2026 CVE Vulnerabilities

53,599 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-3657HIGH7.5The My Sticky Bar plugin for WordPress is vulnerable to SQL injection via the `stickymenu_contact_lead_form` AJAX action...
CVE-2026-3973HIGH8.8A vulnerability was determined in Tenda W3 1.0.0.3(2204). This affects the function formSetAutoPing of the file /goform/...
CVE-2026-3972HIGH8.8A vulnerability was found in Tenda W3 1.0.0.3(2204). Affected by this issue is the function formSetCfm of the file /gofo...
CVE-2026-3971HIGH8.8A vulnerability has been found in Tenda i3 1.0.0.6(2204). Affected by this vulnerability is the function formwrlSSIDset ...
CVE-2026-3970HIGH8.8A flaw has been found in Tenda i3 1.0.0.6(2204). Affected is the function formwrlSSIDget of the file /goform/wifiSSIDget...
CVE-2026-3969HIGH7.3A vulnerability was detected in FeMiner wms up to 1.0. This impacts an unknown function of the file /wms-master/src/basi...
CVE-2026-3936HIGH8.8Use after free in WebView in Google Chrome on Android prior to 146.0.7680.71 allowed a remote attacker to potentially ex...
CVE-2026-3932HIGH7.5Insufficient policy enforcement in PDF in Google Chrome on Android prior to 146.0.7680.71 allowed a remote attacker to b...
CVE-2026-3931HIGH8.8Heap buffer overflow in Skia in Google Chrome prior to 146.0.7680.71 allowed a remote attacker to perform out of bounds ...
CVE-2026-3926HIGH8.8Out of bounds read in V8 in Google Chrome prior to 146.0.7680.71 allowed a remote attacker to perform out of bounds memo...
CVE-2026-3924HIGH7.5use after free in WindowDialog in Google Chrome prior to 146.0.7680.71 allowed a remote attacker who had compromised the...
CVE-2026-3923HIGH8.8Use after free in WebMIDI in Google Chrome prior to 146.0.7680.71 allowed a remote attacker to potentially exploit heap ...
CVE-2026-3922HIGH8.8Use after free in MediaStream in Google Chrome prior to 146.0.7680.71 allowed a remote attacker to potentially exploit h...
CVE-2026-3921HIGH8.8Use after free in TextEncoding in Google Chrome prior to 146.0.7680.71 allowed a remote attacker to potentially exploit ...
CVE-2026-3920HIGH8.8Out of bounds memory access in WebML in Google Chrome prior to 146.0.7680.71 allowed a remote attacker to potentially ex...
CVE-2026-3919HIGH8.8Use after free in Extensions in Google Chrome prior to 146.0.7680.71 allowed an attacker who convinced a user to install...
CVE-2026-3918HIGH8.8Use after free in WebMCP in Google Chrome prior to 146.0.7680.71 allowed a remote attacker to potentially exploit heap c...
CVE-2026-3917HIGH8.8Use after free in Agents in Google Chrome prior to 146.0.7680.71 allowed a remote attacker to potentially exploit heap c...
CVE-2026-3915HIGH8.8Heap buffer overflow in WebML in Google Chrome prior to 146.0.7680.71 allowed a remote attacker to perform an out of bou...
CVE-2026-3914HIGH8.8Integer overflow in WebML in Google Chrome prior to 146.0.7680.71 allowed a remote attacker to potentially exploit heap ...
CVE-2026-3913HIGH8.8Heap buffer overflow in WebML in Google Chrome prior to 146.0.7680.71 allowed a remote attacker to potentially exploit h...
CVE-2026-32132HIGH7.4ZITADEL is an open source identity management platform. Prior to 3.4.8 and 4.12.2, a potential vulnerability exists in Z...
CVE-2026-32131HIGH7.7ZITADEL is an open source identity management platform. Prior to 3.4.8 and 4.12.2, a vulnerability in Zitadel's Manageme...
CVE-2026-32130HIGH7.5ZITADEL is an open source identity management platform. From 2.68.0 to before 3.4.8 and 4.12.2, Zitadel provides a Syste...
CVE-2026-32127HIGH8.8OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0....

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now