2026 CVE Vulnerabilities
52,233 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-6305 | HIGH | 8.8 | 0.3% | Apr 15, 2026 | Heap buffer overflow in PDFium in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to execute arbitrary c... |
| CVE-2026-6304 | HIGH | 8.3 | 0.3% | Apr 15, 2026 | Use after free in Graphite in Google Chrome prior to 147.0.7727.101 allowed a remote attacker who had compromised the re... |
| CVE-2026-6303 | HIGH | 8.8 | 0.4% | Apr 15, 2026 | Use after free in Codecs in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to execute arbitrary code in... |
| CVE-2026-6302 | HIGH | 8.8 | 0.3% | Apr 15, 2026 | Use after free in Video in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to execute arbitrary code ins... |
| CVE-2026-6301 | HIGH | 8.8 | 0.4% | Apr 15, 2026 | Type Confusion in Turbofan in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to execute arbitrary code ... |
| CVE-2026-6300 | HIGH | 8.8 | 0.3% | Apr 15, 2026 | Use after free in CSS in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to execute arbitrary code insid... |
| CVE-2026-6299 | HIGH | 8.8 | 0.3% | Apr 15, 2026 | Use after free in Prerender in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to execute arbitrary code... |
| CVE-2026-6297 | HIGH | 8.3 | 0.2% | Apr 15, 2026 | Use after free in Proxy in Google Chrome prior to 147.0.7727.101 allowed an attacker in a privileged network position to... |
| CVE-2026-40917 | HIGH | 7.1 | 0.2% | Apr 15, 2026 | A flaw was found in GIMP. This vulnerability, a heap buffer over-read in the `icns_slurp()` function, occurs when proces... |
| CVE-2026-40915 | HIGH | 7.8 | 0.4% | Apr 15, 2026 | A flaw was found in GIMP. A remote attacker could exploit an integer overflow vulnerability in the FITS image loader by ... |
| CVE-2026-35569 | HIGH | 8.7 | 0.3% | Apr 15, 2026 | ApostropheCMS is an open-source Node.js content management system. Versions 4.28.0 and prior contain a stored cross-site... |
| CVE-2026-4857 | HIGH | 8.4 | 0.3% | Apr 15, 2026 | IdentityIQ 8.5, all IdentityIQ 8.5 patch levels prior to 8.5p2, IdentityIQ 8.4, and all IdentityIQ 8.4 patch levels prio... |
| CVE-2026-34632 | HIGH | 8.6 | 0.3% | Apr 15, 2026 | Adobe Photoshop Installer was affected by an Uncontrolled Search Path Element vulnerability that could have resulted in ... |
| CVE-2026-34393 | HIGH | 8.8 | 0.4% | Apr 15, 2026 | Weblate is a web based localization tool. In versions prior to 5.17, the user patching API endpoint didn't properly limi... |
| CVE-2026-34242 | HIGH | 7.7 | 0.4% | Apr 15, 2026 | Weblate is a web based localization tool. In versions prior to 5.17, the ZIP download feature didn't verify downloaded f... |
| CVE-2026-33667 | HIGH | 7.4 | 0.3% | Apr 15, 2026 | OpenProject is an open-source project management application. In versions prior to 17.3.0, 2FA OTP verification in the c... |
| CVE-2026-33435 | HIGH | 8 | 0.7% | Apr 15, 2026 | Weblate is a web based localization tool. In versions prior to 5.17, the project backup didn't filter Git and Mercurial ... |
| CVE-2026-32631 | HIGH | 7.4 | 0.3% | Apr 15, 2026 | Git for Windows is the Windows port of Git. Versions prior to 2.53.0.windows.3 do not have protections that prevent atta... |
| CVE-2026-6372 | HIGH | 7.5 | 0.2% | Apr 15, 2026 | Missing Authorization vulnerability in Plisio Accept Cryptocurrencies with Plisio allows Exploiting Incorrectly Configur... |
| CVE-2026-30996 | HIGH | 7.5 | 0.7% | Apr 15, 2026 | An issue in the file handling logic of the component download.php of SAC-NFe v2.0.02 allows attackers to execute a direc... |
| CVE-2026-30995 | HIGH | 8.6 | 0.2% | Apr 15, 2026 | Slah CMS v1.5.0 and below was discovered to contain a SQL injection vulnerability via the id parameter in the vereador_v... |
| CVE-2026-30994 | HIGH | 7.5 | 0.3% | Apr 15, 2026 | Incorrect access control in the config.php component of Slah v1.5.0 and below allows unauthenticated attackers to access... |
| CVE-2026-30624 | HIGH | 8.6 | 0.4% | Apr 15, 2026 | Agent Zero 0.9.8 contains a remote code execution vulnerability in its External MCP Servers configuration feature. The a... |
| CVE-2026-30617 | HIGH | 8.6 | 0.5% | Apr 15, 2026 | LangChain-ChatChat 0.3.1 contains a remote code execution vulnerability in its MCP STDIO server configuration and execut... |
| CVE-2026-30616 | HIGH | 7.3 | 0.3% | Apr 15, 2026 | Jaaz 1.0.30 contains a remote code execution vulnerability in its MCP STDIO command execution handling. A remote attacke... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now