2026 CVE Vulnerabilities
51,137 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-40326 | HIGH | 7.1 | 0.2% | May 6, 2026 | Masa CMS is a content management system forked from Mura CMS. In versions 7.5.2 and earlier, the createBundle method in ... |
| CVE-2026-40325 | HIGH | 8.7 | 0.2% | May 6, 2026 | Masa CMS is a content management system forked from Mura CMS. In versions 7.5.2 and earlier, the `cTrash.restore` functi... |
| CVE-2026-40309 | HIGH | 7.2 | 0.2% | May 6, 2026 | Masa CMS is a content management system forked from Mura CMS. In versions 7.5.2 and earlier, the cTrash.empty function d... |
| CVE-2026-40174 | HIGH | 7.1 | 0.2% | May 6, 2026 | Masa CMS is a content management system forked from Mura CMS. In versions 7.5.2 and earlier, the cUsers.updateAddress fu... |
| CVE-2026-40171 | HIGH | 8.4 | 0.5% | May 6, 2026 | In Jupyter Notebook versions 7.0.0 through 7.5.5, JupyterLab versions 4.5.6 and earlier, and the corresponding @jupyter-... |
| CVE-2026-40076 | HIGH | 8.8 | 0.9% | May 6, 2026 | OpenMRS Core is an open source electronic medical record system platform. In versions 2.7.8 and earlier and versions 2.8... |
| CVE-2026-8018 | HIGH | 8.1 | 0.3% | May 6, 2026 | Insufficient policy enforcement in DevTools in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to potenti... |
| CVE-2026-8016 | HIGH | 8.8 | 0.3% | May 6, 2026 | Use after free in WebRTC in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to execute arbitrary code ins... |
| CVE-2026-8007 | HIGH | 7.5 | 0.2% | May 6, 2026 | Insufficient validation of untrusted input in Cast in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who... |
| CVE-2026-8002 | HIGH | 8.8 | 0.2% | May 6, 2026 | Use after free in Audio in Google Chrome on Mac prior to 148.0.7778.96 allowed a remote attacker to execute arbitrary co... |
| CVE-2026-8001 | HIGH | 8.3 | 0.2% | May 6, 2026 | Use After Free in Printing in Google Chrome on Linux, Mac, ChromeOS prior to 148.0.7778.96 allowed a remote attacker who... |
| CVE-2026-8000 | HIGH | 8.8 | 0.2% | May 6, 2026 | Insufficient validation of untrusted input in ChromeDriver in Google Chrome on Windows prior to 148.0.7778.96 allowed a ... |
| CVE-2026-7997 | HIGH | 7.8 | 0.1% | May 6, 2026 | Insufficient validation of untrusted input in Updater in Google Chrome on Mac prior to 148.0.7778.96 allowed a local att... |
| CVE-2026-7995 | HIGH | 8.8 | 0.2% | May 6, 2026 | Out of bounds read in AdFilter in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to execute arbitrary co... |
| CVE-2026-7994 | HIGH | 7.8 | 0.1% | May 6, 2026 | Inappropriate implementation in Chromoting in Google Chrome on Windows prior to 148.0.7778.96 allowed a local attacker t... |
| CVE-2026-7992 | HIGH | 8.8 | 0.2% | May 6, 2026 | Insufficient validation of untrusted input in UI in Google Chrome on Linux, ChromeOS prior to 148.0.7778.96 allowed a re... |
| CVE-2026-7991 | HIGH | 8.8 | 0.2% | May 6, 2026 | Use after free in UI in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer ... |
| CVE-2026-7990 | HIGH | 7.8 | 0.1% | May 6, 2026 | Insufficient validation of untrusted input in Updater in Google Chrome on Windows prior to 148.0.7778.96 allowed a local... |
| CVE-2026-7988 | HIGH | 8.8 | 0.3% | May 6, 2026 | Type Confusion in WebRTC in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to execute arbitrary code ins... |
| CVE-2026-7987 | HIGH | 8.8 | 0.3% | May 6, 2026 | Use after free in WebRTC in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to execute arbitrary code ins... |
| CVE-2026-7985 | HIGH | 8.3 | 0.2% | May 6, 2026 | Use after free in GPU in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer... |
| CVE-2026-7984 | HIGH | 8.8 | 0.3% | May 6, 2026 | Use after free in ReadingMode in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the ... |
| CVE-2026-7981 | HIGH | 8.1 | 0.2% | May 6, 2026 | Out of bounds read in Codecs in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to obtain potentially sen... |
| CVE-2026-7980 | HIGH | 8.8 | 0.3% | May 6, 2026 | Use after free in WebAudio in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to execute arbitrary code i... |
| CVE-2026-7978 | HIGH | 8.1 | 0.2% | May 6, 2026 | Inappropriate implementation in Companion in Google Chrome on Mac prior to 148.0.7778.96 allowed a remote attacker to pe... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now