2026 CVE Vulnerabilities
56,980 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-15766 | MEDIUM | 6.5 | 0.3% | Jul 14, 2026 | Uninitialized Use in Skia in Google Chrome prior to 150.0.7871.125 allowed a remote attacker to obtain potentially sensi... |
| CVE-2026-15765 | HIGH | 7.5 | 0.3% | Jul 14, 2026 | Use after free in Ozone in Google Chrome prior to 150.0.7871.125 allowed a remote attacker who convinced a user to engag... |
| CVE-2026-15764 | HIGH | 7.5 | 0.3% | Jul 14, 2026 | Use after free in Ozone in Google Chrome on Linux prior to 150.0.7871.125 allowed a remote attacker who convinced a user... |
| CVE-2026-15749 | MEDIUM | 5.3 | 0.1% | Jul 14, 2026 | A security flaw has been discovered in mastergo-design mastergo-magic-mcp up to 0.2.0. This issue affects the function e... |
| CVE-2026-15738 | HIGH | 8.5 | 0.4% | Jul 14, 2026 | Incorrect behavior order in the Gateway API listener-rule generation in Amazon AWS Load Balancer Controller before 3.4.2... |
| CVE-2026-15643 | CRITICAL | 9.2 | 0.2% | Jul 14, 2026 | AWS HealthLake MCP Server (awslabs.healthlake-mcp-server) is a Model Context Protocol server that enables AI assistants ... |
| CVE-2026-53633 | CRITICAL | 9.8 | 0.6% | Jul 14, 2026 | Vitest is a testing framework powered by Vite. From 3.0.0 until 3.2.5, 4.1.8, and 5.0.0-beta.4, Vitest Browser Mode expo... |
| CVE-2026-50659 | MEDIUM | 6.5 | 0.4% | Jul 14, 2026 | Improper encoding or escaping of output in .NET allows an authorized attacker to perform spoofing over a network. |
| CVE-2026-50651 | HIGH | 7.5 | 0.6% | Jul 14, 2026 | Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a netw... |
| CVE-2026-50650 | HIGH | 7.8 | 0.3% | Jul 14, 2026 | Improper control of generation of code ('code injection') in .NET Framework allows an unauthorized attacker to elevate p... |
| CVE-2026-50649 | HIGH | 7.8 | 0.9% | Jul 14, 2026 | Deserialization of untrusted data in .NET allows an unauthorized attacker to execute code locally. |
| CVE-2026-50648 | HIGH | 7.5 | 0.6% | Jul 14, 2026 | Allocation of resources without limits or throttling in .NET Framework allows an unauthorized attacker to deny service o... |
| CVE-2026-50646 | HIGH | 7.8 | 1.6% | Jul 14, 2026 | Protection mechanism failure in .NET Framework allows an unauthorized attacker to execute code locally. |
| CVE-2026-50528 | HIGH | 8.2 | 0.4% | Jul 14, 2026 | Incorrect authorization in .NET allows an unauthorized attacker to bypass a security feature over a network. |
| CVE-2026-50527 | HIGH | 7.5 | 0.6% | Jul 14, 2026 | Stack-based buffer overflow in .NET Framework allows an unauthorized attacker to deny service over a network. |
| CVE-2026-50526 | MEDIUM | 5.5 | 0.2% | Jul 14, 2026 | Improper link resolution before file access ('link following') in .NET allows an authorized attacker to perform tamperin... |
| CVE-2026-50525 | HIGH | 7.5 | 0.6% | Jul 14, 2026 | Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a netw... |
| CVE-2026-50524 | HIGH | 7.5 | 0.6% | Jul 14, 2026 | Improper validation of specified type of input in .NET Framework allows an unauthorized attacker to deny service over a ... |
| CVE-2026-48784 | MEDIUM | 6.1 | 0.4% | Jul 14, 2026 | Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.53, 6.4.4... |
| CVE-2026-48761 | MEDIUM | 6.1 | 0.3% | Jul 14, 2026 | Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 6.1.0 until 6.4.4... |
| CVE-2026-48760 | MEDIUM | 6.1 | 0.4% | Jul 14, 2026 | Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 6.1.0 until 6.4.4... |
| CVE-2026-48747 | MEDIUM | 5.3 | 0.2% | Jul 14, 2026 | Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 7.4.13 and 8.... |
| CVE-2026-48736 | HIGH | 8.6 | 0.5% | Jul 14, 2026 | Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 5.4.0 to 5.4.53, ... |
| CVE-2026-48489 | HIGH | 7.5 | 0.5% | Jul 14, 2026 | Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.53, 6.4.4... |
| CVE-2026-48371 | MEDIUM | 5.4 | 0.4% | Jul 14, 2026 | Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now