2026 CVE Vulnerabilities

48,632 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-11646HIGH8.8Use after free in ViewTransitions in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arbitrar...
CVE-2026-11645HIGH8.8Out of bounds read and write in V8 in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arbitra...
CVE-2026-11644HIGH7.5Use after free in Views in Google Chrome on Linux prior to 149.0.7827.103 allowed an attacker who convinced a user to in...
CVE-2026-11643HIGH8.1Use after free in Proxy in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code via...
CVE-2026-11642HIGH8.3Use after free in Web Apps in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who had compromised the re...
CVE-2026-11641HIGH7.5Use after free in Bluetooth in Google Chrome on Windows prior to 149.0.7827.103 allowed a remote attacker who convinced ...
CVE-2026-11640HIGH8.3Integer overflow in libyuv in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who had compromised the re...
CVE-2026-11639HIGH7.5Use after free in Compositing in Google Chrome on Mac prior to 149.0.7827.103 allowed a remote attacker to execute arbit...
CVE-2026-11637HIGH8.8Use after free in Views in Google Chrome on Mac prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary c...
CVE-2026-11636HIGH7.5Use after free in Autofill in Google Chrome on Windows prior to 149.0.7827.103 allowed a remote attacker who convinced a...
CVE-2026-11635HIGH8.3Use after free in Bluetooth in Google Chrome on Mac prior to 149.0.7827.103 allowed a remote attacker who had compromise...
CVE-2026-11633HIGH8.8Use after free in Bluetooth in Google Chrome on Mac prior to 149.0.7827.103 allowed a remote attacker to execute arbitra...
CVE-2026-11632HIGH7.5Use after free in TabStrip in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who convinced a user to en...
CVE-2026-11631HIGH8.3Use after free in Aura in Google Chrome on Windows prior to 149.0.7827.103 allowed a remote attacker who had compromised...
CVE-2026-11630HIGH8.8Use after free in File Input in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to potentially exploit h...
CVE-2026-11629HIGH8.8Use after free in Ozone in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to potentially exploit heap c...
CVE-2026-9669HIGH8.2bz2.BZ2Decompressor objects could be reused after a decompression error. If an application caught the resulting OSError ...
CVE-2026-44541HIGH7Fides is an open-source privacy engineering platform. From version 2.33.0 to before version 2.84.5, there is a DOM-based...
CVE-2026-40215HIGH7.4A race condition in OpenVPN 2.6.0 through 2.6.19 and 2.7_alpha1 through 2.7.1 allows remote attackers to potentially cau...
CVE-2026-49141HIGH7.1WACRM prior to commit 73041bf contain an authorization bypass vulnerability in the automation engine that allows authent...
CVE-2026-46484HIGH8.1Headplane is a feature-complete Web UI for Headscale. Prior to versions 0.6.3 and 0.7.0-beta.3, Headplane was vulnerable...
CVE-2026-40519HIGH7.7Nginx Proxy Manager versions 2.9.14 through 2.15.1, fixed in commit a5db5ed, contain an authenticated remote code execut...
CVE-2026-11582HIGH7.3A flaw has been found in CodeAstro Student Attendance Management System 1.0. The impacted element is an unknown function...
CVE-2026-46490HIGH8.8samlify is a Node.js library for SAML single sign-on. Prior to version 2.13.0, samlify’s template substitution only esca...
CVE-2026-11557HIGH8.8A weakness has been identified in Tenda F451 1.0.0.7/1.0.0.9. The affected element is the function fromNatlimit of the f...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now