2026 CVE Vulnerabilities
48,632 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-11646 | HIGH | 8.8 | 0.3% | Jun 9, 2026 | Use after free in ViewTransitions in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arbitrar... |
| CVE-2026-11645 | HIGH | 8.8 | 1.7% | Jun 9, 2026 | Out of bounds read and write in V8 in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arbitra... |
| CVE-2026-11644 | HIGH | 7.5 | 0.2% | Jun 9, 2026 | Use after free in Views in Google Chrome on Linux prior to 149.0.7827.103 allowed an attacker who convinced a user to in... |
| CVE-2026-11643 | HIGH | 8.1 | 0.3% | Jun 9, 2026 | Use after free in Proxy in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code via... |
| CVE-2026-11642 | HIGH | 8.3 | 0.2% | Jun 9, 2026 | Use after free in Web Apps in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who had compromised the re... |
| CVE-2026-11641 | HIGH | 7.5 | 0.3% | Jun 9, 2026 | Use after free in Bluetooth in Google Chrome on Windows prior to 149.0.7827.103 allowed a remote attacker who convinced ... |
| CVE-2026-11640 | HIGH | 8.3 | 0.2% | Jun 9, 2026 | Integer overflow in libyuv in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who had compromised the re... |
| CVE-2026-11639 | HIGH | 7.5 | 0.3% | Jun 9, 2026 | Use after free in Compositing in Google Chrome on Mac prior to 149.0.7827.103 allowed a remote attacker to execute arbit... |
| CVE-2026-11637 | HIGH | 8.8 | 0.3% | Jun 9, 2026 | Use after free in Views in Google Chrome on Mac prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary c... |
| CVE-2026-11636 | HIGH | 7.5 | 0.2% | Jun 9, 2026 | Use after free in Autofill in Google Chrome on Windows prior to 149.0.7827.103 allowed a remote attacker who convinced a... |
| CVE-2026-11635 | HIGH | 8.3 | 0.2% | Jun 9, 2026 | Use after free in Bluetooth in Google Chrome on Mac prior to 149.0.7827.103 allowed a remote attacker who had compromise... |
| CVE-2026-11633 | HIGH | 8.8 | 0.2% | Jun 9, 2026 | Use after free in Bluetooth in Google Chrome on Mac prior to 149.0.7827.103 allowed a remote attacker to execute arbitra... |
| CVE-2026-11632 | HIGH | 7.5 | 0.3% | Jun 9, 2026 | Use after free in TabStrip in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who convinced a user to en... |
| CVE-2026-11631 | HIGH | 8.3 | 0.2% | Jun 9, 2026 | Use after free in Aura in Google Chrome on Windows prior to 149.0.7827.103 allowed a remote attacker who had compromised... |
| CVE-2026-11630 | HIGH | 8.8 | 0.3% | Jun 9, 2026 | Use after free in File Input in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to potentially exploit h... |
| CVE-2026-11629 | HIGH | 8.8 | 0.3% | Jun 9, 2026 | Use after free in Ozone in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to potentially exploit heap c... |
| CVE-2026-9669 | HIGH | 8.2 | 0.4% | Jun 8, 2026 | bz2.BZ2Decompressor objects could be reused after a decompression error. If an application caught the resulting OSError ... |
| CVE-2026-44541 | HIGH | 7 | 0.3% | Jun 8, 2026 | Fides is an open-source privacy engineering platform. From version 2.33.0 to before version 2.84.5, there is a DOM-based... |
| CVE-2026-40215 | HIGH | 7.4 | 0.3% | Jun 8, 2026 | A race condition in OpenVPN 2.6.0 through 2.6.19 and 2.7_alpha1 through 2.7.1 allows remote attackers to potentially cau... |
| CVE-2026-49141 | HIGH | 7.1 | 0.2% | Jun 8, 2026 | WACRM prior to commit 73041bf contain an authorization bypass vulnerability in the automation engine that allows authent... |
| CVE-2026-46484 | HIGH | 8.1 | 0.4% | Jun 8, 2026 | Headplane is a feature-complete Web UI for Headscale. Prior to versions 0.6.3 and 0.7.0-beta.3, Headplane was vulnerable... |
| CVE-2026-40519 | HIGH | 7.7 | 0.9% | Jun 8, 2026 | Nginx Proxy Manager versions 2.9.14 through 2.15.1, fixed in commit a5db5ed, contain an authenticated remote code execut... |
| CVE-2026-11582 | HIGH | 7.3 | 0.3% | Jun 8, 2026 | A flaw has been found in CodeAstro Student Attendance Management System 1.0. The impacted element is an unknown function... |
| CVE-2026-46490 | HIGH | 8.8 | 0.4% | Jun 8, 2026 | samlify is a Node.js library for SAML single sign-on. Prior to version 2.13.0, samlify’s template substitution only esca... |
| CVE-2026-11557 | HIGH | 8.8 | 0.5% | Jun 8, 2026 | A weakness has been identified in Tenda F451 1.0.0.7/1.0.0.9. The affected element is the function fromNatlimit of the f... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now