2026 CVE Vulnerabilities
53,233 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-5282 | HIGH | 8.1 | 0.2% | Apr 1, 2026 | Out of bounds read in WebCodecs in Google Chrome prior to 146.0.7680.178 allowed a remote attacker to perform an out of ... |
| CVE-2026-5281 | HIGH | 8.8 | 5.0% | Apr 1, 2026 | Use after free in Dawn in Google Chrome prior to 146.0.7680.178 allowed a remote attacker who had compromised the render... |
| CVE-2026-5280 | HIGH | 8.8 | 0.4% | Apr 1, 2026 | Use after free in WebCodecs in Google Chrome prior to 146.0.7680.178 allowed a remote attacker to execute arbitrary code... |
| CVE-2026-5279 | HIGH | 8.8 | 0.3% | Apr 1, 2026 | Object corruption in V8 in Google Chrome prior to 146.0.7680.178 allowed a remote attacker to execute arbitrary code ins... |
| CVE-2026-5278 | HIGH | 8.8 | 0.4% | Apr 1, 2026 | Use after free in Web MIDI in Google Chrome on Android prior to 146.0.7680.178 allowed a remote attacker to execute arbi... |
| CVE-2026-5277 | HIGH | 7.5 | 0.3% | Apr 1, 2026 | Integer overflow in ANGLE in Google Chrome on Windows prior to 146.0.7680.178 allowed a remote attacker who had compromi... |
| CVE-2026-5275 | HIGH | 8.8 | 0.4% | Apr 1, 2026 | Heap buffer overflow in ANGLE in Google Chrome on Mac prior to 146.0.7680.178 allowed a remote attacker to execute arbit... |
| CVE-2026-5274 | HIGH | 8.8 | 0.3% | Apr 1, 2026 | Integer overflow in Codecs in Google Chrome prior to 146.0.7680.178 allowed a remote attacker to perform arbitrary read/... |
| CVE-2026-5272 | HIGH | 8.8 | 0.4% | Apr 1, 2026 | Heap buffer overflow in GPU in Google Chrome prior to 146.0.7680.178 allowed a remote attacker to execute arbitrary code... |
| CVE-2026-4947 | HIGH | 7.1 | 0.2% | Apr 1, 2026 | Addressed a potential insecure direct object reference (IDOR) vulnerability in the signing invitation acceptance process... |
| CVE-2026-3780 | HIGH | 7.8 | 0.1% | Apr 1, 2026 | The application's installer runs with elevated privileges but resolves system executables and DLLs using untrusted searc... |
| CVE-2026-3779 | HIGH | 7.8 | 0.3% | Apr 1, 2026 | The application's list box calculate array logic keeps stale references to page or form objects after they are deleted o... |
| CVE-2026-3777 | HIGH | 7.8 | 0.1% | Apr 1, 2026 | The application does not properly validate the lifetime and validity of internal view cache pointers after JavaScript ch... |
| CVE-2026-3775 | HIGH | 7.8 | 0.3% | Apr 1, 2026 | The application's update service, when checking for updates, loads certain system libraries from a search path that incl... |
| CVE-2026-3774 | HIGH | 7.5 | 0.1% | Apr 1, 2026 | The application allows PDF JavaScript and document/print actions (such as WillPrint/DidPrint) to update form fields, ann... |
| CVE-2026-35056 | HIGH | 8.6 | 0.7% | Apr 1, 2026 | XenForo before 2.3.9 and before 2.2.18 allows remote code execution (RCE) by authenticated, but malicious, admin users. ... |
| CVE-2026-5238 | HIGH | 7.3 | 0.3% | Apr 1, 2026 | A weakness has been identified in itsourcecode Payroll Management System 1.0. Affected by this issue is some unknown fun... |
| CVE-2026-5237 | HIGH | 7.3 | 0.3% | Mar 31, 2026 | A security flaw has been discovered in itsourcecode Payroll Management System 1.0. Affected by this vulnerability is an ... |
| CVE-2026-5214 | HIGH | 8.8 | 0.7% | Mar 31, 2026 | A vulnerability was found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-32... |
| CVE-2026-34585 | HIGH | 8.2 | 0.3% | Mar 31, 2026 | SiYuan is a personal knowledge management system. Prior to version 3.6.2, a vulnerability allows crafted block attribute... |
| CVE-2026-34453 | HIGH | 7.5 | 1.2% | Mar 31, 2026 | SiYuan is a personal knowledge management system. Prior to version 3.6.2, the publish service exposes bookmarked blocks ... |
| CVE-2026-34406 | HIGH | 8.8 | 0.5% | Mar 31, 2026 | APTRS (Automated Penetration Testing Reporting System) is a Python and Django-based automated reporting tool designed fo... |
| CVE-2026-34404 | HIGH | 7.5 | 0.3% | Mar 31, 2026 | Nuxt OG Image generates OG Images with Vue templates in Nuxt. Prior to version 6.2.5, the image‑generation component by ... |
| CVE-2026-5213 | HIGH | 8.8 | 0.7% | Mar 31, 2026 | A vulnerability was determined in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, D... |
| CVE-2026-5212 | HIGH | 8.8 | 0.7% | Mar 31, 2026 | A vulnerability has been found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, D... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now