2026 CVE Vulnerabilities
52,233 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-40245 | HIGH | 7.5 | 0.5% | Apr 16, 2026 | Free5GC is an open-source Linux Foundation project for 5th generation (5G) mobile core networks. Versions 4.2.1 and belo... |
| CVE-2026-40193 | HIGH | 8.2 | 0.4% | Apr 16, 2026 | maddy is a composable, all-in-one mail server. Versions prior to 0.9.3 contain an LDAP injection vulnerability in the au... |
| CVE-2026-40316 | HIGH | 8.8 | 0.4% | Apr 15, 2026 | OWASP BLT is a QA testing and vulnerability disclosure platform that encompasses websites, apps, git repositories, and m... |
| CVE-2026-40192 | HIGH | 7.5 | 0.7% | Apr 15, 2026 | Pillow is a Python imaging library. Versions 10.3.0 through 12.1.1 did not limit the amount of GZIP-compressed data read... |
| CVE-2026-40261 | HIGH | 8.8 | 1.7% | Apr 15, 2026 | Composer is a dependency manager for PHP. Versions 1.0 through 2.2.26 and 2.3 through 2.9.5 contain a command injection ... |
| CVE-2026-40176 | HIGH | 7.8 | 1.1% | Apr 15, 2026 | Composer is a dependency manager for PHP. Versions 1.0 through 2.2.26 and 2.3 through 2.9.5 contain a command injection ... |
| CVE-2026-22676 | HIGH | 8.5 | 0.1% | Apr 15, 2026 | Barracuda RMM versions prior to 2025.2.2 contain a privilege escalation vulnerability that allows local attackers to gai... |
| CVE-2026-6384 | HIGH | 7.8 | 0.3% | Apr 15, 2026 | A flaw was found in gimp. This buffer overflow vulnerability in the GIF image loading component's `ReadJeffsImage` funct... |
| CVE-2026-6363 | HIGH | 8.8 | 0.3% | Apr 15, 2026 | Type Confusion in V8 in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to potentially perform out of bo... |
| CVE-2026-6361 | HIGH | 8.3 | 0.3% | Apr 15, 2026 | Heap buffer overflow in PDFium in Google Chrome on Windows prior to 147.0.7727.101 allowed a remote attacker who convinc... |
| CVE-2026-6360 | HIGH | 8.8 | 0.3% | Apr 15, 2026 | Use after free in FileSystem in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to potentially exploit o... |
| CVE-2026-6359 | HIGH | 8.8 | 0.3% | Apr 15, 2026 | Use after free in Video in Google Chrome on Windows prior to 147.0.7727.101 allowed a remote attacker who had compromise... |
| CVE-2026-6358 | HIGH | 8.8 | 0.3% | Apr 15, 2026 | Use after free in XR in Google Chrome on Android prior to 147.0.7727.101 allowed a remote attacker to perform an out of ... |
| CVE-2026-6319 | HIGH | 7.5 | 0.3% | Apr 15, 2026 | Use after free in Payments in Google Chrome on Android prior to 147.0.7727.101 allowed a remote attacker who convinced a... |
| CVE-2026-6318 | HIGH | 8.8 | 0.3% | Apr 15, 2026 | Use after free in Codecs in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to execute arbitrary code in... |
| CVE-2026-6317 | HIGH | 8.8 | 0.3% | Apr 15, 2026 | Use after free in Cast in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to execute arbitrary code via ... |
| CVE-2026-6316 | HIGH | 8.8 | 0.3% | Apr 15, 2026 | Use after free in Forms in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to execute arbitrary code ins... |
| CVE-2026-6315 | HIGH | 8.8 | 0.3% | Apr 15, 2026 | Use after free in Permissions in Google Chrome on Android prior to 147.0.7727.101 allowed a remote attacker who convince... |
| CVE-2026-6314 | HIGH | 8.3 | 0.3% | Apr 15, 2026 | Out of bounds write in GPU in Google Chrome prior to 147.0.7727.101 allowed a remote attacker who had compromised the GP... |
| CVE-2026-6311 | HIGH | 8.3 | 0.3% | Apr 15, 2026 | Uninitialized Use in Accessibility in Google Chrome on Windows prior to 147.0.7727.101 allowed a remote attacker who had... |
| CVE-2026-6310 | HIGH | 8.3 | 0.3% | Apr 15, 2026 | Use after free in Dawn in Google Chrome prior to 147.0.7727.101 allowed a remote attacker who had compromised the render... |
| CVE-2026-6309 | HIGH | 8.3 | 0.3% | Apr 15, 2026 | Use after free in Viz in Google Chrome prior to 147.0.7727.101 allowed a remote attacker who had compromised the rendere... |
| CVE-2026-6308 | HIGH | 7.5 | 0.3% | Apr 15, 2026 | Out of bounds read in Media in Google Chrome prior to 147.0.7727.101 allowed a remote attacker who convinced a user to e... |
| CVE-2026-6307 | HIGH | 8.8 | 0.4% | Apr 15, 2026 | Type Confusion in Turbofan in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to execute arbitrary code ... |
| CVE-2026-6306 | HIGH | 8.8 | 0.3% | Apr 15, 2026 | Heap buffer overflow in PDFium in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to execute arbitrary c... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now