2026 CVE Vulnerabilities
48,244 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-13201 | HIGH | 7.3 | 0.1% | Jun 24, 2026 | A flaw was found in KubeVirt's safepath package used by virt-handler. The OpenAtNoFollow function uses O_PATH|O_NOFOLLOW... |
| CVE-2026-11998 | HIGH | 7.6 | 0.3% | Jun 24, 2026 | A flaw in AngularJS' Strict Contextual Escaping (SCE) logic allows bypassing certain SCE policies for resource URLs and ... |
| CVE-2026-55583 | HIGH | 7.6 | 0.2% | Jun 24, 2026 | Twenty is an open-source CRM (customer relationship management) platform. Prior to 2.9.0, Twenty was vulnerable to a cro... |
| CVE-2026-47389 | HIGH | 8.6 | 0.2% | Jun 24, 2026 | Mastodon is a free, open-source social network server based on ActivityPub. Prior to 4.5.10, 4.4.17, and 4.3.23, when us... |
| CVE-2026-46348 | HIGH | 8.7 | 0.3% | Jun 24, 2026 | Mastodon is a free, open-source social network server based on ActivityPub. Prior to 4.5.10, 4.4.17, and 4.3.23, the lis... |
| CVE-2026-27708 | HIGH | 7.1 | 0.3% | Jun 24, 2026 | FOSSBilling is a free, open-source billing and client management system. In versions 0.7.2 and prior, the Servicecustom ... |
| CVE-2026-23879 | HIGH | 8 | 0.4% | Jun 24, 2026 | py7zr is a Python-based library and utility to support 7zip archive compression, decompression, encryption and decryptio... |
| CVE-2026-53950 | HIGH | 7.5 | 0.2% | Jun 24, 2026 | @tryghost/activitypub is Ghost’s social/federation client app. Prior to 3.1.0, the ActivityPub client in Ghost was vulne... |
| CVE-2026-49247 | HIGH | 8.8 | 0.3% | Jun 24, 2026 | Jellyfin is an open source self hosted media server. From 10.9.0 until 10.11.10, the POST /ClientLog/Document endpoint a... |
| CVE-2026-48793 | HIGH | 8.8 | 0.4% | Jun 24, 2026 | Jellyfin is an open source self hosted media server. Prior to 10.11.10, a potential FFmpeg argument injection vulnerabil... |
| CVE-2026-13038 | HIGH | 8.8 | 0.3% | Jun 24, 2026 | Use after free in Autofill in Google Chrome on Windows prior to 149.0.7827.197 allowed a remote attacker to execute arbi... |
| CVE-2026-13037 | HIGH | 7.8 | 0.1% | Jun 24, 2026 | Use after free in WebView in Google Chrome on Android prior to 149.0.7827.197 allowed a local attacker to execute arbitr... |
| CVE-2026-13036 | HIGH | 8.8 | 0.2% | Jun 24, 2026 | Use after free in Blink in Google Chrome prior to 149.0.7827.197 allowed a remote attacker to execute arbitrary code ins... |
| CVE-2026-13035 | HIGH | 8.8 | 0.2% | Jun 24, 2026 | Use after free in Bluetooth in Google Chrome on Mac prior to 149.0.7827.197 allowed a remote attacker to execute arbitra... |
| CVE-2026-13033 | HIGH | 8.8 | 0.3% | Jun 24, 2026 | Out of bounds read and write in Blink>InterestGroups in Google Chrome prior to 149.0.7827.197 allowed a remote attacker ... |
| CVE-2026-13031 | HIGH | 8.8 | 0.2% | Jun 24, 2026 | Use after free in Blink in Google Chrome prior to 149.0.7827.197 allowed a remote attacker to execute arbitrary code ins... |
| CVE-2026-13029 | HIGH | 7.5 | 0.1% | Jun 24, 2026 | Use after free in Web Authentication in Google Chrome prior to 149.0.7827.197 allowed an attacker who convinced a user t... |
| CVE-2026-13027 | HIGH | 8.8 | 0.2% | Jun 24, 2026 | Use after free in FileSystem in Google Chrome prior to 149.0.7827.197 allowed a remote attacker to potentially exploit h... |
| CVE-2026-13026 | HIGH | 8.8 | 0.2% | Jun 24, 2026 | Use after free in Digital Credentials in Google Chrome on Mac prior to 149.0.7827.197 allowed a remote attacker to poten... |
| CVE-2026-13025 | HIGH | 8.3 | 0.2% | Jun 24, 2026 | Race in DevTools in Google Chrome prior to 149.0.7827.197 allowed a remote attacker who had compromised the renderer pro... |
| CVE-2026-54699 | HIGH | 7.7 | 0.4% | Jun 24, 2026 | Warp is an agentic development environment. From 0.2024.03.12.08.02.stable_01 until 0.2026.05.06.15.42.stable_01, Warp c... |
| CVE-2026-49851 | HIGH | 8.7 | 0.4% | Jun 24, 2026 | Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.3.0, Mistune is vulnerable to a CPU exhaustio... |
| CVE-2026-48732 | HIGH | 8.8 | 1.0% | Jun 24, 2026 | Warp is an agentic development environment. From 0.2023.03.21.08.02.stable_00 until 0.2026.05.06.15.42.stable_01, Warp c... |
| CVE-2026-48731 | HIGH | 7.8 | 0.5% | Jun 24, 2026 | Warp is an agentic development environment. From 0.2024.02.20.08.01.stable_01 until 0.2026.05.06.15.42.stable_01, Warp c... |
| CVE-2026-48725 | HIGH | 8.1 | 0.2% | Jun 24, 2026 | Warp is an agentic development environment. From 0.2021.04.25.23.05.stable_00 until 0.2026.05.06.15.42.stable_01, Warp a... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now