2026 CVE Vulnerabilities

53,398 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-4741HIGH8.6Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in TeamJCD JoyConDroid (app...
CVE-2026-4737HIGH7.3Use After Free vulnerability in No-Chicken Echo-Mate (‎SDK/rv1106-sdk/sysdrv/source/kernel/mm modules). This vulnerabili...
CVE-2026-4736HIGH7.3Improper Handling of Values vulnerability in No-Chicken Echo-Mate (SDK/rv1106-sdk/sysdrv/source/kernel/include/net/netfi...
CVE-2026-4735HIGH8.7Deserialization of Untrusted Data vulnerability in DTStack chunjun (‎chunjun-core/src/main/java/com/dtstack/chunjun/util...
CVE-2026-4732HIGH8.4Out-of-bounds Read vulnerability in tildearrow furnace (‎extern/libsndfile-modified/src modules). This vulnerability is ...
CVE-2026-4731HIGH8.5Integer Overflow or Wraparound vulnerability in artraweditor ART (‎rtengine‎ modules). This vulnerability is associated ...
CVE-2026-4625HIGH7.3A flaw has been found in SourceCodester Online Admission System 1.0. This affects an unknown function of the file /progr...
CVE-2026-4624HIGH7.3A vulnerability was detected in SourceCodester Online Library Management System 1.0. The impacted element is an unknown ...
CVE-2026-4623HIGH7.3A security vulnerability has been detected in DefaultFuction Jeson-Customer-Relationship-Management-System up to 1b4679c...
CVE-2026-33307HIGH7.5Mod_gnutls is a TLS module for Apache HTTPD based on GnuTLS. In versions prior to 0.12.3 and 0.13.0, code for client cer...
CVE-2026-4680HIGH8.8Use after free in FedCM in Google Chrome prior to 146.0.7680.165 allowed a remote attacker to execute arbitrary code ins...
CVE-2026-4679HIGH8.8Integer overflow in Fonts in Google Chrome prior to 146.0.7680.165 allowed a remote attacker to perform an out of bounds...
CVE-2026-4678HIGH8.8Use after free in WebGPU in Google Chrome prior to 146.0.7680.165 allowed a remote attacker to execute arbitrary code in...
CVE-2026-4677HIGH8.8Inappropriate implementation in WebAudio in Google Chrome prior to 146.0.7680.165 allowed a remote attacker to perform a...
CVE-2026-4676HIGH8.8Use after free in Dawn in Google Chrome prior to 146.0.7680.165 allowed a remote attacker to potentially perform a sandb...
CVE-2026-4675HIGH8.8Heap buffer overflow in WebGL in Google Chrome prior to 146.0.7680.165 allowed a remote attacker to perform an out of bo...
CVE-2026-4674HIGH8.8Out of bounds read in CSS in Google Chrome prior to 146.0.7680.165 allowed a remote attacker to perform out of bounds me...
CVE-2026-4673HIGH8.8Heap buffer overflow in WebAudio in Google Chrome prior to 146.0.7680.165 allowed a remote attacker to perform an out of...
CVE-2026-4617HIGH7.3A weakness has been identified in SourceCodester Patients Waiting Area Queue Management System 1.0. The impacted element...
CVE-2026-33306HIGH7.5bcrypt-ruby is a Ruby binding for the OpenBSD bcrypt() password hashing algorithm. Prior to version 3.1.22, an integer o...
CVE-2026-33298HIGH7.8llama.cpp is an inference of several LLM models in C/C++. Prior to b7824, an integer overflow vulnerability in the `ggml...
CVE-2026-22739HIGH8.6Vulnerability in Spring Cloud when substituting the profile parameter from a request made to the Spring Cloud Config Ser...
CVE-2026-4615HIGH7.3A vulnerability was identified in SourceCodester Online Catering Reservation 1.0. Impacted is an unknown function of the...
CVE-2026-4613HIGH7.3A vulnerability was found in SourceCodester E-Commerce Site 1.0. This vulnerability affects unknown code of the file /pr...
CVE-2026-4021HIGH8.1The Contest Gallery plugin for WordPress is vulnerable to an authentication bypass leading to admin account takeover in ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now