2026 CVE Vulnerabilities
51,613 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-7357 | HIGH | 7.5 | 0.2% | Apr 28, 2026 | Use after free in GPU in Google Chrome prior to 147.0.7727.138 allowed a remote attacker who had compromised the rendere... |
| CVE-2026-7356 | HIGH | 8.8 | 0.3% | Apr 28, 2026 | Use after free in Navigation in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to execute arbitrary cod... |
| CVE-2026-7355 | HIGH | 8.8 | 0.3% | Apr 28, 2026 | Use after free in Media in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to execute arbitrary code ins... |
| CVE-2026-7354 | HIGH | 8.8 | 0.3% | Apr 28, 2026 | Out of bounds read and write in Angle in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to potentially ... |
| CVE-2026-7353 | HIGH | 8.3 | 0.3% | Apr 28, 2026 | Heap buffer overflow in Skia in Google Chrome prior to 147.0.7727.138 allowed a remote attacker who had compromised the ... |
| CVE-2026-7352 | HIGH | 8.3 | 0.2% | Apr 28, 2026 | Use after free in Media in Google Chrome on Android prior to 147.0.7727.138 allowed a remote attacker who had compromise... |
| CVE-2026-7350 | HIGH | 8.3 | 0.2% | Apr 28, 2026 | Use after free in WebMIDI in Google Chrome prior to 147.0.7727.138 allowed a remote attacker who had compromised the ren... |
| CVE-2026-7349 | HIGH | 7.5 | 0.1% | Apr 28, 2026 | Use after free in Cast in Google Chrome prior to 147.0.7727.138 allowed an attacker on the local network segment to exec... |
| CVE-2026-7348 | HIGH | 8.8 | 0.3% | Apr 28, 2026 | Use after free in Codecs in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to execute arbitrary code in... |
| CVE-2026-7347 | HIGH | 8.1 | 0.4% | Apr 28, 2026 | Use after free in Chromoting in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to execute arbitrary cod... |
| CVE-2026-7346 | HIGH | 8.1 | 0.3% | Apr 28, 2026 | Inappropriate implementation in Tint in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to perform out o... |
| CVE-2026-7345 | HIGH | 8.3 | 0.2% | Apr 28, 2026 | Insufficient validation of untrusted input in Feedback in Google Chrome prior to 147.0.7727.138 allowed a remote attacke... |
| CVE-2026-7344 | HIGH | 8.8 | 0.2% | Apr 28, 2026 | Use after free in Accessibility in Google Chrome on Windows prior to 147.0.7727.138 allowed a remote attacker who had co... |
| CVE-2026-7343 | HIGH | 7.5 | 0.2% | Apr 28, 2026 | Use after free in Views in Google Chrome on Windows prior to 147.0.7727.138 allowed a remote attacker who had compromise... |
| CVE-2026-7342 | HIGH | 8.8 | 0.4% | Apr 28, 2026 | Use after free in WebView in Google Chrome on Android prior to 147.0.7727.138 allowed a remote attacker to execute arbit... |
| CVE-2026-7341 | HIGH | 8.8 | 0.4% | Apr 28, 2026 | Use after free in WebRTC in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to execute arbitrary code in... |
| CVE-2026-7339 | HIGH | 8.8 | 0.3% | Apr 28, 2026 | Heap buffer overflow in WebRTC in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to potentially exploit... |
| CVE-2026-7338 | HIGH | 7.5 | 0.1% | Apr 28, 2026 | Use after free in Cast in Google Chrome prior to 147.0.7727.138 allowed an attacker on the local network segment to pote... |
| CVE-2026-7337 | HIGH | 8.8 | 0.3% | Apr 28, 2026 | Type Confusion in V8 in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to execute arbitrary code inside... |
| CVE-2026-7336 | HIGH | 8.8 | 0.4% | Apr 28, 2026 | Use after free in WebRTC in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to execute arbitrary code in... |
| CVE-2026-7335 | HIGH | 8.8 | 0.3% | Apr 28, 2026 | Use after free in media in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to execute arbitrary code ins... |
| CVE-2026-7334 | HIGH | 8.8 | 0.3% | Apr 28, 2026 | Use after free in Views in Google Chrome on Mac prior to 147.0.7727.138 allowed a remote attacker to potentially exploit... |
| CVE-2026-42167 | HIGH | 8.1 | 4.4% | Apr 28, 2026 | mod_sql in ProFTPD before 1.3.9a allows remote attackers to execute arbitrary code via a username, in scenarios where th... |
| CVE-2026-7319 | HIGH | 7.3 | 0.5% | Apr 28, 2026 | A flaw has been found in elinsky execution-system-mcp 0.1.0. The impacted element is the function _get_context_file_path... |
| CVE-2026-7316 | HIGH | 7.3 | 1.3% | Apr 28, 2026 | A vulnerability has been found in eiliyaabedini aider-mcp up to 667b914301aada695aab0e46d1fb3a7d5e32c8af. Affected is an... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now