2026 CVE Vulnerabilities

48,546 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-48610HIGH8.1Under certain network configurations, a malicious actor with access to network could exploit an Improper Access Control ...
CVE-2026-47368HIGH8.6A malicious actor with access to the network could exploit a Path Traversal vulnerability found in certain devices runni...
CVE-2026-47366HIGH7.2Improper verification of access permissions when modifying permissions through the Administration Control Panel (ACP) al...
CVE-2026-45170HIGH8.8Idira Vendor PAM - Self-Hosted Connector versions prior 1.1.100504 under specific conditions and configuration scenarios...
CVE-2026-11933HIGH8.8A use-after-free vulnerability exists in MongoDB Server's server-side JavaScript engine when converting BSON documents t...
CVE-2026-45418HIGH8.8ClipBucket v5 is an open source video sharing platform. Prior to version 5.5.3 - #132, any authenticated user who can up...
CVE-2026-6250HIGH8.1An authenticated format string vulnerability exists in the ONVIF service of Tapo C110 v2 due to improper handling of use...
CVE-2026-45174HIGH7.8Idira Endpoint Privilege Manager Linux Agent versions prior to 26.5 allow a local attacker to potentially compromise the...
CVE-2026-45172HIGH8.8Due to incomplete input validation in Idira Privileged Session Manager for SSH (PSMP) versions prior to 15.0.2, 14.6.3, ...
CVE-2026-45171HIGH8.8Incomplete input validation and improperly configured folder permissions within Idira Privileged Session Manager (PSM) v...
CVE-2026-44890HIGH7.5Netty is a network application framework for development of protocol servers and clients. In netty-codec-redis prior to ...
CVE-2026-44250HIGH7.5Netty is a network application framework for development of protocol servers and clients. In netty-codec-redis prior to ...
CVE-2026-44249HIGH8.1Netty is a network application framework for development of protocol servers and clients. In netty-handler prior to vers...
CVE-2026-42653HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in iova.Mihai SliceWP...
CVE-2026-12035HIGH8.8Use after free in Views in Google Chrome on Windows prior to 149.0.7827.115 allowed a remote attacker to potentially exp...
CVE-2026-12034HIGH8.3Insufficient validation of untrusted input in Linux Toolkit Theming in Google Chrome on Linux prior to 149.0.7827.115 al...
CVE-2026-12031HIGH8.3Inappropriate implementation in Views in Google Chrome on Windows prior to 149.0.7827.115 allowed a remote attacker who ...
CVE-2026-12030HIGH8.3Out of bounds write in GPU in Google Chrome on Android prior to 149.0.7827.115 allowed a remote attacker who had comprom...
CVE-2026-12029HIGH8.3Use after free in Video in Google Chrome on Windows prior to 149.0.7827.115 allowed a remote attacker who had compromise...
CVE-2026-12028HIGH8.3Use after free in GPU in Google Chrome on Android prior to 149.0.7827.115 allowed a remote attacker who had compromised ...
CVE-2026-12023HIGH8.3Use after free in GPU in Google Chrome on Mac prior to 149.0.7827.115 allowed a remote attacker who had compromised the ...
CVE-2026-12022HIGH8.3Race in Safe Browsing in Google Chrome on Mac prior to 149.0.7827.115 allowed a remote attacker who had compromised the ...
CVE-2026-12020HIGH8.8Use after free in Autofill in Google Chrome on Mac prior to 149.0.7827.115 allowed a remote attacker to potentially expl...
CVE-2026-12019HIGH8.3Heap buffer overflow in Codecs in Google Chrome on Linux and ChromeOS prior to 149.0.7827.115 allowed a remote attacker ...
CVE-2026-12018HIGH8.8Inappropriate implementation in Mojo in Google Chrome on Windows prior to 149.0.7827.115 allowed a local attacker to per...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now