2026 CVE Vulnerabilities
48,018 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-9935 | MEDIUM | 4.3 | 0.2% | May 28, 2026 | Uninitialized Use in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to leak cross-origin data ... |
| CVE-2026-9930 | MEDIUM | 4.3 | 0.2% | May 28, 2026 | Out of bounds write in Dawn in Google Chrome on Mac prior to 148.0.7778.216 allowed a remote attacker to perform an out ... |
| CVE-2026-9929 | MEDIUM | 4.3 | 0.2% | May 28, 2026 | Inappropriate implementation in WebGL in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attacker to l... |
| CVE-2026-9921 | MEDIUM | 4.3 | 0.2% | May 28, 2026 | Uninitialized Use in WebGL in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attacker to leak cross-o... |
| CVE-2026-9919 | MEDIUM | 4.3 | 0.2% | May 28, 2026 | Out of bounds read in WebGL in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attacker to leak cross-... |
| CVE-2026-9917 | MEDIUM | 6.5 | 0.3% | May 28, 2026 | Uninitialized Use in WebGL in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attacker to obtain poten... |
| CVE-2026-9913 | MEDIUM | 4.3 | 0.2% | May 28, 2026 | Inappropriate implementation in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to potentially ... |
| CVE-2026-9912 | MEDIUM | 6.5 | 0.2% | May 28, 2026 | Inappropriate implementation in GPU in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attacker to obt... |
| CVE-2026-9911 | MEDIUM | 4.3 | 0.2% | May 28, 2026 | Integer overflow in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to perform an out of bounds... |
| CVE-2026-9908 | MEDIUM | 6.5 | 0.2% | May 28, 2026 | Out of bounds read in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to obtain potentially sen... |
| CVE-2026-9907 | MEDIUM | 4.3 | 0.2% | May 28, 2026 | Out of bounds read in Dawn in Google Chrome on Windows prior to 148.0.7778.216 allowed a remote attacker to leak cross-o... |
| CVE-2026-9903 | MEDIUM | 5 | 0.2% | May 28, 2026 | Insufficient validation of untrusted input in Site Isolation in Google Chrome prior to 148.0.7778.216 allowed a remote a... |
| CVE-2026-9882 | MEDIUM | 6.5 | 0.2% | May 28, 2026 | Integer overflow in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to leak cross-origin data v... |
| CVE-2026-10028 | MEDIUM | 4.3 | 0.2% | May 28, 2026 | A flaw was found in glib-networking. A remote attacker can exploit this vulnerability by presenting a specially crafted ... |
| CVE-2026-10018 | MEDIUM | 6.5 | 0.2% | May 28, 2026 | Integer overflow in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to obtain potentially sensi... |
| CVE-2026-10010 | MEDIUM | 5 | 0.1% | May 28, 2026 | Inappropriate implementation in Input in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attacker who ... |
| CVE-2026-10008 | MEDIUM | 6.5 | 0.2% | May 28, 2026 | Uninitialized Use in GPU in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attacker to obtain potenti... |
| CVE-2026-10004 | MEDIUM | 6.5 | 0.2% | May 28, 2026 | Insufficient validation of untrusted input in Passwords in Google Chrome prior to 148.0.7778.216 allowed a remote attack... |
| CVE-2026-49299 | MEDIUM | 5.3 | 0.3% | May 28, 2026 | In OpenStack Neutron before 28.0.1, the tagging controller enforces plural policy action names on single-tag write opera... |
| CVE-2026-47713 | MEDIUM | 4.3 | 0.2% | May 28, 2026 | AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatti... |
| CVE-2026-45410 | MEDIUM | 5.3 | 0.2% | May 28, 2026 | TREK is a collaborative travel planner. Prior to 3.0.18, early return on missing user during login flow allowed an attac... |
| CVE-2026-45366 | MEDIUM | 4.7 | 0.1% | May 28, 2026 | typescript-utcp is a typescript implementation of UTCP. Prior to 1.1.2, the @utcp/http package is vulnerable to a blind ... |
| CVE-2026-45023 | MEDIUM | 5.4 | 0.2% | May 28, 2026 | AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agent... |
| CVE-2026-44885 | MEDIUM | 5.5 | 0.6% | May 28, 2026 | Portainer Community Edition is a lightweight service delivery platform for containerized applications that can be used t... |
| CVE-2026-44884 | MEDIUM | 6.5 | 0.3% | May 28, 2026 | Portainer Community Edition is a lightweight service delivery platform for containerized applications that can be used t... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now