2026 CVE Vulnerabilities
47,997 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-13801 | HIGH | 8.3 | 0.2% | Jun 30, 2026 | Integer overflow in Chromecast in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the... |
| CVE-2026-13800 | HIGH | 7.8 | 0.1% | Jun 30, 2026 | Inappropriate implementation in Updater in Google Chrome on Windows prior to 150.0.7871.47 allowed a local attacker to p... |
| CVE-2026-13799 | HIGH | 8.1 | 0.2% | Jun 30, 2026 | Use after free in QUIC in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to potentially exploit heap cor... |
| CVE-2026-13794 | HIGH | 7.5 | 0.3% | Jun 30, 2026 | Insufficient validation of untrusted input in WebAppInstalls in Google Chrome on Windows prior to 150.0.7871.47 allowed ... |
| CVE-2026-13791 | HIGH | 8.1 | 0.2% | Jun 30, 2026 | Insufficient validation of untrusted input in Downloads in Google Chrome prior to 150.0.7871.47 allowed an attacker who ... |
| CVE-2026-13788 | HIGH | 8.8 | 0.3% | Jun 30, 2026 | Use after free in Fullscreen in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker to execute arb... |
| CVE-2026-13787 | HIGH | 8.1 | 0.2% | Jun 30, 2026 | Use after free in Chromoting in Google Chrome on Windows prior to 150.0.7871.47 allowed a remote attacker to execute arb... |
| CVE-2026-13786 | HIGH | 8.8 | 0.3% | Jun 30, 2026 | Use after free in Ozone in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to execute arbitrary code via ... |
| CVE-2026-13784 | HIGH | 8.8 | 0.2% | Jun 30, 2026 | Use after free in Views in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage... |
| CVE-2026-13783 | HIGH | 8.8 | 0.2% | Jun 30, 2026 | Use after free in Views in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage... |
| CVE-2026-13779 | HIGH | 8.1 | 0.2% | Jun 30, 2026 | Use after free in Chromoting in Google Chrome on ChromeOS prior to 150.0.7871.47 allowed a remote attacker to execute ar... |
| CVE-2026-13778 | HIGH | 7.8 | 0.2% | Jun 30, 2026 | Use after free in WebUSB in Google Chrome on Mac prior to 150.0.7871.47 allowed a local attacker to execute arbitrary co... |
| CVE-2026-13777 | HIGH | 8.8 | 0.2% | Jun 30, 2026 | Insufficient validation of untrusted input in iOSWeb in Google Chrome on iOS prior to 150.0.7871.47 allowed a remote att... |
| CVE-2026-13774 | HIGH | 8.1 | 0.2% | Jun 30, 2026 | Use after free in Extensions in Google Chrome prior to 150.0.7871.47 allowed an attacker who convinced a user to install... |
| CVE-2026-58448 | HIGH | 7.1 | 0.2% | Jun 30, 2026 | yudao-cloud before 2026.06 contains a broken access control vulnerability in the BPM module that allows any authenticate... |
| CVE-2026-58447 | HIGH | 7.1 | 0.2% | Jun 30, 2026 | Invidious through 2.20260626.0, fixed in commit 77ad416, contains a broken object level authorization vulnerability that... |
| CVE-2026-57585 | HIGH | 7.5 | 0.3% | Jun 30, 2026 | MessagePack is the serializer implementation for Python msgpack.org. Prior to 1.2.1, there is an Out-of-bounds read/cras... |
| CVE-2026-52868 | HIGH | 8.8 | 0.4% | Jun 30, 2026 | An unauthenticated attacker can read worklist records from a directory outside the intended per-AE worklist storage area... |
| CVE-2026-52196 | HIGH | 7.5 | 0.5% | Jun 30, 2026 | Buffer Overflow vulnerability in UTT nv518G nv518GV3v3.2.7-210919-161313 allows a remote attacker to cause a denial of s... |
| CVE-2026-50254 | HIGH | 8.7 | 0.4% | Jun 30, 2026 | An unauthenticated remote attacker can repeatedly send a single crafted connection request to leak memory. Against store... |
| CVE-2026-35505 | HIGH | 8.7 | 0.4% | Jun 30, 2026 | An unauthenticated remote attacker can repeatedly send crafted connection requests to leak memory. In single-process dep... |
| CVE-2026-44628 | HIGH | 8.7 | 0.4% | Jun 30, 2026 | An unauthenticated attacker can crash the worklist server with a single crafted query when the server has a valid Called... |
| CVE-2026-13207 | HIGH | 8.7 | 0.4% | Jun 30, 2026 | FUXA versions 1.3.1 and prior contain an authentication bypass vulnerability via dot-segment path normalization in the R... |
| CVE-2026-9836 | HIGH | 7.5 | 0.2% | Jun 30, 2026 | IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 is affected by an information disclosure vulnerability. |
| CVE-2026-13759 | HIGH | 8.8 | 0.3% | Jun 30, 2026 | IBM WebSphere Extreme Scale 8.6.1.0 through 8.6.1.6 ships three ObjectInputStream subclasses (WsObjectInputStream, Objec... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now