2026 CVE Vulnerabilities

53,233 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-5282HIGH8.1Out of bounds read in WebCodecs in Google Chrome prior to 146.0.7680.178 allowed a remote attacker to perform an out of ...
CVE-2026-5281HIGH8.8Use after free in Dawn in Google Chrome prior to 146.0.7680.178 allowed a remote attacker who had compromised the render...
CVE-2026-5280HIGH8.8Use after free in WebCodecs in Google Chrome prior to 146.0.7680.178 allowed a remote attacker to execute arbitrary code...
CVE-2026-5279HIGH8.8Object corruption in V8 in Google Chrome prior to 146.0.7680.178 allowed a remote attacker to execute arbitrary code ins...
CVE-2026-5278HIGH8.8Use after free in Web MIDI in Google Chrome on Android prior to 146.0.7680.178 allowed a remote attacker to execute arbi...
CVE-2026-5277HIGH7.5Integer overflow in ANGLE in Google Chrome on Windows prior to 146.0.7680.178 allowed a remote attacker who had compromi...
CVE-2026-5275HIGH8.8Heap buffer overflow in ANGLE in Google Chrome on Mac prior to 146.0.7680.178 allowed a remote attacker to execute arbit...
CVE-2026-5274HIGH8.8Integer overflow in Codecs in Google Chrome prior to 146.0.7680.178 allowed a remote attacker to perform arbitrary read/...
CVE-2026-5272HIGH8.8Heap buffer overflow in GPU in Google Chrome prior to 146.0.7680.178 allowed a remote attacker to execute arbitrary code...
CVE-2026-4947HIGH7.1Addressed a potential insecure direct object reference (IDOR) vulnerability in the signing invitation acceptance process...
CVE-2026-3780HIGH7.8The application's installer runs with elevated privileges but resolves system executables and DLLs using untrusted searc...
CVE-2026-3779HIGH7.8The application's list box calculate array logic keeps stale references to page or form objects after they are deleted o...
CVE-2026-3777HIGH7.8The application does not properly validate the lifetime and validity of internal view cache pointers after JavaScript ch...
CVE-2026-3775HIGH7.8The application's update service, when checking for updates, loads certain system libraries from a search path that incl...
CVE-2026-3774HIGH7.5The application allows PDF JavaScript and document/print actions (such as WillPrint/DidPrint) to update form fields, ann...
CVE-2026-35056HIGH8.6XenForo before 2.3.9 and before 2.2.18 allows remote code execution (RCE) by authenticated, but malicious, admin users. ...
CVE-2026-5238HIGH7.3A weakness has been identified in itsourcecode Payroll Management System 1.0. Affected by this issue is some unknown fun...
CVE-2026-5237HIGH7.3A security flaw has been discovered in itsourcecode Payroll Management System 1.0. Affected by this vulnerability is an ...
CVE-2026-5214HIGH8.8A vulnerability was found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-32...
CVE-2026-34585HIGH8.2SiYuan is a personal knowledge management system. Prior to version 3.6.2, a vulnerability allows crafted block attribute...
CVE-2026-34453HIGH7.5SiYuan is a personal knowledge management system. Prior to version 3.6.2, the publish service exposes bookmarked blocks ...
CVE-2026-34406HIGH8.8APTRS (Automated Penetration Testing Reporting System) is a Python and Django-based automated reporting tool designed fo...
CVE-2026-34404HIGH7.5Nuxt OG Image generates OG Images with Vue templates in Nuxt. Prior to version 6.2.5, the image‑generation component by ...
CVE-2026-5213HIGH8.8A vulnerability was determined in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, D...
CVE-2026-5212HIGH8.8A vulnerability has been found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, D...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now