2026 CVE Vulnerabilities
48,516 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-12462 | HIGH | 7.5 | 0.3% | Jun 17, 2026 | Use after free in Media in Google Chrome prior to 149.0.7827.155 allowed a remote attacker who had compromised the rende... |
| CVE-2026-12455 | HIGH | 7.5 | 0.2% | Jun 17, 2026 | Use after free in Tab Strip in Google Chrome prior to 149.0.7827.155 allowed a remote attacker who convinced a user to e... |
| CVE-2026-12454 | HIGH | 8.3 | 0.1% | Jun 17, 2026 | Race in Safe Browsing in Google Chrome on Mac prior to 149.0.7827.155 allowed a remote attacker who had compromised the ... |
| CVE-2026-12452 | HIGH | 8.8 | 0.3% | Jun 17, 2026 | Use after free in Downloads in Google Chrome on Android prior to 149.0.7827.155 allowed a remote attacker to potentially... |
| CVE-2026-12451 | HIGH | 8.3 | 0.2% | Jun 17, 2026 | Use after free in DigitalCredentials in Google Chrome prior to 149.0.7827.155 allowed a remote attacker who had compromi... |
| CVE-2026-12449 | HIGH | 7.8 | 0.1% | Jun 17, 2026 | Use after free in Chromoting in Google Chrome on Windows prior to 149.0.7827.155 allowed a local attacker to perform OS-... |
| CVE-2026-12448 | HIGH | 8.8 | 0.3% | Jun 17, 2026 | Inappropriate implementation in WebView in Google Chrome on Android prior to 149.0.7827.155 allowed a remote attacker to... |
| CVE-2026-12447 | HIGH | 8.8 | 0.4% | Jun 17, 2026 | Heap buffer overflow in WebRTC in Google Chrome prior to 149.0.7827.155 allowed a remote attacker to execute arbitrary c... |
| CVE-2026-12445 | HIGH | 7.5 | 0.2% | Jun 17, 2026 | Use after free in Extensions in Google Chrome prior to 149.0.7827.155 allowed an attacker who convinced a user to instal... |
| CVE-2026-12443 | HIGH | 8.8 | 0.6% | Jun 17, 2026 | Use after free in Web Authentication in Google Chrome prior to 149.0.7827.155 allowed a remote attacker to execute arbit... |
| CVE-2026-12442 | HIGH | 8.8 | 0.4% | Jun 17, 2026 | Use after free in Passwords in Google Chrome on Android prior to 149.0.7827.155 allowed a remote attacker to execute arb... |
| CVE-2026-12441 | HIGH | 8.8 | 0.3% | Jun 17, 2026 | Use after free in File Input in Google Chrome on Linux prior to 149.0.7827.155 allowed a remote attacker to potentially ... |
| CVE-2026-12439 | HIGH | 8.8 | 0.3% | Jun 17, 2026 | Use after free in Digital Credentials in Google Chrome prior to 149.0.7827.155 allowed a remote attacker to potentially ... |
| CVE-2026-12438 | HIGH | 8.3 | 0.2% | Jun 17, 2026 | Inappropriate implementation in WebView in Google Chrome on Android prior to 149.0.7827.155 allowed a remote attacker wh... |
| CVE-2026-12437 | HIGH | 8.3 | 0.3% | Jun 17, 2026 | Use after free in WebShare in Google Chrome on Windows prior to 149.0.7827.155 allowed a remote attacker who had comprom... |
| CVE-2026-12360 | HIGH | 7.5 | 0.3% | Jun 17, 2026 | The JetEngine plugin for WordPress is vulnerable to SQL injection in all versions up to and including 3.8.10.1. The list... |
| CVE-2026-12256 | HIGH | 8.8 | 0.5% | Jun 17, 2026 | Contributor PHP Object Injection in Avada <= 3.15.3 versions. |
| CVE-2026-12199 | HIGH | 7.5 | 0.3% | Jun 17, 2026 | A vulnerability in `nltk.app.wordnet_app` up to version 3.9.3 allows unauthenticated remote shutdown of the local WordNe... |
| CVE-2026-12165 | HIGH | 8.8 | 0.4% | Jun 17, 2026 | The Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe plugin for WordPress is vulnerable to Privi... |
| CVE-2026-11858 | HIGH | 8.4 | 0.1% | Jun 17, 2026 | Quanos SCHEMA ST4 on-premises contains a local privilege escalation vulnerability in the Client Update Service. The upda... |
| CVE-2026-11857 | HIGH | 8.4 | 0.3% | Jun 17, 2026 | Quanos SCHEMA ST4 on-premises contains a local privilege escalation vulnerability in the Client Update Service due to in... |
| CVE-2026-11410 | HIGH | 7.2 | 2.8% | Jun 17, 2026 | An authenticated OS command injection vulnerability exists in the BigPond Cable (BPA) WAN configuration module in TL-WR9... |
| CVE-2026-11409 | HIGH | 7.2 | 2.8% | Jun 17, 2026 | An authenticated OS command injection vulnerability exists in the IPv6 PPPoE configuration handler in TL-WR940N v6 due t... |
| CVE-2026-0083 | HIGH | 7 | 0.1% | Jun 17, 2026 | In Nfc::eventCallback() of Nfc.h, there is a possible use after free due to a race condition. This could lead to local e... |
| CVE-2026-0082 | HIGH | 7.8 | 0.2% | Jun 17, 2026 | In tryStartActivity of NfcDispatcher.java, there is a possible automatic special app access permission assignment due to... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now