2026 CVE Vulnerabilities
47,565 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-10977 | MEDIUM | 6.5 | 0.3% | Jun 4, 2026 | Uninitialized Use in Skia in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the rend... |
| CVE-2026-10950 | MEDIUM | 6.5 | 0.3% | Jun 4, 2026 | Insufficient policy enforcement in Autofill in Google Chrome on iOS prior to 149.0.7827.53 allowed a remote attacker to ... |
| CVE-2026-10944 | MEDIUM | 6.5 | 0.3% | Jun 4, 2026 | Insufficient policy enforcement in Autofill in Google Chrome on iOS prior to 149.0.7827.53 allowed a remote attacker to ... |
| CVE-2026-10938 | MEDIUM | 6.5 | 0.4% | Jun 4, 2026 | Inappropriate implementation in Input in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromi... |
| CVE-2026-10937 | MEDIUM | 6.5 | 0.3% | Jun 4, 2026 | Inappropriate implementation in Passwords in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to bypass sa... |
| CVE-2026-10916 | MEDIUM | 6.1 | 0.2% | Jun 4, 2026 | Insufficient validation of untrusted input in DevTools in Google Chrome prior to 149.0.7827.53 allowed a remote attacker... |
| CVE-2026-10912 | MEDIUM | 6.5 | 0.3% | Jun 4, 2026 | Insufficient validation of untrusted input in Extensions in Google Chrome prior to 149.0.7827.53 allowed a remote attack... |
| CVE-2026-10875 | MEDIUM | 6.3 | 0.3% | Jun 4, 2026 | A security flaw has been discovered in projectworlds Online Art Gallery Shop Project 1.0. The impacted element is an unk... |
| CVE-2026-10874 | MEDIUM | 6.3 | 0.3% | Jun 4, 2026 | A vulnerability was identified in projectworlds Online Art Gallery Shop Project 1.0. The affected element is an unknown ... |
| CVE-2026-42547 | MEDIUM | 5.4 | 0.2% | Jun 4, 2026 | IRIS is a web collaborative platform that helps incident responders share technical details during investigations. In ve... |
| CVE-2026-42543 | MEDIUM | 4.3 | 0.2% | Jun 4, 2026 | IRIS is a web collaborative platform that helps incident responders share technical details during investigations. Versi... |
| CVE-2026-42540 | MEDIUM | 4.3 | 0.2% | Jun 4, 2026 | IRIS is a web collaborative platform that helps incident responders share technical details during investigations. Versi... |
| CVE-2026-42539 | MEDIUM | 6.5 | 0.2% | Jun 4, 2026 | IRIS is a web collaborative platform that helps incident responders share technical details during investigations. Versi... |
| CVE-2026-42538 | MEDIUM | 6.3 | 0.2% | Jun 4, 2026 | IRIS is a web collaborative platform that helps incident responders share technical details during investigations. Versi... |
| CVE-2026-42329 | MEDIUM | 4.7 | 0.2% | Jun 4, 2026 | Iris is a web collaborative platform that helps incident responders share technical details during investigations. Versi... |
| CVE-2026-5589 | MEDIUM | 6.3 | 0.2% | Jun 4, 2026 | An integer underflow in bt_mesh_sol_recv() in the Bluetooth Mesh solicitation handling (subsys/bluetooth/mesh/solicitati... |
| CVE-2026-21404 | MEDIUM | 6.3 | 0.1% | Jun 4, 2026 | NAVTOR NavBox through version 4.16.1.20 contains hard-coded credentials within its Windows Communication Foundation (SOA... |
| CVE-2026-48480 | MEDIUM | 6.6 | 0.2% | Jun 4, 2026 | The netty incubator codec.bhttp is a java language binary http parser. Prior to version 0.0.22.FInal, the codec-ohttp im... |
| CVE-2026-36499 | MEDIUM | 6.5 | 0.3% | Jun 4, 2026 | A missing upper-bound check in the udpif_set_threads() function of Open vSwitch v3.6.90 allows an attacker with OVSDB wr... |
| CVE-2026-41207 | MEDIUM | 5.3 | 0.2% | Jun 4, 2026 | The netty incubator codec.bhttp is a java language binary http parser. Prior to version 0.0.21.Final, HKDF_expand return... |
| CVE-2026-49940 | MEDIUM | 6.5 | 0.2% | Jun 4, 2026 | Net::CIDR::Set versions through 0.20 for Perl accept non-ASCII IP addresses and netmasks. Unicode digits such as the Ar... |
| CVE-2026-46739 | MEDIUM | 5.3 | 0.3% | Jun 4, 2026 | Net::Statsd versions before 0.13 for Perl allow metric injections. The metric names are not checked for newlines, colon... |
| CVE-2026-7774 | MEDIUM | 6.9 | 0.6% | Jun 4, 2026 | tarfile.data_filter could be bypassed using crafted link entries, including symlinks with empty or directory-like names,... |
| CVE-2026-45287 | MEDIUM | 5.5 | 0.2% | Jun 4, 2026 | OpenTelemetry-Go is the Go implementation of OpenTelemetry. Prior to version 0.0.17, `go.opentelemetry.io/otel/schema/v1... |
| CVE-2026-41178 | MEDIUM | 5.3 | 0.2% | Jun 4, 2026 | OpenTelemetry-Go is the Go implementation of OpenTelemetry. Versions 1.41.0 and 1.43.0 removed raw-length rejection and ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now