2026 CVE Vulnerabilities

43,284 CVEs published in 2026.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2026-57621CRITICAL9.8Unauthenticated PHP Object Injection in Booktics <= 1.0.21 versions.
CVE-2026-27436CRITICAL9.1Editor Arbitrary Code Execution in Five Star Business Profile and Schema <= 2.3.19 versions.
CVE-2026-27419CRITICAL9.9Subscriber Arbitrary File Upload in Zegen <= 1.1.9 versions.
CVE-2026-14439CRITICAL9.4A path traversal vulnerability exists in the Git Service component shared by Altium Enterprise Server and Altium 365. Th...
CVE-2026-14425CRITICAL9.6Use after free in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandb...
CVE-2026-14424CRITICAL9.6Use after free in Dawn in Google Chrome on Mac prior to 150.0.7871.46 allowed a remote attacker to potentially perform a...
CVE-2026-14423CRITICAL9.6Type Confusion in Tint in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbo...
CVE-2026-14420CRITICAL9.6Out of bounds read and write in Dawn in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially pe...
CVE-2026-14419CRITICAL9.6Use after free in Skia in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbo...
CVE-2026-14417CRITICAL9.6Use after free in Dawn in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbo...
CVE-2026-14416CRITICAL9.6Out of bounds read in Dawn in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sa...
CVE-2026-14411CRITICAL9.6Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to...
CVE-2026-14405CRITICAL9.6Uninitialized Use in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to execute arbitrary code insi...
CVE-2026-14398CRITICAL9.6Use after free in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandb...
CVE-2026-14397CRITICAL9.6Out of bounds write in ANGLE in Google Chrome on Mac prior to 150.0.7871.46 allowed a remote attacker to potentially per...
CVE-2026-14392CRITICAL9.6Out of bounds write in Tint in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a s...
CVE-2026-14390CRITICAL9.6Use after free in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandb...
CVE-2026-14387CRITICAL9.6Integer overflow in Skia in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sand...
CVE-2026-14382CRITICAL9.6Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to...
CVE-2026-52186CRITICAL9.8SQL Injection vulnerability in UTT nv518G nv518GV3v3.2.7-210919-161313 allows a remote attacker to execute arbitrary cod...
CVE-2026-58457CRITICAL9.8Shenzhen Aitemi M300 Wi-Fi Repeater (hardware model MT02) contains an unauthenticated OS command injection vulnerability...
CVE-2026-14363CRITICAL9.8Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in The Wikimedia Foun...
CVE-2026-53492CRITICAL9.6containerd is an open-source container runtime. In Versions prior to 2.3.2, 2.2.5 and 2.1.9, the CRI implementation impr...
CVE-2026-51947CRITICAL9.8An issue in Pivotal CRM 6.6.4.08 and systems using patch-ghi-15381-cwe-502-20251225.zip (fixed in Pivotal CRM 6.6.5.10 a...
CVE-2026-50195CRITICAL9.9containerd is an open-source container runtime. Versions prior to 2.3.2, 2.2.5 and 2.1.9 contain a vulnerability in the ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now