2026 CVE Vulnerabilities
43,284 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-57621 | CRITICAL | 9.8 | — | Jul 2, 2026 | Unauthenticated PHP Object Injection in Booktics <= 1.0.21 versions. |
| CVE-2026-27436 | CRITICAL | 9.1 | — | Jul 2, 2026 | Editor Arbitrary Code Execution in Five Star Business Profile and Schema <= 2.3.19 versions. |
| CVE-2026-27419 | CRITICAL | 9.9 | — | Jul 2, 2026 | Subscriber Arbitrary File Upload in Zegen <= 1.1.9 versions. |
| CVE-2026-14439 | CRITICAL | 9.4 | 0.6% | Jul 1, 2026 | A path traversal vulnerability exists in the Git Service component shared by Altium Enterprise Server and Altium 365. Th... |
| CVE-2026-14425 | CRITICAL | 9.6 | 0.2% | Jul 1, 2026 | Use after free in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandb... |
| CVE-2026-14424 | CRITICAL | 9.6 | 0.2% | Jul 1, 2026 | Use after free in Dawn in Google Chrome on Mac prior to 150.0.7871.46 allowed a remote attacker to potentially perform a... |
| CVE-2026-14423 | CRITICAL | 9.6 | 0.2% | Jul 1, 2026 | Type Confusion in Tint in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbo... |
| CVE-2026-14420 | CRITICAL | 9.6 | 0.2% | Jul 1, 2026 | Out of bounds read and write in Dawn in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially pe... |
| CVE-2026-14419 | CRITICAL | 9.6 | 0.2% | Jul 1, 2026 | Use after free in Skia in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbo... |
| CVE-2026-14417 | CRITICAL | 9.6 | 0.2% | Jul 1, 2026 | Use after free in Dawn in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbo... |
| CVE-2026-14416 | CRITICAL | 9.6 | 0.2% | Jul 1, 2026 | Out of bounds read in Dawn in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sa... |
| CVE-2026-14411 | CRITICAL | 9.6 | 0.2% | Jul 1, 2026 | Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to... |
| CVE-2026-14405 | CRITICAL | 9.6 | 0.3% | Jul 1, 2026 | Uninitialized Use in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to execute arbitrary code insi... |
| CVE-2026-14398 | CRITICAL | 9.6 | 0.2% | Jul 1, 2026 | Use after free in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandb... |
| CVE-2026-14397 | CRITICAL | 9.6 | 0.2% | Jul 1, 2026 | Out of bounds write in ANGLE in Google Chrome on Mac prior to 150.0.7871.46 allowed a remote attacker to potentially per... |
| CVE-2026-14392 | CRITICAL | 9.6 | 0.2% | Jul 1, 2026 | Out of bounds write in Tint in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a s... |
| CVE-2026-14390 | CRITICAL | 9.6 | 0.2% | Jul 1, 2026 | Use after free in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandb... |
| CVE-2026-14387 | CRITICAL | 9.6 | 0.2% | Jul 1, 2026 | Integer overflow in Skia in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sand... |
| CVE-2026-14382 | CRITICAL | 9.6 | 0.2% | Jul 1, 2026 | Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to... |
| CVE-2026-52186 | CRITICAL | 9.8 | 0.3% | Jul 1, 2026 | SQL Injection vulnerability in UTT nv518G nv518GV3v3.2.7-210919-161313 allows a remote attacker to execute arbitrary cod... |
| CVE-2026-58457 | CRITICAL | 9.8 | 1.7% | Jul 1, 2026 | Shenzhen Aitemi M300 Wi-Fi Repeater (hardware model MT02) contains an unauthenticated OS command injection vulnerability... |
| CVE-2026-14363 | CRITICAL | 9.8 | 0.3% | Jul 1, 2026 | Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in The Wikimedia Foun... |
| CVE-2026-53492 | CRITICAL | 9.6 | 0.5% | Jul 1, 2026 | containerd is an open-source container runtime. In Versions prior to 2.3.2, 2.2.5 and 2.1.9, the CRI implementation impr... |
| CVE-2026-51947 | CRITICAL | 9.8 | 0.6% | Jul 1, 2026 | An issue in Pivotal CRM 6.6.4.08 and systems using patch-ghi-15381-cwe-502-20251225.zip (fixed in Pivotal CRM 6.6.5.10 a... |
| CVE-2026-50195 | CRITICAL | 9.9 | 0.3% | Jul 1, 2026 | containerd is an open-source container runtime. Versions prior to 2.3.2, 2.2.5 and 2.1.9 contain a vulnerability in the ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now