2026 CVE Vulnerabilities

52,233 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-6305HIGH8.8Heap buffer overflow in PDFium in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to execute arbitrary c...
CVE-2026-6304HIGH8.3Use after free in Graphite in Google Chrome prior to 147.0.7727.101 allowed a remote attacker who had compromised the re...
CVE-2026-6303HIGH8.8Use after free in Codecs in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to execute arbitrary code in...
CVE-2026-6302HIGH8.8Use after free in Video in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to execute arbitrary code ins...
CVE-2026-6301HIGH8.8Type Confusion in Turbofan in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to execute arbitrary code ...
CVE-2026-6300HIGH8.8Use after free in CSS in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to execute arbitrary code insid...
CVE-2026-6299HIGH8.8Use after free in Prerender in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to execute arbitrary code...
CVE-2026-6297HIGH8.3Use after free in Proxy in Google Chrome prior to 147.0.7727.101 allowed an attacker in a privileged network position to...
CVE-2026-40917HIGH7.1A flaw was found in GIMP. This vulnerability, a heap buffer over-read in the `icns_slurp()` function, occurs when proces...
CVE-2026-40915HIGH7.8A flaw was found in GIMP. A remote attacker could exploit an integer overflow vulnerability in the FITS image loader by ...
CVE-2026-35569HIGH8.7ApostropheCMS is an open-source Node.js content management system. Versions 4.28.0 and prior contain a stored cross-site...
CVE-2026-4857HIGH8.4IdentityIQ 8.5, all IdentityIQ 8.5 patch levels prior to 8.5p2, IdentityIQ 8.4, and all IdentityIQ 8.4 patch levels prio...
CVE-2026-34632HIGH8.6Adobe Photoshop Installer was affected by an Uncontrolled Search Path Element vulnerability that could have resulted in ...
CVE-2026-34393HIGH8.8Weblate is a web based localization tool. In versions prior to 5.17, the user patching API endpoint didn't properly limi...
CVE-2026-34242HIGH7.7Weblate is a web based localization tool. In versions prior to 5.17, the ZIP download feature didn't verify downloaded f...
CVE-2026-33667HIGH7.4OpenProject is an open-source project management application. In versions prior to 17.3.0, 2FA OTP verification in the c...
CVE-2026-33435HIGH8Weblate is a web based localization tool. In versions prior to 5.17, the project backup didn't filter Git and Mercurial ...
CVE-2026-32631HIGH7.4Git for Windows is the Windows port of Git. Versions prior to 2.53.0.windows.3 do not have protections that prevent atta...
CVE-2026-6372HIGH7.5Missing Authorization vulnerability in Plisio Accept Cryptocurrencies with Plisio allows Exploiting Incorrectly Configur...
CVE-2026-30996HIGH7.5An issue in the file handling logic of the component download.php of SAC-NFe v2.0.02 allows attackers to execute a direc...
CVE-2026-30995HIGH8.6Slah CMS v1.5.0 and below was discovered to contain a SQL injection vulnerability via the id parameter in the vereador_v...
CVE-2026-30994HIGH7.5Incorrect access control in the config.php component of Slah v1.5.0 and below allows unauthenticated attackers to access...
CVE-2026-30624HIGH8.6Agent Zero 0.9.8 contains a remote code execution vulnerability in its External MCP Servers configuration feature. The a...
CVE-2026-30617HIGH8.6LangChain-ChatChat 0.3.1 contains a remote code execution vulnerability in its MCP STDIO server configuration and execut...
CVE-2026-30616HIGH7.3Jaaz 1.0.30 contains a remote code execution vulnerability in its MCP STDIO command execution handling. A remote attacke...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now