2026 CVE Vulnerabilities

48,527 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-8550MEDIUM6.5Use after free in Google Lens in Google Chrome prior to 148.0.7778.168 allowed a remote attacker who had compromised the...
CVE-2026-8546MEDIUM5.3Out of bounds read in GPU in Google Chrome on Mac and Windows prior to 148.0.7778.168 allowed a remote attacker who had ...
CVE-2026-8543MEDIUM5.3Out of bounds read in FileSystem in Google Chrome on Mac prior to 148.0.7778.168 allowed a remote attacker who convinced...
CVE-2026-8541MEDIUM5.3Out of bounds read in UI in Google Chrome prior to 148.0.7778.168 allowed a remote attacker who had compromised the rend...
CVE-2026-8539MEDIUM5.4Script injection in SanitizerAPI in Google Chrome on Android prior to 148.0.7778.168 allowed a remote attacker to inject...
CVE-2026-8538MEDIUM5.3Insufficient validation of untrusted input in GPU in Google Chrome prior to 148.0.7778.168 allowed a remote attacker who...
CVE-2026-8537MEDIUM4.3Insufficient policy enforcement in ViewTransitions in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to...
CVE-2026-8535MEDIUM5.3Out of bounds read in Media in Google Chrome on Linux and ChromeOS prior to 148.0.7778.168 allowed a remote attacker who...
CVE-2026-8528MEDIUM4.3Insufficient validation of untrusted input in SiteIsolation in Google Chrome prior to 148.0.7778.168 allowed a remote at...
CVE-2026-8516MEDIUM5.3Insufficient validation of untrusted input in DataTransfer in Google Chrome prior to 148.0.7778.168 allowed a remote att...
CVE-2026-43996MEDIUM5.5OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / a...
CVE-2026-26062MEDIUM6.5Fleet is open source device management software. Prior to version 4.81.0, Fleet contained a denial-of-service (DoS) issu...
CVE-2026-24000MEDIUM5.3Fleet is open source device management software. Prior to version 4.80.1, Fleet trusted client-supplied IP address heade...
CVE-2026-45148MEDIUM4.3SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, broken access control in the searchAsset,...
CVE-2026-45147MEDIUM4.3SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, POST /api/tag/getTag is registered with m...
CVE-2026-38740MEDIUM5.3Foscam VD1 Video Doorbell before V5.3.13_1072 is vulnerable to Cleartext Transmission of Sensitive Information. The devi...
CVE-2026-27680MEDIUM4.3Due to improper input handling under certain conditions, SAP NetWeaver Application Server ABAP allows an attacker to inj...
CVE-2026-22707MEDIUM5.4Strapi is an open source headless content management system. In Strapi versions prior to 5.33.3, the Upload plugin's Con...
CVE-2026-22706MEDIUM6.5Strapi is an open source headless content management system. In Strapi versions prior to 5.33.3, changing or resetting a...
CVE-2026-46469MEDIUM5.5An issue was discovered in GStreamer gst-plugins-good before 1.28.2. When parsing MP4 audio tracks, the isomp4 plugin's ...
CVE-2026-44544MEDIUM4.9gittuf is a platform-agnostic Git security system. Prior to 0.14.0, an attacker with push access to gittuf's Reference S...
CVE-2026-44520MEDIUM5.7Docling-Graph turns documents into validated Pydantic objects, then builds a directed knowledge graph with explicit sema...
CVE-2026-44283MEDIUM4.3etcd is a distributed key-value store for the data of a distributed system. Prior to 3.4.44, 3.5.30, and 3.6.11, a vulne...
CVE-2026-42897MEDIUM6.1Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows...
CVE-2026-42598MEDIUM6.9Pode is a Cross-Platform PowerShell web framework for creating REST APIs, Web Sites, and TCP/SMTP servers. From 2.4.0, t...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now