2026 CVE Vulnerabilities

47,997 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-13801HIGH8.3Integer overflow in Chromecast in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the...
CVE-2026-13800HIGH7.8Inappropriate implementation in Updater in Google Chrome on Windows prior to 150.0.7871.47 allowed a local attacker to p...
CVE-2026-13799HIGH8.1Use after free in QUIC in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to potentially exploit heap cor...
CVE-2026-13794HIGH7.5Insufficient validation of untrusted input in WebAppInstalls in Google Chrome on Windows prior to 150.0.7871.47 allowed ...
CVE-2026-13791HIGH8.1Insufficient validation of untrusted input in Downloads in Google Chrome prior to 150.0.7871.47 allowed an attacker who ...
CVE-2026-13788HIGH8.8Use after free in Fullscreen in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker to execute arb...
CVE-2026-13787HIGH8.1Use after free in Chromoting in Google Chrome on Windows prior to 150.0.7871.47 allowed a remote attacker to execute arb...
CVE-2026-13786HIGH8.8Use after free in Ozone in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to execute arbitrary code via ...
CVE-2026-13784HIGH8.8Use after free in Views in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage...
CVE-2026-13783HIGH8.8Use after free in Views in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage...
CVE-2026-13779HIGH8.1Use after free in Chromoting in Google Chrome on ChromeOS prior to 150.0.7871.47 allowed a remote attacker to execute ar...
CVE-2026-13778HIGH7.8Use after free in WebUSB in Google Chrome on Mac prior to 150.0.7871.47 allowed a local attacker to execute arbitrary co...
CVE-2026-13777HIGH8.8Insufficient validation of untrusted input in iOSWeb in Google Chrome on iOS prior to 150.0.7871.47 allowed a remote att...
CVE-2026-13774HIGH8.1Use after free in Extensions in Google Chrome prior to 150.0.7871.47 allowed an attacker who convinced a user to install...
CVE-2026-58448HIGH7.1yudao-cloud before 2026.06 contains a broken access control vulnerability in the BPM module that allows any authenticate...
CVE-2026-58447HIGH7.1Invidious through 2.20260626.0, fixed in commit 77ad416, contains a broken object level authorization vulnerability that...
CVE-2026-57585HIGH7.5MessagePack is the serializer implementation for Python msgpack.org. Prior to 1.2.1, there is an Out-of-bounds read/cras...
CVE-2026-52868HIGH8.8An unauthenticated attacker can read worklist records from a directory outside the intended per-AE worklist storage area...
CVE-2026-52196HIGH7.5Buffer Overflow vulnerability in UTT nv518G nv518GV3v3.2.7-210919-161313 allows a remote attacker to cause a denial of s...
CVE-2026-50254HIGH8.7An unauthenticated remote attacker can repeatedly send a single crafted connection request to leak memory. Against store...
CVE-2026-35505HIGH8.7An unauthenticated remote attacker can repeatedly send crafted connection requests to leak memory. In single-process dep...
CVE-2026-44628HIGH8.7An unauthenticated attacker can crash the worklist server with a single crafted query when the server has a valid Called...
CVE-2026-13207HIGH8.7FUXA versions 1.3.1 and prior contain an authentication bypass vulnerability via dot-segment path normalization in the R...
CVE-2026-9836HIGH7.5IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 is affected by an information disclosure vulnerability.
CVE-2026-13759HIGH8.8IBM WebSphere Extreme Scale 8.6.1.0 through 8.6.1.6 ships three ObjectInputStream subclasses (WsObjectInputStream, Objec...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now