2026 CVE Vulnerabilities
50,970 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-9133 | HIGH | 8.3 | 0.3% | May 20, 2026 | Active debug code exists in the ARN resolver of amazon-mq rabbitmq-aws before version 0.2.1. A debug ARN scheme (arn:aws... |
| CVE-2026-9126 | HIGH | 8.8 | 0.4% | May 20, 2026 | Use after free in DOM in Google Chrome on prior to 148.0.7778.179 allowed a remote attacker to execute arbitrary code in... |
| CVE-2026-9123 | HIGH | 7.5 | 0.2% | May 20, 2026 | Heap buffer overflow in Chromecast in Google Chrome on Android, Linux, ChromeOS prior to 148.0.7778.179 allowed a local ... |
| CVE-2026-9121 | HIGH | 8.8 | 0.3% | May 20, 2026 | Out of bounds read in GPU in Google Chrome on prior to 148.0.7778.179 allowed a remote attacker to potentially exploit h... |
| CVE-2026-9120 | HIGH | 8.8 | 0.5% | May 20, 2026 | Use after free in WebRTC in Google Chrome prior to 148.0.7778.179 allowed a remote attacker to execute arbitrary code vi... |
| CVE-2026-9119 | HIGH | 8.8 | 0.5% | May 20, 2026 | Heap buffer overflow in WebRTC in Google Chrome on prior to 148.0.7778.179 allowed a remote attacker to execute arbitrar... |
| CVE-2026-9118 | HIGH | 8.8 | 0.4% | May 20, 2026 | Use after free in XR in Google Chrome on Windows prior to 148.0.7778.179 allowed a remote attacker to execute arbitrary ... |
| CVE-2026-9117 | HIGH | 7.5 | 0.3% | May 20, 2026 | Type Confusion in GFX in Google Chrome on Linux, ChromeOS prior to 148.0.7778.179 allowed a remote attacker who had comp... |
| CVE-2026-9114 | HIGH | 8.8 | 0.4% | May 20, 2026 | Use after free in QUIC in Google Chrome on prior to 148.0.7778.179 allowed a remote attacker to execute arbitrary code i... |
| CVE-2026-9112 | HIGH | 8.8 | 0.4% | May 20, 2026 | Use after free in GPU in Google Chrome on Windows prior to 148.0.7778.179 allowed a remote attacker to execute arbitrary... |
| CVE-2026-9111 | HIGH | 8.8 | 0.8% | May 20, 2026 | Use after free in WebRTC in Google Chrome on Linux prior to 148.0.7778.179 allowed a remote attacker to execute arbitrar... |
| CVE-2026-39850 | HIGH | 7.4 | 0.4% | May 20, 2026 | Yii 2 is a PHP application framework. Versions 2.0.54 and prior contain flawed logic in the core view rendering method V... |
| CVE-2026-39352 | HIGH | 8.7 | 1.3% | May 20, 2026 | Frappe is a full-stack web application framework. Versions prior to 15.105.0 and 16.15.0 contain a possible Arbitrary Fi... |
| CVE-2026-39310 | HIGH | 8.6 | 0.4% | May 20, 2026 | Trilium Notes is a cross-platform, hierarchical note taking application focused on building large personal knowledge bas... |
| CVE-2026-24218 | HIGH | 8.1 | 0.6% | May 20, 2026 | NVIDIA DGX OS contains a vulnerability in the factory provisioning process, where the cloning of a base image causes id... |
| CVE-2026-24217 | HIGH | 8.8 | 0.8% | May 20, 2026 | NVIDIA BioNeMo Core for Linux contains a vulnerability where a user could cause a path traversal by loading a malicious ... |
| CVE-2026-24216 | HIGH | 7.8 | 0.3% | May 20, 2026 | NVIDIA BioNemo for Linux contains a vulnerability where a user could cause a deserialization of untrusted data. A succes... |
| CVE-2026-24188 | HIGH | 7.5 | 0.4% | May 20, 2026 | NVIDIA TensorRT contains a vulnerability where an attacker could cause an out-of-bounds write. A successful exploit of t... |
| CVE-2026-9087 | HIGH | 8.1 | 0.3% | May 20, 2026 | A flaw was found in Keycloak. The cross-session verification proof is keyed only by (local userId, idpAlias) and is not ... |
| CVE-2026-7613 | HIGH | 7.2 | 0.3% | May 20, 2026 | The Cost of Goods by PixelYourSite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'csvdata[0]... |
| CVE-2026-44926 | HIGH | 8.8 | 0.4% | May 20, 2026 | InfoScale CmdServer before 7.4.2 mishandles access control. |
| CVE-2026-44925 | HIGH | 8.8 | 0.2% | May 20, 2026 | Cross-Site Request Forgery (CSRF) vulnerability in InfoScale v.9.1.3 Operations Manager (VIOM) allows an attacker to for... |
| CVE-2026-20199 | HIGH | 7.2 | 0.4% | May 20, 2026 | A vulnerability in the SSL certificate handling of Cisco ThousandEyes Virtual Appliance could allow an authenticated, re... |
| CVE-2026-8488 | HIGH | 7.5 | 0.4% | May 20, 2026 | Allocation of resources without limits or throttling vulnerability in Progress Software MOVEit Automation allows Excessi... |
| CVE-2026-8487 | HIGH | 7.5 | 0.3% | May 20, 2026 | Incorrect default permissions vulnerability in Progress Software MOVEit Automation allows Retrieve Embedded Sensitive Da... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now