2026 CVE Vulnerabilities

48,516 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-12462HIGH7.5Use after free in Media in Google Chrome prior to 149.0.7827.155 allowed a remote attacker who had compromised the rende...
CVE-2026-12455HIGH7.5Use after free in Tab Strip in Google Chrome prior to 149.0.7827.155 allowed a remote attacker who convinced a user to e...
CVE-2026-12454HIGH8.3Race in Safe Browsing in Google Chrome on Mac prior to 149.0.7827.155 allowed a remote attacker who had compromised the ...
CVE-2026-12452HIGH8.8Use after free in Downloads in Google Chrome on Android prior to 149.0.7827.155 allowed a remote attacker to potentially...
CVE-2026-12451HIGH8.3Use after free in DigitalCredentials in Google Chrome prior to 149.0.7827.155 allowed a remote attacker who had compromi...
CVE-2026-12449HIGH7.8Use after free in Chromoting in Google Chrome on Windows prior to 149.0.7827.155 allowed a local attacker to perform OS-...
CVE-2026-12448HIGH8.8Inappropriate implementation in WebView in Google Chrome on Android prior to 149.0.7827.155 allowed a remote attacker to...
CVE-2026-12447HIGH8.8Heap buffer overflow in WebRTC in Google Chrome prior to 149.0.7827.155 allowed a remote attacker to execute arbitrary c...
CVE-2026-12445HIGH7.5Use after free in Extensions in Google Chrome prior to 149.0.7827.155 allowed an attacker who convinced a user to instal...
CVE-2026-12443HIGH8.8Use after free in Web Authentication in Google Chrome prior to 149.0.7827.155 allowed a remote attacker to execute arbit...
CVE-2026-12442HIGH8.8Use after free in Passwords in Google Chrome on Android prior to 149.0.7827.155 allowed a remote attacker to execute arb...
CVE-2026-12441HIGH8.8Use after free in File Input in Google Chrome on Linux prior to 149.0.7827.155 allowed a remote attacker to potentially ...
CVE-2026-12439HIGH8.8Use after free in Digital Credentials in Google Chrome prior to 149.0.7827.155 allowed a remote attacker to potentially ...
CVE-2026-12438HIGH8.3Inappropriate implementation in WebView in Google Chrome on Android prior to 149.0.7827.155 allowed a remote attacker wh...
CVE-2026-12437HIGH8.3Use after free in WebShare in Google Chrome on Windows prior to 149.0.7827.155 allowed a remote attacker who had comprom...
CVE-2026-12360HIGH7.5The JetEngine plugin for WordPress is vulnerable to SQL injection in all versions up to and including 3.8.10.1. The list...
CVE-2026-12256HIGH8.8Contributor PHP Object Injection in Avada <= 3.15.3 versions.
CVE-2026-12199HIGH7.5A vulnerability in `nltk.app.wordnet_app` up to version 3.9.3 allows unauthenticated remote shutdown of the local WordNe...
CVE-2026-12165HIGH8.8The Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe plugin for WordPress is vulnerable to Privi...
CVE-2026-11858HIGH8.4Quanos SCHEMA ST4 on-premises contains a local privilege escalation vulnerability in the Client Update Service. The upda...
CVE-2026-11857HIGH8.4Quanos SCHEMA ST4 on-premises contains a local privilege escalation vulnerability in the Client Update Service due to in...
CVE-2026-11410HIGH7.2An authenticated OS command injection vulnerability exists in the BigPond Cable (BPA) WAN configuration module in TL-WR9...
CVE-2026-11409HIGH7.2An authenticated OS command injection vulnerability exists in the IPv6 PPPoE configuration handler in TL-WR940N v6 due t...
CVE-2026-0083HIGH7In Nfc::eventCallback() of Nfc.h, there is a possible use after free due to a race condition. This could lead to local e...
CVE-2026-0082HIGH7.8In tryStartActivity of NfcDispatcher.java, there is a possible automatic special app access permission assignment due to...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now