2026 CVE Vulnerabilities
48,521 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-45248 | MEDIUM | 6.9 | 0.4% | May 14, 2026 | Hedera Guardian through 3.5.1 contains an authentication bypass vulnerability in the GET /api/v1/demo/registered-users e... |
| CVE-2026-44428 | MEDIUM | 4.7 | 0.2% | May 14, 2026 | The MCP Registry provides MCP clients with a list of MCP servers, like an app store for MCP servers. Prior to 1.7.6, the... |
| CVE-2026-44679 | MEDIUM | 6.9 | 0.3% | May 14, 2026 | Tuist is a virtual platform team for Swift app devs. Prior to 1.180.10, the forgot password flow allows an unauthenticat... |
| CVE-2026-44662 | MEDIUM | 5.1 | 0.2% | May 14, 2026 | rust-openssl provides OpenSSL bindings for the Rust programming language. From 0.10.0 to before 0.10.79, CipherCtxRef::c... |
| CVE-2026-44661 | MEDIUM | 4.7 | 0.2% | May 14, 2026 | python-utcp is the python implementation of UTCP. Prior to 1.1.3, the utcp-http plugin is vulnerable to a blind Server-S... |
| CVE-2026-44430 | MEDIUM | 4 | 0.3% | May 14, 2026 | The MCP Registry provides MCP clients with a list of MCP servers, like an app store for MCP servers. Prior to 1.7.7, the... |
| CVE-2026-44429 | MEDIUM | 5.4 | 0.2% | May 14, 2026 | The MCP Registry provides MCP clients with a list of MCP servers, like an app store for MCP servers. Prior to 1.7.7, the... |
| CVE-2026-8586 | MEDIUM | 5.5 | 0.1% | May 14, 2026 | Inappropriate implementation in Chromoting in Google Chrome prior to 148.0.7778.168 allowed a local attacker to bypass d... |
| CVE-2026-8584 | MEDIUM | 4.2 | 0.1% | May 14, 2026 | Inappropriate implementation in Views in Google Chrome on iOS prior to 148.0.7778.168 allowed a remote attacker who had ... |
| CVE-2026-8583 | MEDIUM | 5.3 | 0.2% | May 14, 2026 | Insufficient policy enforcement in WebXR in Google Chrome on Android prior to 148.0.7778.168 allowed a remote attacker w... |
| CVE-2026-8582 | MEDIUM | 5.3 | 0.2% | May 14, 2026 | Object lifecycle issue in Dawn in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to obtain potentially ... |
| CVE-2026-8576 | MEDIUM | 4.3 | 0.2% | May 14, 2026 | Inappropriate implementation in CORS in Google Chrome on Linux and ChromeOS prior to 148.0.7778.168 allowed a remote att... |
| CVE-2026-8570 | MEDIUM | 6.5 | 0.3% | May 14, 2026 | Type Confusion in V8 in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to obtain potentially sensitive ... |
| CVE-2026-8567 | MEDIUM | 4.3 | 0.2% | May 14, 2026 | Integer overflow in ANGLE in Google Chrome on Windows prior to 148.0.7778.168 allowed a remote attacker to perform an ou... |
| CVE-2026-8566 | MEDIUM | 4.3 | 0.2% | May 14, 2026 | Insufficient policy enforcement in Payments in Google Chrome on Android prior to 148.0.7778.168 allowed a remote attacke... |
| CVE-2026-8565 | MEDIUM | 4.7 | 0.1% | May 14, 2026 | Inappropriate implementation in Downloads in Google Chrome on Mac prior to 148.0.7778.168 allowed an attacker who convin... |
| CVE-2026-8564 | MEDIUM | 4.2 | 0.2% | May 14, 2026 | Incorrect security UI in Downloads in Google Chrome on Android and Mac prior to 148.0.7778.168 allowed a remote attacker... |
| CVE-2026-8563 | MEDIUM | 4.3 | 0.2% | May 14, 2026 | Insufficient policy enforcement in IFrame Sandbox in Google Chrome on Windows prior to 148.0.7778.168 allowed a remote a... |
| CVE-2026-8562 | MEDIUM | 4.3 | 0.2% | May 14, 2026 | Side-channel information leakage in Navigation in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to lea... |
| CVE-2026-8561 | MEDIUM | 5.4 | 0.2% | May 14, 2026 | Incorrect security UI in Fullscreen in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to perform UI spo... |
| CVE-2026-8560 | MEDIUM | 4.3 | 0.3% | May 14, 2026 | Heap buffer overflow in SwiftShader in Google Chrome on Mac and iOS prior to 148.0.7778.168 allowed a remote attacker to... |
| CVE-2026-8559 | MEDIUM | 4.3 | 0.2% | May 14, 2026 | Integer overflow in Internationalization in Google Chrome on Windows prior to 148.0.7778.168 allowed a remote attacker t... |
| CVE-2026-8552 | MEDIUM | 4.3 | 0.2% | May 14, 2026 | Heap buffer overflow in GPU in Google Chrome on Android prior to 148.0.7778.168 allowed a remote attacker to perform an ... |
| CVE-2026-8550 | MEDIUM | 6.5 | 0.2% | May 14, 2026 | Use after free in Google Lens in Google Chrome prior to 148.0.7778.168 allowed a remote attacker who had compromised the... |
| CVE-2026-8546 | MEDIUM | 5.3 | 0.2% | May 14, 2026 | Out of bounds read in GPU in Google Chrome on Mac and Windows prior to 148.0.7778.168 allowed a remote attacker who had ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now