2026 CVE Vulnerabilities

67,331 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-4452HIGH8.8Integer overflow in ANGLE in Google Chrome on Windows prior to 146.0.7680.153 allowed a remote attacker to potentially e...
CVE-2026-4451HIGH8.8Insufficient validation of untrusted input in Navigation in Google Chrome prior to 146.0.7680.153 allowed a remote attac...
CVE-2026-4450HIGH8.8Out of bounds write in V8 in Google Chrome prior to 146.0.7680.153 allowed a remote attacker to potentially exploit heap...
CVE-2026-4449HIGH8.8Use after free in Blink in Google Chrome prior to 146.0.7680.153 allowed a remote attacker to potentially exploit heap c...
CVE-2026-4448HIGH8.8Heap buffer overflow in ANGLE in Google Chrome prior to 146.0.7680.153 allowed a remote attacker to potentially exploit ...
CVE-2026-4447HIGH8.8Inappropriate implementation in V8 in Google Chrome prior to 146.0.7680.153 allowed a remote attacker to execute arbitra...
CVE-2026-4446HIGH8.8Use after free in WebRTC in Google Chrome prior to 146.0.7680.153 allowed a remote attacker to potentially exploit heap ...
CVE-2026-4445HIGH8.8Use after free in WebRTC in Google Chrome prior to 146.0.7680.153 allowed a remote attacker to potentially exploit heap ...
CVE-2026-4444HIGH8.8Stack buffer overflow in WebRTC in Google Chrome prior to 146.0.7680.153 allowed a remote attacker to potentially exploi...
CVE-2026-4443HIGH8.8Heap buffer overflow in WebAudio in Google Chrome prior to 146.0.7680.153 allowed a remote attacker to execute arbitrary...
CVE-2026-4442HIGH8.8Heap buffer overflow in CSS in Google Chrome prior to 146.0.7680.153 allowed a remote attacker to potentially exploit he...
CVE-2026-4441HIGH8.8Use after free in Base in Google Chrome prior to 146.0.7680.153 allowed a remote attacker to potentially exploit heap co...
CVE-2026-4440HIGH8.8Out of bounds read and write in WebGL in Google Chrome prior to 146.0.7680.153 allowed a remote attacker to perform arbi...
CVE-2026-4439HIGH8.8Out of bounds memory access in WebGL in Google Chrome on Android prior to 146.0.7680.153 allowed a remote attacker to po...
CVE-2026-32881MEDIUM5.3ewe is a Gleam web server. ewe is a Gleam web server. Versions 0.6.0 through 3.0.4 are vulnerable to authentication bypa...
CVE-2026-32880MEDIUM6.4ChurchCRM is an open-source church management system. Versions prior to 7.0.2 allow an admin user to edit JSON type syst...
CVE-2026-32875HIGH7.5UltraJSON is a fast JSON encoder and decoder written in pure C with bindings for Python 3.7+. Versions 5.10 through 5.11...
CVE-2026-32874HIGH7.5UltraJSON is a fast JSON encoder and decoder written in pure C with bindings for Python 3.7+. Versions 5.4.0 through 5.1...
CVE-2026-32873HIGH7.5ewe is a Gleam web server. Versions 0.8.0 through 3.0.4 contain a bug in the handle_trailers function where rejected tra...
CVE-2026-32817CRITICAL9.1Admidio is an open-source user management solution. In versions 5.0.0 through 5.0.6, the documents and files module does...
CVE-2026-32813HIGH8Admidio is an open-source user management solution. Versions 5.0.6 and below are vulnerable to arbitrary SQL Injection t...
CVE-2026-32812MEDIUM6.8Admidio is an open-source user management solution. In versions 5.0.0 through 5.0.6, unrestricted URL fetch in the SSO M...
CVE-2026-32811HIGH7.5Heimdall is a cloud native Identity Aware Proxy and Access Control Decision service. When using Heimdall in envoy gRPC d...
CVE-2026-32808HIGH8.1pyLoad is a free and open-source download manager written in Python. Versions before 0.5.0b3.dev97 are vulnerable to pat...
CVE-2026-32711HIGH7.8pydicom is a pure Python package for working with DICOM files. Versions 2.0.0-rc.1 through 3.0.1 are vulnerable to Path ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now