote Code Execution in all versions up...
CVE-2026-3533HIGH8.8The Jupiter X Core plugin for WordPress is vulnerable to limited file uploads due to missing authorization on import_pop...
CVE-2026-33286CRITICAL9.1Graphiti is a framework that sits on top of models and exposes them via a JSON:API-compliant interface. Versions prior t...
CVE-2026-33283HIGH7.5Ella Core is a 5G core designed for private networks. Versions prior to 1.6.0 panic when processing malformed UL NAS Tra...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now