2026 CVE Vulnerabilities

56,980 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-15766MEDIUM6.5Uninitialized Use in Skia in Google Chrome prior to 150.0.7871.125 allowed a remote attacker to obtain potentially sensi...
CVE-2026-15765HIGH7.5Use after free in Ozone in Google Chrome prior to 150.0.7871.125 allowed a remote attacker who convinced a user to engag...
CVE-2026-15764HIGH7.5Use after free in Ozone in Google Chrome on Linux prior to 150.0.7871.125 allowed a remote attacker who convinced a user...
CVE-2026-15749MEDIUM5.3A security flaw has been discovered in mastergo-design mastergo-magic-mcp up to 0.2.0. This issue affects the function e...
CVE-2026-15738HIGH8.5Incorrect behavior order in the Gateway API listener-rule generation in Amazon AWS Load Balancer Controller before 3.4.2...
CVE-2026-15643CRITICAL9.2AWS HealthLake MCP Server (awslabs.healthlake-mcp-server) is a Model Context Protocol server that enables AI assistants ...
CVE-2026-53633CRITICAL9.8Vitest is a testing framework powered by Vite. From 3.0.0 until 3.2.5, 4.1.8, and 5.0.0-beta.4, Vitest Browser Mode expo...
CVE-2026-50659MEDIUM6.5Improper encoding or escaping of output in .NET allows an authorized attacker to perform spoofing over a network.
CVE-2026-50651HIGH7.5Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a netw...
CVE-2026-50650HIGH7.8Improper control of generation of code ('code injection') in .NET Framework allows an unauthorized attacker to elevate p...
CVE-2026-50649HIGH7.8Deserialization of untrusted data in .NET allows an unauthorized attacker to execute code locally.
CVE-2026-50648HIGH7.5Allocation of resources without limits or throttling in .NET Framework allows an unauthorized attacker to deny service o...
CVE-2026-50646HIGH7.8Protection mechanism failure in .NET Framework allows an unauthorized attacker to execute code locally.
CVE-2026-50528HIGH8.2Incorrect authorization in .NET allows an unauthorized attacker to bypass a security feature over a network.
CVE-2026-50527HIGH7.5Stack-based buffer overflow in .NET Framework allows an unauthorized attacker to deny service over a network.
CVE-2026-50526MEDIUM5.5Improper link resolution before file access ('link following') in .NET allows an authorized attacker to perform tamperin...
CVE-2026-50525HIGH7.5Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a netw...
CVE-2026-50524HIGH7.5Improper validation of specified type of input in .NET Framework allows an unauthorized attacker to deny service over a ...
CVE-2026-48784MEDIUM6.1Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.53, 6.4.4...
CVE-2026-48761MEDIUM6.1Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 6.1.0 until 6.4.4...
CVE-2026-48760MEDIUM6.1Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 6.1.0 until 6.4.4...
CVE-2026-48747MEDIUM5.3Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 7.4.13 and 8....
CVE-2026-48736HIGH8.6Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 5.4.0 to 5.4.53, ...
CVE-2026-48489HIGH7.5Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.53, 6.4.4...
CVE-2026-48371MEDIUM5.4Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now