2026 CVE Vulnerabilities
43,261 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-28751 | LOW | 3.3 | 0.1% | May 19, 2026 | in OpenHarmony v6.0 and prior versions allow a local attacker cause DOS. |
| CVE-2026-27781 | LOW | 3.3 | 0.1% | May 19, 2026 | in OpenHarmony v6.0 and prior versions allow a local attacker cause DOS. |
| CVE-2026-25110 | LOW | 3.3 | 0.1% | May 19, 2026 | in OpenHarmony v6.0 and prior versions allow a local attacker cause DOS. |
| CVE-2026-27964 | LOW | 3.9 | 0.1% | May 18, 2026 | FacturaScripts is an open source accounting and invoicing software. Versions 2025.7 and prior contain a Reflected Cross-... |
| CVE-2026-4643 | LOW | 3.5 | 0.2% | May 18, 2026 | Mattermost Desktop App versions <=6.1 6.0.1 5.4.13.0 fail to prevent server-rendered content from closing an underlying ... |
| CVE-2026-6334 | LOW | 3.8 | 0.1% | May 18, 2026 | Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13 fail to enforce client identity binding during the OAuth autho... |
| CVE-2026-8770 | LOW | 3.3 | 0.3% | May 18, 2026 | A vulnerability was identified in continuedev continue up to 1.2.22. This affects the function lsTool of the file core/t... |
| CVE-2026-8741 | LOW | 3.1 | 0.3% | May 17, 2026 | A vulnerability has been found in EMQX up to 6.2.0. This affects an unknown function of the file apps/emqx/src/emqx_pers... |
| CVE-2026-45316 | LOW | 3.5 | 0.2% | May 15, 2026 | Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.3, the P... |
| CVE-2026-45803 | LOW | 3.5 | 0.2% | May 15, 2026 | `gh` is GitHub’s official command line tool. From 1.6.0 to before 2.92.0, a security vulnerability has been identified i... |
| CVE-2026-41963 | LOW | 2.8 | 0.1% | May 15, 2026 | Stack overflow vulnerability in the media platform. Impact: Successful exploitation of this vulnerability may affect ava... |
| CVE-2026-41962 | LOW | 3.6 | 0.1% | May 15, 2026 | Permission control vulnerability in the app management and control module. Impact: Successful exploitation of this vulne... |
| CVE-2026-0428 | LOW | 1.8 | 0.1% | May 15, 2026 | Insufficient parameter sanitization in TEE SOC Driver could allow an attacker to issue a malformed DRV_SOC_CMD_ID_SRIOV_... |
| CVE-2026-45781 | LOW | 3.5 | 0.2% | May 14, 2026 | The MCP Registry provides MCP clients with a list of MCP servers, like an app store for MCP servers. Prior to 1.7.9, OCI... |
| CVE-2026-8579 | LOW | 3.1 | 0.1% | May 14, 2026 | Insufficient validation of untrusted input in Skia in Google Chrome prior to 148.0.7778.168 allowed a remote attacker wh... |
| CVE-2026-8578 | LOW | 3.1 | 0.2% | May 14, 2026 | Out of bounds read in GPU in Google Chrome on Linux prior to 148.0.7778.168 allowed a remote attacker who had compromise... |
| CVE-2026-8572 | LOW | 3.1 | 0.2% | May 14, 2026 | Insufficient policy enforcement in Network in Google Chrome on Android prior to 148.0.7778.168 allowed a remote attacker... |
| CVE-2026-8556 | LOW | 3.1 | 0.2% | May 14, 2026 | Inappropriate implementation in ANGLE in Google Chrome on Windows prior to 148.0.7778.168 allowed a remote attacker who ... |
| CVE-2026-8554 | LOW | 3.1 | 0.2% | May 14, 2026 | Type Confusion in ANGLE in Google Chrome on Windows prior to 148.0.7778.168 allowed a remote attacker who had compromise... |
| CVE-2026-8553 | LOW | 3.1 | 0.2% | May 14, 2026 | Use after free in GPU in Google Chrome prior to 148.0.7778.168 allowed a remote attacker who had compromised the rendere... |
| CVE-2026-8545 | LOW | 3.1 | 0.2% | May 14, 2026 | Object corruption in Compositing in Google Chrome prior to 148.0.7778.168 allowed a remote attacker who had compromised ... |
| CVE-2026-8536 | LOW | 3.1 | 0.2% | May 14, 2026 | Insufficient validation of untrusted input in ReadingMode in Google Chrome on Mac prior to 148.0.7778.168 allowed a remo... |
| CVE-2026-44638 | LOW | 2.5 | 0.1% | May 14, 2026 | libsixel is a SIXEL encoder/decoder implementation derived from kmiya's sixel. From to 1.8.7-r1, a wrong NULL check aft... |
| CVE-2026-44589 | LOW | 3.7 | 0.2% | May 14, 2026 | Nuxt OG Image generates OG Images with Vue templates in Nuxt. The isBlockedUrl() denylist introduced in nuxt-og-image@6.... |
| CVE-2026-6923 | LOW | 3.8 | 0.1% | May 14, 2026 | A side-channel attack, which requires a physical presence to the TPM, can lead to extraction of an Elliptic Curve Diffie... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now