2026 CVE Vulnerabilities
45,440 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-15118 | HIGH | 8.8 | 0.2% | Jul 8, 2026 | Use after free in Input in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to execute arbitrary code ins... |
| CVE-2026-15117 | HIGH | 7.5 | 0.2% | Jul 8, 2026 | Use after free in Payments in Google Chrome prior to 150.0.7871.115 allowed a remote attacker who convinced a user to en... |
| CVE-2026-15116 | HIGH | 8.8 | 0.2% | Jul 8, 2026 | Use after free in Actor in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to execute arbitrary code ins... |
| CVE-2026-15114 | HIGH | 8.8 | 0.1% | Jul 8, 2026 | Out of bounds read and write in Codecs in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to potentially... |
| CVE-2026-15112 | HIGH | 8.8 | 0.2% | Jul 8, 2026 | Use after free in Ozone in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to potentially exploit heap c... |
| CVE-2026-15111 | HIGH | 7.5 | 0.2% | Jul 8, 2026 | Use after free in Views in Google Chrome prior to 150.0.7871.115 allowed a remote attacker who convinced a user to engag... |
| CVE-2026-15110 | HIGH | 8.8 | 0.1% | Jul 8, 2026 | Use after free in Extensions in Google Chrome prior to 150.0.7871.115 allowed an attacker who convinced a user to instal... |
| CVE-2026-15107 | HIGH | 8.8 | 0.2% | Jul 8, 2026 | Use after free in IndexedDB in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to execute arbitrary code... |
| CVE-2026-55878 | HIGH | 7.8 | 0.1% | Jul 8, 2026 | Symfony UX is a JavaScript ecosystem for Symfony. From 2.32.0 before 2.36.1 and from 3.0.0 before 3.2.0, the ux:install ... |
| CVE-2026-55849 | HIGH | 8.5 | 0.2% | Jul 8, 2026 | @cyclonedx/cyclonedx-npm creates CycloneDX Software Bill of Materials from npm projects. From 2.1.0 before 5.0.0, the CL... |
| CVE-2026-55830 | HIGH | 8.3 | 0.2% | Jul 8, 2026 | RestrictedPython is a tool that helps to define a subset of the Python language which allows to provide a program input ... |
| CVE-2026-55470 | HIGH | 7.5 | 0.4% | Jul 8, 2026 | HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to 6.9.10... |
| CVE-2026-51535 | HIGH | 7.5 | 0.2% | Jul 8, 2026 | In OpENer 2.3.0 (commit 76b95cf), a resource exhaustion (Denial of Service) vulnerability exists in its network processi... |
| CVE-2026-44161 | HIGH | 7.2 | 0.4% | Jul 8, 2026 | Fluentd collects events from various data sources and writes them to files, RDBMS, NoSQL, IaaS, SaaS, Hadoop and so on. ... |
| CVE-2026-44160 | HIGH | 7.5 | 0.6% | Jul 8, 2026 | Fluentd collects events from various data sources and writes them to files, RDBMS, NoSQL, IaaS, SaaS, Hadoop and so on. ... |
| CVE-2026-44025 | HIGH | 7.5 | 0.5% | Jul 8, 2026 | Fluentd collects events from various data sources and writes them to files, RDBMS, NoSQL, IaaS, SaaS, Hadoop and so on. ... |
| CVE-2026-35552 | HIGH | 8.1 | 0.2% | Jul 8, 2026 | In CAXperts UPVWebServices 2.4.2212.603 through 2.7.6 and UDiTH Portal 2026.0.0 through 2026.2.0, an authenticated remot... |
| CVE-2026-10037 | HIGH | 8.8 | 0.1% | Jul 8, 2026 | A sandbox escape vulnerability exists in the OpenJDK packages provided in Ubuntu. The .jar MIME handlers installed by th... |
| CVE-2026-60105 | HIGH | 8.6 | 0.3% | Jul 8, 2026 | Monsta FTP before 2.14.5 contains a server-side request forgery vulnerability in the fetchRemoteFile action caused by an... |
| CVE-2026-59818 | HIGH | 8.1 | 0.4% | Jul 8, 2026 | etcd is a distributed key-value store for the data of a distributed system. Prior to 3.5.32 and 3.6.13, when etcd is con... |
| CVE-2026-58525 | HIGH | 8.2 | 0.4% | Jul 8, 2026 | Improper access control in Microsoft Edge (Chromium-based) allows an unauthorized attacker to bypass a security feature ... |
| CVE-2026-58208 | HIGH | 7.5 | 0.5% | Jul 8, 2026 | NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.14.3 and 2.... |
| CVE-2026-58192 | HIGH | 8.6 | 0.3% | Jul 8, 2026 | Appium is a cross-platform automation framework for all kinds of apps, built on top of the W3C WebDriver protocol. Prior... |
| CVE-2026-57480 | HIGH | 8.7 | 0.3% | Jul 8, 2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.9.1-a... |
| CVE-2026-56669 | HIGH | 7.5 | 0.4% | Jul 8, 2026 | Elysia is a Typescript framework for request validation, type inference, OpenAPI documentation, and client-server commun... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now