2026 CVE Vulnerabilities
64,785 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-45316 | LOW | 3.5 | 0.2% | May 15, 2026 | Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.3, the P... |
| CVE-2026-45803 | LOW | 3.5 | 0.2% | May 15, 2026 | `gh` is GitHub’s official command line tool. From 1.6.0 to before 2.92.0, a security vulnerability has been identified i... |
| CVE-2026-41963 | LOW | 2.8 | 0.1% | May 15, 2026 | Stack overflow vulnerability in the media platform. Impact: Successful exploitation of this vulnerability may affect ava... |
| CVE-2026-41962 | LOW | 3.6 | 0.1% | May 15, 2026 | Permission control vulnerability in the app management and control module. Impact: Successful exploitation of this vulne... |
| CVE-2026-0428 | LOW | 1.8 | 0.1% | May 15, 2026 | Insufficient parameter sanitization in TEE SOC Driver could allow an attacker to issue a malformed DRV_SOC_CMD_ID_SRIOV_... |
| CVE-2026-45781 | LOW | 3.5 | 0.2% | May 14, 2026 | The MCP Registry provides MCP clients with a list of MCP servers, like an app store for MCP servers. Prior to 1.7.9, OCI... |
| CVE-2026-8579 | LOW | 3.1 | 0.1% | May 14, 2026 | Insufficient validation of untrusted input in Skia in Google Chrome prior to 148.0.7778.168 allowed a remote attacker wh... |
| CVE-2026-8578 | LOW | 3.1 | 0.2% | May 14, 2026 | Out of bounds read in GPU in Google Chrome on Linux prior to 148.0.7778.168 allowed a remote attacker who had compromise... |
| CVE-2026-8572 | LOW | 3.1 | 0.2% | May 14, 2026 | Insufficient policy enforcement in Network in Google Chrome on Android prior to 148.0.7778.168 allowed a remote attacker... |
| CVE-2026-8556 | LOW | 3.1 | 0.2% | May 14, 2026 | Inappropriate implementation in ANGLE in Google Chrome on Windows prior to 148.0.7778.168 allowed a remote attacker who ... |
| CVE-2026-8554 | LOW | 3.1 | 0.2% | May 14, 2026 | Type Confusion in ANGLE in Google Chrome on Windows prior to 148.0.7778.168 allowed a remote attacker who had compromise... |
| CVE-2026-8553 | LOW | 3.1 | 0.2% | May 14, 2026 | Use after free in GPU in Google Chrome prior to 148.0.7778.168 allowed a remote attacker who had compromised the rendere... |
| CVE-2026-8545 | LOW | 3.1 | 0.2% | May 14, 2026 | Object corruption in Compositing in Google Chrome prior to 148.0.7778.168 allowed a remote attacker who had compromised ... |
| CVE-2026-8536 | LOW | 3.1 | 0.2% | May 14, 2026 | Insufficient validation of untrusted input in ReadingMode in Google Chrome on Mac prior to 148.0.7778.168 allowed a remo... |
| CVE-2026-44638 | LOW | 2.5 | 0.1% | May 14, 2026 | libsixel is a SIXEL encoder/decoder implementation derived from kmiya's sixel. From to 1.8.7-r1, a wrong NULL check aft... |
| CVE-2026-44589 | LOW | 3.7 | 0.2% | May 14, 2026 | Nuxt OG Image generates OG Images with Vue templates in Nuxt. The isBlockedUrl() denylist introduced in nuxt-og-image@6.... |
| CVE-2026-6923 | LOW | 3.8 | 0.1% | May 14, 2026 | A side-channel attack, which requires a physical presence to the TPM, can lead to extraction of an Elliptic Curve Diffie... |
| CVE-2026-44515 | LOW | 2.3 | 0.2% | May 14, 2026 | Nextcloud News is an RSS/Atom feed reader. Prior to 28.3.0-beta.1, Nextcloud News allows authenticated users to add feed... |
| CVE-2026-44348 | LOW | 2.5 | 0.1% | May 14, 2026 | PoDoFo is a C++17 PDF manipulation library. From 1.0.0 to before 1.0.4, a double-free vulnerability exists in compute_ha... |
| CVE-2026-7471 | LOW | 3.5 | 0.2% | May 14, 2026 | GitLab has remediated an issue in GitLab EE affecting all versions from 18.8 before 18.9.7, 18.10 before 18.10.6, and 18... |
| CVE-2026-2900 | LOW | 2.7 | 0.2% | May 14, 2026 | GitLab has remediated an issue in GitLab EE affecting all versions from 16.10 before 18.9.7, 18.10 before 18.10.6, and 1... |
| CVE-2026-33585 | LOW | 3.8 | 0.1% | May 13, 2026 | Improper management of the idle timeout parameter in the Keycloak interface of the Arqit SKA-Platform enables an attacke... |
| CVE-2026-0238 | LOW | 3.2 | 0.1% | May 13, 2026 | A vulnerability in Palo Alto Networks Broker VM allows an authenticated administrator to inject arbitrary content into c... |
| CVE-2026-44582 | LOW | 3.7 | 0.2% | May 13, 2026 | Next.js is a React framework for building full-stack web applications. From 13.4.6 to before 15.5.16 and 16.2.5, React S... |
| CVE-2026-44459 | LOW | 3.8 | 0.2% | May 13, 2026 | Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.18, improper validat... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now