2026 CVE Vulnerabilities
47,548 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-11197 | MEDIUM | 6.5 | 0.2% | Jun 4, 2026 | Insufficient policy enforcement in Workers in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had com... |
| CVE-2026-11196 | MEDIUM | 6.5 | 0.2% | Jun 4, 2026 | Type Confusion in XML in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to obtain potentially sensitive ... |
| CVE-2026-11195 | MEDIUM | 6.5 | 0.2% | Jun 4, 2026 | Inappropriate implementation in MHTML in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who convinced a ... |
| CVE-2026-11194 | MEDIUM | 6.5 | 0.2% | Jun 4, 2026 | Inappropriate implementation in Network in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-... |
| CVE-2026-11193 | MEDIUM | 6.5 | 0.2% | Jun 4, 2026 | Insufficient policy enforcement in Password Manager in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to... |
| CVE-2026-11192 | MEDIUM | 4.3 | 0.2% | Jun 4, 2026 | Insufficient validation of untrusted input in Password Manager in Google Chrome prior to 149.0.7827.53 allowed a remote ... |
| CVE-2026-11190 | MEDIUM | 6.5 | 0.2% | Jun 4, 2026 | Inappropriate implementation in Extensions in Google Chrome prior to 149.0.7827.53 allowed an attacker who convinced a u... |
| CVE-2026-11189 | MEDIUM | 6.5 | 0.2% | Jun 4, 2026 | Insufficient validation of untrusted input in DevTools in Google Chrome prior to 149.0.7827.53 allowed an attacker who c... |
| CVE-2026-11187 | MEDIUM | 6.3 | 0.2% | Jun 4, 2026 | Inappropriate implementation in Glic in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to bypass navigat... |
| CVE-2026-11186 | MEDIUM | 6.1 | 0.2% | Jun 4, 2026 | Inappropriate implementation in CSS in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to inject arbitrar... |
| CVE-2026-11184 | MEDIUM | 6.3 | 0.2% | Jun 4, 2026 | Insufficient policy enforcement in Actor in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to bypass nav... |
| CVE-2026-11183 | MEDIUM | 6.5 | 0.2% | Jun 4, 2026 | Out of bounds read in GWP-ASan in Google Chrome prior to 149.0.7827.53 allowed a local attacker to obtain potentially se... |
| CVE-2026-11182 | MEDIUM | 6.5 | 0.2% | Jun 4, 2026 | Inappropriate implementation in SVG in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-orig... |
| CVE-2026-11181 | MEDIUM | 6.3 | 0.1% | Jun 4, 2026 | Inappropriate implementation in Media Session in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to bypas... |
| CVE-2026-11180 | MEDIUM | 6.5 | 0.2% | Jun 4, 2026 | Inappropriate implementation in SVG in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-orig... |
| CVE-2026-11178 | MEDIUM | 4.3 | 0.2% | Jun 4, 2026 | Insufficient policy enforcement in WebView in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker ... |
| CVE-2026-11176 | MEDIUM | 6.5 | 0.2% | Jun 4, 2026 | Inappropriate implementation in Media in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-or... |
| CVE-2026-11174 | MEDIUM | 5.3 | 0.2% | Jun 4, 2026 | Inappropriate implementation in Site Isolation in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had... |
| CVE-2026-11168 | MEDIUM | 6.5 | 0.2% | Jun 4, 2026 | Inappropriate implementation in Extensions in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had com... |
| CVE-2026-11166 | MEDIUM | 6.8 | 0.2% | Jun 4, 2026 | Inappropriate implementation in SVG in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to inject arbitrar... |
| CVE-2026-11162 | MEDIUM | 4.3 | 0.2% | Jun 4, 2026 | Inappropriate implementation in CSS in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-orig... |
| CVE-2026-11161 | MEDIUM | 4.3 | 0.2% | Jun 4, 2026 | Inappropriate implementation in DataTransfer in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak c... |
| CVE-2026-11160 | MEDIUM | 6.5 | 0.2% | Jun 4, 2026 | Out of bounds read in Input in Google Chrome on Linux prior to 149.0.7827.53 allowed a remote attacker to obtain potenti... |
| CVE-2026-11159 | MEDIUM | 4.3 | 0.2% | Jun 4, 2026 | Uninitialized Use in Skia in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data vi... |
| CVE-2026-11157 | MEDIUM | 5.4 | 0.1% | Jun 4, 2026 | Script injection in Accessibility in Google Chrome prior to 149.0.7827.53 allowed an attacker who convinced a user to in... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now