2026 CVE Vulnerabilities
50,982 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-8531 | HIGH | 8.8 | 0.3% | May 14, 2026 | Heap buffer overflow in WebML in Google Chrome on Windows prior to 148.0.7778.168 allowed a remote attacker to potential... |
| CVE-2026-8530 | HIGH | 8.3 | 0.3% | May 14, 2026 | Use after free in Network in Google Chrome on Windows prior to 148.0.7778.168 allowed a remote attacker who had compromi... |
| CVE-2026-8529 | HIGH | 8.8 | 0.3% | May 14, 2026 | Heap buffer overflow in Codecs in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to execute arbitrary c... |
| CVE-2026-8527 | HIGH | 8.8 | 0.3% | May 14, 2026 | Insufficient validation of untrusted input in Downloads in Google Chrome prior to 148.0.7778.168 allowed a remote attack... |
| CVE-2026-8526 | HIGH | 8.8 | 0.4% | May 14, 2026 | Out of bounds write in WebRTC in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to execute arbitrary co... |
| CVE-2026-8525 | HIGH | 8.3 | 0.2% | May 14, 2026 | Heap buffer overflow in ANGLE in Google Chrome on Mac prior to 148.0.7778.168 allowed a remote attacker to potentially p... |
| CVE-2026-8524 | HIGH | 8.8 | 0.4% | May 14, 2026 | Out of bounds write in WebAudio in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to execute arbitrary ... |
| CVE-2026-8523 | HIGH | 8.3 | 0.2% | May 14, 2026 | Use after free in Mojo in Google Chrome prior to 148.0.7778.168 allowed a remote attacker who had compromised the render... |
| CVE-2026-8522 | HIGH | 8.8 | 0.3% | May 14, 2026 | Use after free in Downloads in Google Chrome on Mac prior to 148.0.7778.168 allowed a remote attacker to execute arbitra... |
| CVE-2026-8521 | HIGH | 7.5 | 0.2% | May 14, 2026 | Use after free in Tab Groups in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to execute arbitrary cod... |
| CVE-2026-8520 | HIGH | 8.3 | 0.2% | May 14, 2026 | Race in Payments in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to potentially perform a sandbox esc... |
| CVE-2026-8519 | HIGH | 8.8 | 0.2% | May 14, 2026 | Integer overflow in ANGLE in Google Chrome on Windows prior to 148.0.7778.168 allowed a remote attacker to perform an ou... |
| CVE-2026-8518 | HIGH | 8.8 | 0.3% | May 14, 2026 | Use after free in Blink in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to execute arbitrary code ins... |
| CVE-2026-8517 | HIGH | 8.8 | 0.5% | May 14, 2026 | Object lifecycle issue in WebShare in Google Chrome on Mac prior to 148.0.7778.168 allowed a remote attacker who convinc... |
| CVE-2026-8515 | HIGH | 8.3 | 0.2% | May 14, 2026 | Use after free in HID in Google Chrome prior to 148.0.7778.168 allowed a remote attacker who convinced a user to engage ... |
| CVE-2026-8514 | HIGH | 8.3 | 0.2% | May 14, 2026 | Use after free in Aura in Google Chrome prior to 148.0.7778.168 allowed a remote attacker who had compromised the render... |
| CVE-2026-8513 | HIGH | 8.3 | 0.2% | May 14, 2026 | Use after free in Input in Google Chrome on Android prior to 148.0.7778.168 allowed a remote attacker who had compromise... |
| CVE-2026-8512 | HIGH | 8.3 | 0.2% | May 14, 2026 | Use after free in FileSystem in Google Chrome prior to 148.0.7778.168 allowed a remote attacker who convinced a user to ... |
| CVE-2026-8510 | HIGH | 7.5 | 0.2% | May 14, 2026 | Integer overflow in Skia in Google Chrome on Windows prior to 148.0.7778.168 allowed a remote attacker who had compromis... |
| CVE-2026-8509 | HIGH | 8.8 | 0.4% | May 14, 2026 | Heap buffer overflow in WebML in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to execute arbitrary co... |
| CVE-2026-46356 | HIGH | 7.5 | 0.3% | May 14, 2026 | Fleet is open source device management software. Prior to version 4.80.1, a vulnerability in Fleet's IP extraction logic... |
| CVE-2026-44637 | HIGH | 7.1 | 0.2% | May 14, 2026 | libsixel is a SIXEL encoder/decoder implementation derived from kmiya's sixel. From to 1.8.7-r1, a signed integer overf... |
| CVE-2026-44636 | HIGH | 7.8 | 0.1% | May 14, 2026 | libsixel is a SIXEL encoder/decoder implementation derived from kmiya's sixel. From to 1.8.7-r1, signed integer overflo... |
| CVE-2026-43909 | HIGH | 8.8 | 0.4% | May 14, 2026 | OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / a... |
| CVE-2026-43908 | HIGH | 8.8 | 0.4% | May 14, 2026 | OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / a... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now