2026 CVE Vulnerabilities
43,286 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-13852 | CRITICAL | 9.1 | 0.1% | Jun 30, 2026 | Insufficient validation of untrusted input in WebAppInstalls in Google Chrome on Android prior to 150.0.7871.47 allowed ... |
| CVE-2026-13851 | CRITICAL | 9.1 | 0.3% | Jun 30, 2026 | Insufficient validation of untrusted input in WebAppInstalls in Google Chrome on Android prior to 150.0.7871.47 allowed ... |
| CVE-2026-13846 | CRITICAL | 9.6 | 0.3% | Jun 30, 2026 | Use after free in USB in Google Chrome on Mac prior to 150.0.7871.47 allowed a remote attacker who had compromised the r... |
| CVE-2026-13843 | CRITICAL | 9.6 | 0.3% | Jun 30, 2026 | Insufficient validation of untrusted input in Chrome for iOS in Google Chrome on iOS prior to 150.0.7871.47 allowed a re... |
| CVE-2026-13798 | CRITICAL | 9.6 | 0.2% | Jun 30, 2026 | Heap buffer overflow in Chromecast in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised... |
| CVE-2026-13797 | CRITICAL | 9.6 | 0.2% | Jun 30, 2026 | Insufficient validation of untrusted input in Chromecast in Google Chrome prior to 150.0.7871.47 allowed a remote attack... |
| CVE-2026-13796 | CRITICAL | 9.6 | 0.2% | Jun 30, 2026 | Integer overflow in Chromecast in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the... |
| CVE-2026-13792 | CRITICAL | 9.6 | 0.3% | Jun 30, 2026 | Use after free in Touchbar in Google Chrome on Mac prior to 150.0.7871.47 allowed a remote attacker to potentially perfo... |
| CVE-2026-13789 | CRITICAL | 9.6 | 0.3% | Jun 30, 2026 | Use after free in GPU in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer... |
| CVE-2026-13785 | CRITICAL | 9.6 | 0.2% | Jun 30, 2026 | Use after free in Bluetooth in Google Chrome on Mac prior to 150.0.7871.47 allowed a remote attacker who convinced a use... |
| CVE-2026-13782 | CRITICAL | 10 | 0.2% | Jun 30, 2026 | Use after free in Browser in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the rend... |
| CVE-2026-13781 | CRITICAL | 9.6 | 0.2% | Jun 30, 2026 | Insufficient validation of untrusted input in Skia in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who... |
| CVE-2026-13780 | CRITICAL | 9.6 | 0.2% | Jun 30, 2026 | Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 150.0.7871.47 allowed a remote attacker wh... |
| CVE-2026-13776 | CRITICAL | 9.8 | 0.2% | Jun 30, 2026 | Type Confusion in Dawn in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the rendere... |
| CVE-2026-13775 | CRITICAL | 9.8 | 0.2% | Jun 30, 2026 | Use after free in GPU in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer... |
| CVE-2026-58449 | CRITICAL | 9.8 | 0.7% | Jun 30, 2026 | txtai through 9.10.0, fixed in commit 11b32da, exposes an API /reindex endpoint whose function body parameter is resolve... |
| CVE-2026-50003 | CRITICAL | 9.8 | 0.4% | Jun 30, 2026 | A malicious or compromised server can make a DCMTK client using bit-preserving C-GET storage mode write files outside th... |
| CVE-2026-37106 | CRITICAL | 9.8 | 0.5% | Jun 30, 2026 | An issue in DokuWiki 2025-05-14b "Librarian" 56.2 allows a remote attacker to create an account via the register functio... |
| CVE-2026-11541 | CRITICAL | 9.8 | 0.3% | Jun 30, 2026 | IBM CICS Transaction Gateway for Multiplatforms 9.1, 9.2, 9.3, and 10.1 IBM WebSphere Application Server 9.0, and 8.5 an... |
| CVE-2026-7874 | CRITICAL | 9.1 | 0.2% | Jun 30, 2026 | IBM Langflow OSS 1.0.0 through 1.10.0 Langflow could allow disclosure of all stored credentials due to the use of a weak... |
| CVE-2026-7873 | CRITICAL | 9.9 | 0.3% | Jun 30, 2026 | IBM Langflow OSS 1.0.0 through 1.10.0 allows authenticated attackers to execute arbitrary OS commands and read sensitive... |
| CVE-2026-7871 | CRITICAL | 9.8 | 0.4% | Jun 30, 2026 | IBM Langflow OSS 1.0.0 through 1.10.0 allows users with Redis access to execute arbitrary code with full application pri... |
| CVE-2026-7803 | CRITICAL | 9.8 | 0.4% | Jun 30, 2026 | IBM Langflow OSS 1.0.0 through 1.10.0 could allow arbitrary code execution due to improper validation of flow nodes with... |
| CVE-2026-7663 | CRITICAL | 9.8 | 0.2% | Jun 30, 2026 | IBM Langflow OSS 1.0.0 through 1.9.6 could allow unauthenticated attackers to access protected MCP project resources and... |
| CVE-2026-13773 | CRITICAL | 10 | 3.0% | Jun 30, 2026 | IBM WebSphere Extreme Scale 8.6.1.0 through 8.6.1.6 Approximately 50 generated CORBA stub classes in WebSphere eXtreme S... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now