2026 CVE Vulnerabilities
48,527 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-8550 | MEDIUM | 6.5 | 0.2% | May 14, 2026 | Use after free in Google Lens in Google Chrome prior to 148.0.7778.168 allowed a remote attacker who had compromised the... |
| CVE-2026-8546 | MEDIUM | 5.3 | 0.2% | May 14, 2026 | Out of bounds read in GPU in Google Chrome on Mac and Windows prior to 148.0.7778.168 allowed a remote attacker who had ... |
| CVE-2026-8543 | MEDIUM | 5.3 | 0.3% | May 14, 2026 | Out of bounds read in FileSystem in Google Chrome on Mac prior to 148.0.7778.168 allowed a remote attacker who convinced... |
| CVE-2026-8541 | MEDIUM | 5.3 | 0.2% | May 14, 2026 | Out of bounds read in UI in Google Chrome prior to 148.0.7778.168 allowed a remote attacker who had compromised the rend... |
| CVE-2026-8539 | MEDIUM | 5.4 | 0.2% | May 14, 2026 | Script injection in SanitizerAPI in Google Chrome on Android prior to 148.0.7778.168 allowed a remote attacker to inject... |
| CVE-2026-8538 | MEDIUM | 5.3 | 0.2% | May 14, 2026 | Insufficient validation of untrusted input in GPU in Google Chrome prior to 148.0.7778.168 allowed a remote attacker who... |
| CVE-2026-8537 | MEDIUM | 4.3 | 0.2% | May 14, 2026 | Insufficient policy enforcement in ViewTransitions in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to... |
| CVE-2026-8535 | MEDIUM | 5.3 | 0.2% | May 14, 2026 | Out of bounds read in Media in Google Chrome on Linux and ChromeOS prior to 148.0.7778.168 allowed a remote attacker who... |
| CVE-2026-8528 | MEDIUM | 4.3 | 0.2% | May 14, 2026 | Insufficient validation of untrusted input in SiteIsolation in Google Chrome prior to 148.0.7778.168 allowed a remote at... |
| CVE-2026-8516 | MEDIUM | 5.3 | 0.2% | May 14, 2026 | Insufficient validation of untrusted input in DataTransfer in Google Chrome prior to 148.0.7778.168 allowed a remote att... |
| CVE-2026-43996 | MEDIUM | 5.5 | 0.2% | May 14, 2026 | OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / a... |
| CVE-2026-26062 | MEDIUM | 6.5 | 0.4% | May 14, 2026 | Fleet is open source device management software. Prior to version 4.81.0, Fleet contained a denial-of-service (DoS) issu... |
| CVE-2026-24000 | MEDIUM | 5.3 | 0.4% | May 14, 2026 | Fleet is open source device management software. Prior to version 4.80.1, Fleet trusted client-supplied IP address heade... |
| CVE-2026-45148 | MEDIUM | 4.3 | 0.2% | May 14, 2026 | SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, broken access control in the searchAsset,... |
| CVE-2026-45147 | MEDIUM | 4.3 | 0.2% | May 14, 2026 | SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, POST /api/tag/getTag is registered with m... |
| CVE-2026-38740 | MEDIUM | 5.3 | 0.1% | May 14, 2026 | Foscam VD1 Video Doorbell before V5.3.13_1072 is vulnerable to Cleartext Transmission of Sensitive Information. The devi... |
| CVE-2026-27680 | MEDIUM | 4.3 | 0.2% | May 14, 2026 | Due to improper input handling under certain conditions, SAP NetWeaver Application Server ABAP allows an attacker to inj... |
| CVE-2026-22707 | MEDIUM | 5.4 | 0.2% | May 14, 2026 | Strapi is an open source headless content management system. In Strapi versions prior to 5.33.3, the Upload plugin's Con... |
| CVE-2026-22706 | MEDIUM | 6.5 | 0.3% | May 14, 2026 | Strapi is an open source headless content management system. In Strapi versions prior to 5.33.3, changing or resetting a... |
| CVE-2026-46469 | MEDIUM | 5.5 | 0.1% | May 14, 2026 | An issue was discovered in GStreamer gst-plugins-good before 1.28.2. When parsing MP4 audio tracks, the isomp4 plugin's ... |
| CVE-2026-44544 | MEDIUM | 4.9 | 0.2% | May 14, 2026 | gittuf is a platform-agnostic Git security system. Prior to 0.14.0, an attacker with push access to gittuf's Reference S... |
| CVE-2026-44520 | MEDIUM | 5.7 | 0.2% | May 14, 2026 | Docling-Graph turns documents into validated Pydantic objects, then builds a directed knowledge graph with explicit sema... |
| CVE-2026-44283 | MEDIUM | 4.3 | 0.2% | May 14, 2026 | etcd is a distributed key-value store for the data of a distributed system. Prior to 3.4.44, 3.5.30, and 3.6.11, a vulne... |
| CVE-2026-42897 | MEDIUM | 6.1 | 5.6% | May 14, 2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows... |
| CVE-2026-42598 | MEDIUM | 6.9 | 0.3% | May 14, 2026 | Pode is a Cross-Platform PowerShell web framework for creating REST APIs, Web Sites, and TCP/SMTP servers. From 2.4.0, t... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now