2026 CVE Vulnerabilities
47,636 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-14394 | HIGH | 8.8 | 0.2% | Jul 1, 2026 | Use after free in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially exploit heap corru... |
| CVE-2026-14393 | HIGH | 8.8 | 0.2% | Jul 1, 2026 | Use after free in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to execute arbitrary code inside ... |
| CVE-2026-14389 | HIGH | 8.3 | 0.2% | Jul 1, 2026 | Integer overflow in Skia in Google Chrome prior to 150.0.7871.46 allowed a remote attacker who had compromised the rende... |
| CVE-2026-14385 | HIGH | 8.8 | 0.2% | Jul 1, 2026 | Heap buffer overflow in ANGLE in Google Chrome on Mac prior to 150.0.7871.46 allowed a remote attacker to perform out of... |
| CVE-2026-14383 | HIGH | 8.8 | 0.3% | Jul 1, 2026 | Inappropriate implementation in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to execute arbitrar... |
| CVE-2026-54712 | HIGH | 7.5 | 0.2% | Jul 1, 2026 | OpenTelemetry Java Instrumentation provides OpenTelemetry auto-instrumentation and instrumentation libraries for Java. I... |
| CVE-2026-54263 | HIGH | 7.3 | 0.2% | Jul 1, 2026 | Wagtail is an open source content management system built on Django. In versions prior to 7.0.8, 7.3.3 and 7.4.2, reflec... |
| CVE-2026-52190 | HIGH | 7.5 | 0.2% | Jul 1, 2026 | Buffer Overflow vulnerability in UTT nv518G nv518GV3v3.2.7-210919-161313 allows a remote attacker to cause a denial of s... |
| CVE-2026-38891 | HIGH | 7.5 | 0.2% | Jul 1, 2026 | An improper input validation in the gazebo_ros_diff_drive.cpp component of gazebo_plugins v3.9.0 allows attackers to cau... |
| CVE-2026-36912 | HIGH | 7.5 | 0.2% | Jul 1, 2026 | A NULL pointer dereference in the AP4_AtomSampleTable::GetSample() function of Aleksoid1978 MPC-BE before commit 4341cb3... |
| CVE-2026-58263 | HIGH | 7.2 | 0.2% | Jul 1, 2026 | Jodit Editor is a WYSIWYG editor with a built-in file browser & image editor. In versions prior to 4.12.28, the built-in... |
| CVE-2026-55660 | HIGH | 7.6 | 0.2% | Jul 1, 2026 | Tina is a headless content management system. In versions prior to @tinacms/app 2.5.6 and tinacms 3.9.3, cross-origin po... |
| CVE-2026-55153 | HIGH | 7.1 | 0.3% | Jul 1, 2026 | mchange-commons-java is a Java library of shared utility classes used by mchange projects like the c3p0 connection pool.... |
| CVE-2026-54074 | HIGH | 7.8 | 0.2% | Jul 1, 2026 | Tina is a headless content management system. @tinacms/cli versions prior to 2.4.3 contain a Remote Code Execution vulne... |
| CVE-2026-50521 | HIGH | 8.3 | 0.8% | Jul 1, 2026 | Use after free in Microsoft Edge (Chromium-based) allows an authorized attacker to execute code over a network. |
| CVE-2026-58593 | HIGH | 8.7 | 0.2% | Jul 1, 2026 | NodeBB does not bind the claimed author of an inbound ActivityPub object to the authenticated remote actor. The inbound ... |
| CVE-2026-58592 | HIGH | 8.9 | 0.3% | Jul 1, 2026 | Ladybird contains a dangling-reference memory-safety flaw in its WebAssembly ESM-integration module loader. When a JavaS... |
| CVE-2026-14265 | HIGH | 8.8 | 0.4% | Jul 1, 2026 | Deserialization of untrusted data in the RemoteQueryCachePlugin in Amazon Web Services AWS Advanced JDBC Wrapper 3.3.0 t... |
| CVE-2026-58451 | HIGH | 7.1 | 0.4% | Jul 1, 2026 | Horde IMP before 7.0.1 contains a path traversal vulnerability in lib/Compose.php that allows authenticated attackers to... |
| CVE-2026-49119 | HIGH | 8.7 | 0.7% | Jul 1, 2026 | Gradio before 6.16.0 contain a path traversal vulnerability in the FileExplorer component's preprocess() method that all... |
| CVE-2026-41121 | HIGH | 7.8 | 0.1% | Jul 1, 2026 | Dell Device Management Agent, versions prior to DDMA 26.05, contain an Improper Link Resolution Before File Access ('Lin... |
| CVE-2026-13760 | HIGH | 7.3 | — | Jul 1, 2026 | OS command injection in the NodejsFunction Docker bundling pipeline (OsCommand helper) in AWS aws-cdk-lib on all platfor... |
| CVE-2026-57736 | HIGH | 7.4 | — | Jul 1, 2026 | Insertion of Sensitive Information Into Sent Data vulnerability in HubSpot allows Retrieve Embedded Sensitive Data. Thi... |
| CVE-2026-57723 | HIGH | 7.4 | — | Jul 1, 2026 | Cross-Site Request Forgery (CSRF) vulnerability in e4jvikwp VikBooking Hotel Booking Engine & PMS allows Path Traversal.... |
| CVE-2026-54428 | HIGH | 7.5 | 0.6% | Jul 1, 2026 | Allocation of resources without limits or throttling in the HTTP/2 HPACK decoder in Apache HttpComponents Core (5.4.2 an... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now