2026 CVE Vulnerabilities

47,798 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-56286HIGH8.1Capgo before 12.128.2 contains an authentication bypass vulnerability in the account deletion endpoint that allows delet...
CVE-2026-56249HIGH7.6Capgo before 12.128.2 contains an authorization bypass vulnerability in the channel creation endpoint that allows authen...
CVE-2026-56247HIGH8.8Capgo before 12.128.2 allows org admins to assign org-scoped RBAC roles at app scope without validating role scope compa...
CVE-2026-56233HIGH8.7Capgo before 12.128.2 contains a path traversal vulnerability in the builder upload proxy that allows authenticated user...
CVE-2026-56230HIGH8.8Capgo before 12.128.2 contains a broken object level authorization vulnerability in middlewareKey() that accepts the cli...
CVE-2026-56219HIGH8.7Capgo before 12.128.2 contains a NULL-auth bypass vulnerability in the public.get_org_user_access_rbac function that all...
CVE-2026-54673HIGH8.2electron-updater allows for automatic updates for Electron apps. Prior to 9.7.0, the HTTP redirect handler (HttpExecutor...
CVE-2026-54672HIGH7.8electron-updater allows for automatic updates for Electron apps. Prior to 26.15.0, AppImage targets built by app-builder...
CVE-2026-52198HIGH7.5Buffer Overflow vulnerability in UTT nv518G nv518GV3v3.2.7-210919-161313 allows a remote attacker to cause a denial of s...
CVE-2026-52197HIGH7.5An issue in UTT nv518G nv518GV3v3.2.7-210919-161313 allows a remote attacker to cause a denial of service via the gohead...
CVE-2026-52195HIGH7.5Buffer Overflow vulnerability in UTT nv518G nv518GV3v3.2.7-210919-161313 allows a remote attacker to cause a denial of s...
CVE-2026-52193HIGH7.5Buffer Overflow vulnerability in UTT nv518G nv518GV3v3.2.7-210919-161313 allows a remote attacker to cause a denial of s...
CVE-2026-14151HIGH8.3Inappropriate implementation in AI in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised...
CVE-2026-14149HIGH8.8Use after free in Audio in Google Chrome on Linux prior to 150.0.7871.47 allowed a remote attacker to execute arbitrary ...
CVE-2026-14124HIGH7.8Inappropriate implementation in CredentialProvider in Google Chrome on Windows prior to 150.0.7871.47 allowed a local at...
CVE-2026-14122HIGH8.1Insufficient validation of untrusted input in WebAppInstalls in Google Chrome on Windows prior to 150.0.7871.47 allowed ...
CVE-2026-14115HIGH7.5Insufficient validation of untrusted input in Cast in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who...
CVE-2026-14114HIGH7.5Inappropriate implementation in WebAppInstalls in Google Chrome on Android prior to 150.0.7871.47 allowed a local attack...
CVE-2026-14111HIGH8.1Use after free in WebProtect in Google Chrome prior to 150.0.7871.47 allowed an attacker who convinced a user to install...
CVE-2026-14108HIGH8.8Use after free in PDFium in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to execute arbitrary code ins...
CVE-2026-14107HIGH8.8Use after free in Scheduling in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to execute arbitrary code...
CVE-2026-14102HIGH8.8Use after free in Passwords in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to potentially exploit hea...
CVE-2026-14099HIGH8.8Use after free in Chrome for iOS in Google Chrome on iOS prior to 150.0.7871.47 allowed a remote attacker who convinced ...
CVE-2026-14094HIGH7.8Use after free in Installer in Google Chrome on Windows prior to 150.0.7871.47 allowed a local attacker to perform OS-le...
CVE-2026-14091HIGH8.8Use after free in DevTools in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to execute arbitrary code i...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now