2026 CVE Vulnerabilities

53,578 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-56820CRITICAL9.1Netty is a network application framework for development of protocol servers and clients. In versions 4.2.0.Final throug...
CVE-2026-56819HIGH7.5Netty is a network application framework for development of protocol servers and clients. In versions 4.2.0.Final throug...
CVE-2026-56817CRITICAL9.8Netty is a network application framework for development of protocol servers and clients. In versions 4.2.0.Final throug...
CVE-2026-16517LOW2.9A signed integer overflow vulnerability was found in libarchive's ZIP writer. In the archive_write_zip_header function i...
CVE-2026-16486MEDIUM4.3A vulnerability was found in SourceCodester Class and Exam Timetabling System 1.0. This affects an unknown part of the f...
CVE-2026-16485MEDIUM4.3A vulnerability has been found in SourceCodester Class and Exam Timetabling System 1.0. Affected by this issue is some u...
CVE-2026-16424CRITICAL9.6Use after free in GPU in Google Chrome on Android prior to 150.0.7871.182 allowed a remote attacker who had compromised ...
CVE-2026-16423HIGH8.8Use after free in UI in Google Chrome prior to 150.0.7871.182 allowed a remote attacker who convinced a user to engage i...
CVE-2026-16422HIGH7.5Insufficient validation of untrusted input in Certificate in Google Chrome on Linux prior to 150.0.7871.182 allowed an a...
CVE-2026-16421HIGH8.8Inappropriate implementation in WebAudio in Google Chrome prior to 150.0.7871.182 allowed a remote attacker to execute a...
CVE-2026-16420HIGH8.8Type Confusion in WebAudio in Google Chrome prior to 150.0.7871.182 allowed a remote attacker to execute arbitrary code ...
CVE-2026-16419CRITICAL9.6Out of bounds read and write in ANGLE in Google Chrome on Android prior to 150.0.7871.182 allowed a remote attacker to p...
CVE-2026-16418HIGH8.8Stack buffer overflow in V8 in Google Chrome prior to 150.0.7871.182 allowed a remote attacker to execute arbitrary code...
CVE-2026-16417LOW3.1Uninitialized Use in Skia in Google Chrome prior to 150.0.7871.182 allowed a remote attacker who had compromised the ren...
CVE-2026-16416CRITICAL9.3Integer overflow in Chromecast in Google Chrome prior to 150.0.7871.182 allowed a local attacker to potentially perform ...
CVE-2026-16415MEDIUM5.4Insufficient validation of untrusted input in Extensions in Google Chrome prior to 150.0.7871.182 allowed a remote attac...
CVE-2026-16414HIGH7.8Insufficient validation of untrusted input in Chromecast in Google Chrome prior to 150.0.7871.182 allowed a local attack...
CVE-2026-16413HIGH8.3Out of bounds write in ANGLE in Google Chrome prior to 150.0.7871.182 allowed a remote attacker who had compromised the ...
CVE-2026-8989MEDIUM6.8Autel Maxi Charger Single firmware through V1.03.51 permits unrestricted access to the NXP i.MX6 recovery mode through e...
CVE-2026-8988MEDIUM6.8Autel Maxi Charger Single firmware through V1.03.51 exposes an accessible UART interface that permits interruption of th...
CVE-2026-8987HIGH8.8Autel Maxi Charger Single firmware through V1.03.51 contains a heap-based buffer overflow in the set_ap_param command ha...
CVE-2026-8986CRITICAL9.8Autel Maxi Charger Single firmware through V1.03.51 is vulnerable to OS command injection when processing OCPP GetDiagno...
CVE-2026-8985CRITICAL9.8Autel Maxi Charger Single firmware through V1.03.51 is vulnerable to OS command injection in the /test endpoint exposed ...
CVE-2026-8984CRITICAL9.8Autel Maxi Charger Single firmware through V1.03.51 allows unauthenticated remote code execution via the service listeni...
CVE-2026-65319HIGH8.7Feedbin (commit 739884a) contains an unauthenticated information disclosure vulnerability that allows unauthenticated at...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now