2026 CVE Vulnerabilities

47,565 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-10977MEDIUM6.5Uninitialized Use in Skia in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the rend...
CVE-2026-10950MEDIUM6.5Insufficient policy enforcement in Autofill in Google Chrome on iOS prior to 149.0.7827.53 allowed a remote attacker to ...
CVE-2026-10944MEDIUM6.5Insufficient policy enforcement in Autofill in Google Chrome on iOS prior to 149.0.7827.53 allowed a remote attacker to ...
CVE-2026-10938MEDIUM6.5Inappropriate implementation in Input in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromi...
CVE-2026-10937MEDIUM6.5Inappropriate implementation in Passwords in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to bypass sa...
CVE-2026-10916MEDIUM6.1Insufficient validation of untrusted input in DevTools in Google Chrome prior to 149.0.7827.53 allowed a remote attacker...
CVE-2026-10912MEDIUM6.5Insufficient validation of untrusted input in Extensions in Google Chrome prior to 149.0.7827.53 allowed a remote attack...
CVE-2026-10875MEDIUM6.3A security flaw has been discovered in projectworlds Online Art Gallery Shop Project 1.0. The impacted element is an unk...
CVE-2026-10874MEDIUM6.3A vulnerability was identified in projectworlds Online Art Gallery Shop Project 1.0. The affected element is an unknown ...
CVE-2026-42547MEDIUM5.4IRIS is a web collaborative platform that helps incident responders share technical details during investigations. In ve...
CVE-2026-42543MEDIUM4.3IRIS is a web collaborative platform that helps incident responders share technical details during investigations. Versi...
CVE-2026-42540MEDIUM4.3IRIS is a web collaborative platform that helps incident responders share technical details during investigations. Versi...
CVE-2026-42539MEDIUM6.5IRIS is a web collaborative platform that helps incident responders share technical details during investigations. Versi...
CVE-2026-42538MEDIUM6.3IRIS is a web collaborative platform that helps incident responders share technical details during investigations. Versi...
CVE-2026-42329MEDIUM4.7Iris is a web collaborative platform that helps incident responders share technical details during investigations. Versi...
CVE-2026-5589MEDIUM6.3An integer underflow in bt_mesh_sol_recv() in the Bluetooth Mesh solicitation handling (subsys/bluetooth/mesh/solicitati...
CVE-2026-21404MEDIUM6.3NAVTOR NavBox through version 4.16.1.20 contains hard-coded credentials within its Windows Communication Foundation (SOA...
CVE-2026-48480MEDIUM6.6The netty incubator codec.bhttp is a java language binary http parser. Prior to version 0.0.22.FInal, the codec-ohttp im...
CVE-2026-36499MEDIUM6.5A missing upper-bound check in the udpif_set_threads() function of Open vSwitch v3.6.90 allows an attacker with OVSDB wr...
CVE-2026-41207MEDIUM5.3The netty incubator codec.bhttp is a java language binary http parser. Prior to version 0.0.21.Final, HKDF_expand return...
CVE-2026-49940MEDIUM6.5Net::CIDR::Set versions through 0.20 for Perl accept non-ASCII IP addresses and netmasks. Unicode digits such as the Ar...
CVE-2026-46739MEDIUM5.3Net::Statsd versions before 0.13 for Perl allow metric injections. The metric names are not checked for newlines, colon...
CVE-2026-7774MEDIUM6.9tarfile.data_filter could be bypassed using crafted link entries, including symlinks with empty or directory-like names,...
CVE-2026-45287MEDIUM5.5OpenTelemetry-Go is the Go implementation of OpenTelemetry. Prior to version 0.0.17, `go.opentelemetry.io/otel/schema/v1...
CVE-2026-41178MEDIUM5.3OpenTelemetry-Go is the Go implementation of OpenTelemetry. Versions 1.41.0 and 1.43.0 removed raw-length rejection and ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now