2026 CVE Vulnerabilities

45,376 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-24610MEDIUM4.3Subscriber Broken Access Control in MetForm Pro <= 3.9.1 versions.
CVE-2026-24575MEDIUM4.3Subscriber Broken Access Control in WishList Member X <= 3.29.0 versions.
CVE-2026-12491MEDIUM4.8A flaw was found in vLLM, an open-source library for large language model inference. This vulnerability arises from impr...
CVE-2026-12469MEDIUM4.3Uninitialized Use in GPU in Google Chrome on Android prior to 149.0.7827.155 allowed a remote attacker to leak cross-ori...
CVE-2026-12463MEDIUM4.7Inappropriate implementation in Views in Google Chrome on Linux prior to 149.0.7827.155 allowed a remote attacker who ha...
CVE-2026-12461MEDIUM6.5Out of bounds read in WebRTC in Google Chrome on Windows prior to 149.0.7827.155 allowed a remote attacker to obtain pot...
CVE-2026-12460MEDIUM4.2Insufficient policy enforcement in File System Access in Google Chrome prior to 149.0.7827.155 allowed a remote attacker...
CVE-2026-12459MEDIUM6.1Inappropriate implementation in Serial in Google Chrome prior to 149.0.7827.155 allowed a remote attacker to inject arbi...
CVE-2026-12457MEDIUM4.2Inappropriate implementation in Extensions in Google Chrome prior to 149.0.7827.155 allowed a remote attacker who had co...
CVE-2026-12456MEDIUM4.2Inappropriate implementation in Extensions in Google Chrome prior to 149.0.7827.155 allowed an attacker who convinced a ...
CVE-2026-12453MEDIUM4.2Insufficient validation of untrusted input in Input in Google Chrome prior to 149.0.7827.155 allowed a remote attacker w...
CVE-2026-12450MEDIUM6.5Inappropriate implementation in Media in Google Chrome prior to 149.0.7827.155 allowed a remote attacker to obtain poten...
CVE-2026-12446MEDIUM4.3Inappropriate implementation in Passwords in Google Chrome prior to 149.0.7827.155 allowed a remote attacker to leak cro...
CVE-2026-12444MEDIUM5.5Out of bounds read in Chromoting in Google Chrome on Windows prior to 149.0.7827.155 allowed a local attacker to obtain ...
CVE-2026-12115MEDIUM6.6The Counter Box – Add Countdowns, Timers & Dynamic Counters to WordPress plugin for WordPress is vulnerable to PHP Objec...
CVE-2026-11975MEDIUM6.2Stored cross-site scripting (XSS) in NewsItemApiController In SimplCommerce prior to commit 6142d3b5 allows an authentic...
CVE-2026-10839MEDIUM5.1Open redirection vulnerability in the authentication system allows an attacker to use manipulated values in the X-Forwar...
CVE-2026-10837MEDIUM5.1Open redirection vulnerability due to insufficient validation of the X-Forwarded-Host HTTP header. An attacker could cre...
CVE-2026-10836MEDIUM5.1Improper handling of HTTP headers that allows a remote attacker to manipulate the value of the Host header using special...
CVE-2026-0064MEDIUM5.5In multiple places, there is a possible persistent denial of service due to resource exhaustion. This could lead to loca...
CVE-2026-46979MEDIUM6.5Vulnerability in the PeopleSoft Enterprise CS Campus Community product of Oracle PeopleSoft (component: Integration and ...
CVE-2026-46877MEDIUM6Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: VMSVGA device). The supported v...
CVE-2026-46871MEDIUM6.5Vulnerability in the MySQL Shell product of Oracle MySQL (component: Shell for VS Code). The supported version that is...
CVE-2026-46869MEDIUM6.5Vulnerability in the MySQL Shell product of Oracle MySQL (component: Shell: Dump and Load). Supported versions that are...
CVE-2026-46825MEDIUM6Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: VMSVGA device). The supported v...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now