2026 CVE Vulnerabilities

67,767 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-93380LOW3.1Race condition in FileSystem in Google Chrome prior to 153.0.8010.52 allowed a remote attacker who had compromised the r...
CVE-2026-93379MEDIUM4.3Incorrect authorization in ORB in Google Chrome prior to 153.0.8010.52 allowed a remote attacker to bypass site isolatio...
CVE-2026-93378LOW3.1Missing authorization in Storage in Google Chrome prior to 153.0.8010.52 allowed a remote attacker who had compromised t...
CVE-2026-93377HIGH8.8Type confusion in V8 in Google Chrome prior to 153.0.8010.52 allowed a remote attacker leveraging social engineering to ...
CVE-2026-93376MEDIUM6.3Out of bounds read in DataTransfer in Google Chrome prior to 153.0.8010.52 allowed a local attacker leveraging social en...
CVE-2026-93375HIGH8.1Incorrect reference resolution in Tracing in Google Chrome on on Windows prior to 153.0.8010.52 allowed a local attacker...
CVE-2026-93374CRITICAL9.6Use after free in Dawn in Google Chrome on on Android prior to 153.0.8010.52 allowed a remote attacker to potentially ex...
CVE-2026-93373CRITICAL9.6Use after free in Extensions in Google Chrome prior to 153.0.8010.52 allowed a remote attacker to execute arbitrary code...
CVE-2026-93372CRITICAL9.6Buffer overflow in WebGL in Google Chrome on on Android prior to 153.0.8010.52 allowed a remote attacker to execute arbi...
CVE-2026-86049HIGH7.1Jupyter Server is the backend for Jupyter web applications. Prior to version 2.21.0, the 5xx request logging path in jup...
CVE-2026-77615HIGH8.7Paella Player is a set of libraries to create a multi stream video player. Prior to Paella Player 2.12.11 (as used in Op...
CVE-2026-77281MEDIUM6.5Caddy is an extensible server platform that uses TLS by default. In version 2.11.3 and earlier, three configuration-depe...
CVE-2026-76154HIGH7.3A stored cross-site scripting vulnerability in the Geomap panel's MapLibre base layer allows a user with the Editor role...
CVE-2026-68537HIGH7.5`fulgur` converts untrusted HTML/CSS into PDF, commonly on a server that processes input supplied by many tenants. In ve...
CVE-2026-68523HIGH7.5`fulgur` converts untrusted HTML/CSS into PDF, commonly on a server that processes input supplied by many tenants. In ve...
CVE-2026-67071MEDIUM6.5HCL DevOps Deploy / HCL Launch is susceptible to an information disclosure vulnerability when processing redacted proper...
CVE-2026-57847——Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-54918MEDIUM5.3NetBox Device Type Library is a collection of community-sourced device type definitions for import into NetBox. In the a...
CVE-2026-54916HIGH8.8NetBox Device Type Library is a collection of community-sourced device type definitions for import into NetBox. The abse...
CVE-2026-54907MEDIUM5.3Caddy Proxy Manager is a web interface for managing Caddy Server reverse proxies and certificates. Prior to 1.5.1, Caddy...
CVE-2026-54604MEDIUM5.3OpenSlide is a C library for reading whole slide image files. Prior to 4.0.1, a behavior change in libtiff 4.7.1 causes ...
CVE-2026-54597HIGH8.3ITFlow provides an IT documentation, ticketing and accounting system for small managed service providers. Prior to versi...
CVE-2026-54596HIGH8.1ITFlow provides an IT documentation, ticketing and accounting system for small managed service providers. Prior to versi...
CVE-2026-54565MEDIUM4.7rhwp is an HWP viewer and editor implemented in Rust and WebAssembly. Prior to rhwp 0.7.15 and rhwp Chrome and Firefox e...
CVE-2026-54521MEDIUM6.1FairEmail is a fully featured, open source, privacy-friendly email app for Android. Prior to 1.2319, the ActivityAMP AMP...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now