Search

Found 48,692 results in 1973ms · Match type: Filtered list

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2026-9896 high 8.8 8.8 FIX debian debianmacos macos linux-kernel google 7d ago Out of bounds write in V8 in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
CVE-2026-9895 high 8.3 8.3 FIX debian debian google 7d ago Out of bounds read in GPU in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. …
CVE-2026-9894 high 8.3 8.3 FIX debian debian google 7d ago Use after free in GPU in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chr…
CVE-2026-9893 high 8.3 8.3 FIX debian debian google 7d ago Use after free in Skia in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Ch…
CVE-2026-9892 high 8.3 8.3 FIX debian debian google 7d ago Inappropriate implementation in Skia in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via…
CVE-2026-9890 high 8.3 8.3 FIX debian debian google 7d ago Use after free in XR in Google Chrome on Windows prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML …
CVE-2026-9889 high 8.3 8.3 FIX debian debian google 7d ago Out of bounds read and write in Dawn in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security …
CVE-2026-9888 high 8.3 8.3 FIX debian debian google 7d ago Use after free in WebView in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted …
CVE-2026-9887 high 8.8 8.8 FIX debian debianmacos macos linux-kernel google 7d ago Use after free in Proxy in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code via a crafted PAC script. (Chromium security severity: Critical)
CVE-2026-9885 high 8.3 8.3 FIX debian debianmacos macos google 7d ago Insufficient validation of untrusted input in UI in Google Chrome on Mac prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox es…
CVE-2026-9884 high 8.8 8.8 FIX debian debianmacos macos google 7d ago Use after free in Browser in Google Chrome on Mac prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: Critical)
CVE-2026-9883 high 8.8 8.8 FIX debian debianmacos macos linux-kernel google 7d ago Use after free in Base in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: Critical)
CVE-2026-9880 high 8.3 8.3 FIX debian debianmacos macos linux-kernel google 7d ago Insufficient validation of untrusted input in WebGL in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape…
CVE-2026-9879 high 8.8 8.8 FIX debian debianmacos macos linux-kernel google 7d ago Out of bounds write in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: Critical)
CVE-2026-9878 high 8.8 8.8 FIX debian debianmacos macos linux-kernel google 7d ago Use after free in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Critical)
CVE-2026-9877 high 8.3 8.3 FIX debian debianmacos macos linux-kernel google 7d ago Use after free in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (C…
CVE-2026-9873 high 8.8 8.8 FIX debian debianmacos macos linux-kernel google 7d ago Use after free in Network in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Critical)
CVE-2026-10022 high 8.8 8.8 FIX debian debianmacos macos linux-kernel google 7d ago Type Confusion in V8 in Google Chrome prior to 148.0.7778.216 allowed an attacker who convinced a user to install a malicious extension to execute arbitrary code inside a sandbox via a crafted Chrome…
CVE-2026-10021 high 8.8 8.8 FIX debian debianmacos macos linux-kernel google 7d ago Insufficient validation of untrusted input in USB in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: Me…
CVE-2026-10020 high 8.3 8.3 FIX debian debian google 7d ago Insufficient validation of untrusted input in Skia in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sand…
CVE-2026-10019 high 8.8 8.8 FIX debian debianmacos macos linux-kernel google 7d ago Integer overflow in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-10017 high 8.3 8.3 FIX debian debian google 7d ago Out of bounds read in Headless in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML p…
CVE-2026-10016 high 8.8 8.8 FIX debian debianmacos macos linux-kernel google 7d ago Use after free in DOM in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
CVE-2026-10015 high 8.8 8.8 FIX debian debianmacos macos linux-kernel google 7d ago Integer overflow in WTF in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
CVE-2026-10014 high 8.3 8.3 FIX debian debian google 7d ago Use after free in WebMIDI in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted …
CVE-2026-10013 high 8.8 8.8 FIX debian debianmacos macos linux-kernel google 7d ago Use after free in WebCodecs in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
CVE-2026-10012 high 8.3 8.3 FIX debian debianmacos macos linux-kernel google 7d ago Use after free in Skia in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Ch…
CVE-2026-10009 high 7.5 7.5 FIX debian debianmacos macos linux-kernel google 7d ago Integer overflow in Skia in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to execute arbitrary code inside a sandbox via a crafted HTML page…
CVE-2026-10007 high 8.8 8.8 FIX debian debianmacos macos linux-kernel google 7d ago Use after free in SVG in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
CVE-2026-10006 high 7.5 7.5 FIX debian debianmacos macos linux-kernel google 7d ago Race in WebAudio in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
CVE-2026-10005 high 7.5 7.5 FIX debian debianmacos macos google 7d ago Use after free in WebAppInstalls in Google Chrome on Mac prior to 148.0.7778.216 allowed a remote attacker who convinced a user to engage in specific UI gestures to execute arbitrary code via a craft…
CVE-2026-10003 high 7.5 7.5 FIX debian debianmacos macos linux-kernel google 7d ago Use after free in Views in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who convinced a user to engage in specific UI gestures to execute arbitrary code via a crafted HTML page. (C…
CVE-2026-10002 high 8.8 8.8 FIX debian debianmacos macos linux-kernel google 7d ago Use after free in PDFium in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file. (Chromium security severity: High)
CVE-2026-10001 high 8.3 8.3 FIX debian debian 7d ago Use after free in PerformanceManager in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted …
CVE-2026-10000 high 8.3 8.3 FIX debian debian google 7d ago Use after free in Passwords in Google Chrome on Windows prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafte…
CVE-2026-47179 high 7.7 7.7 7d ago Arcane is an interface for managing Docker containers, images, networks, and volumes. Prior to 1.19.4, ProjectService.GetProjectFileContent returns the contents of any Docker Compose include directiv…
CVE-2026-42563 unknown FIX debian debian 7d ago Dulwich Vulnerable to Command Injection via Merge Driver Path
CVE-2026-42305 unknown FIX debian debian 7d ago Dulwich has an arbitrary file write via NTFS-hostile tree entries on Windows
CVE-2026-49299 unknown FIX debian debian 7d ago In OpenStack Neutron before 28.0.1, the tagging controller enforces plural policy action names on single-tag write operations while the defined policy rules use singular names. The mismatched names e…
CVE-2026-48116 high 7.5 7.5 mintplexlabs 7d ago AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. Prior to 1.13.0, the filesystem-search-files agent skill passes its LLM-con…
CVE-2026-39929 high 7.5 7.5 7d ago Lakeside SysTrack Agent versions prior to 11.2.1.28, 11.3.0.38, 11.4.0.24, 11.5.0.15 contain an out-of-bounds read vulnerability in the Command ID 30 UDP packet handler that allows remote attackers t…
CVE-2026-10044 high 7.5 7.5 7d ago Usagi-org ai-goofish-monitor contains an unauthenticated arbitrary file read vulnerability in the GET /api/prompts/{filename} endpoint on Windows deployments that allows unauthenticated remote attack…
CVE-2026-45342 unknown 7d ago LinkAce is a self-hosted archive to collect website links. Prior to 2.5.6, LinkAce contains an Insecure Direct Object Reference vulnerability in the authorization policy layer that allows any authent…
CVE-2026-45343 unknown 7d ago LinkAce is a self-hosted archive to collect website links. Prior to 2.5.6, LinkAce contains a stored cross-site scripting vulnerability that allows a low-privilege user to execute arbitrary JavaScrip…
CVE-2026-45344 high 8.1 8.1 7d ago LinkAce is a self-hosted archive to collect website links. Prior to 2.5.6, the setup database configuration flow on uninitialized LinkAce instances accepts attacker-controlled database credential fie…
CVE-2026-47718 unknown 7d ago FUXA provides guest and invalid-token access to protected read APIs in secure mode
CVE-2026-46837 high 8.8 8.8 oracle 7d ago Vulnerability in the Oracle Flow Manufacturing product of Oracle E-Business Suite (component: Security). Supported versions that are affected are 12.2.9-12.2.15. Easily exploitable vulnerability all…
CVE-2026-46835 high 7.5 7.5 oracle 7d ago Vulnerability in the Net Service component of Oracle Database Server. Supported versions that are affected are 23.4.0-23.26.2. Easily exploitable vulnerability allows unauthenticated attacker with n…
CVE-2026-46834 high 7.5 7.5 oracle 7d ago Vulnerability in the Net Service component of Oracle Database Server. Supported versions that are affected are 23.4.0-23.26.2. Easily exploitable vulnerability allows unauthenticated attacker with n…
CVE-2026-46829 high 7.5 7.5 oracle 7d ago Vulnerability in Oracle REST Data Services (component: Mongoapi). Supported versions that are affected are 24.2.0-26.1.0. Easily exploitable vulnerability allows unauthenticated attacker with networ…
CVE-2026-46828 high 8.1 8.1 oracle 7d ago Vulnerability in the Oracle Payroll product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability all…
CVE-2026-46827 high 8.8 8.8 oracle 7d ago Vulnerability in the Oracle Payroll product of Oracle E-Business Suite (component: Self Service Manager). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability al…
CVE-2026-46826 high 8.8 8.8 oracle 7d ago Vulnerability in the Oracle Payroll product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability all…
CVE-2026-46823 high 7.7 7.7 oracle 7d ago Vulnerability in the Oracle Public Sector Financials (International) product of Oracle E-Business Suite (component: Authorization). Supported versions that are affected are 12.2.6-12.2.15. Easily ex…
CVE-2026-46821 high 7.7 7.7 oracle 7d ago Vulnerability in the Oracle Financials Common Modules product of Oracle E-Business Suite (component: Common Components). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable v…
CVE-2026-46820 high 8.5 8.5 oracle 7d ago Vulnerability in the Oracle Financials Common Modules product of Oracle E-Business Suite (component: Common Components). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable v…
CVE-2026-46818 high 7.4 7.4 oracle 7d ago Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability al…
CVE-2026-35277 high 8.1 8.1 oracle 7d ago Vulnerability in Oracle REST Data Services (component: Core). Supported versions that are affected are 24.2.0-26.1.0. Easily exploitable vulnerability allows low privileged attacker with network acc…
CVE-2026-35266 high 7.9 7.9 oracle 7d ago Vulnerability in Oracle REST Data Services (component: Core). Supported versions that are affected are 24.2.0-26.1.0. Difficult to exploit vulnerability allows low privileged attacker with network a…
CVE-2026-9039 unknown 7d ago A configuration weakness in the device’s remote management service allows an authenticated session to be established over a communication channel intended solely for vehicle-charger signaling. The se…
CVE-2026-9038 unknown 7d ago A stack-based buffer overflow vulnerability in the charging controller’s signal-processing logic allows an attacker with physical access to the charging interface to supply message fields that exceed…
CVE-2026-9037 unknown 7d ago A firmware update mechanism in the affected charging controller fails to validate the authenticity of firmware packages delivered through the device's management interface. Because cryptographic sign…
CVE-2026-49128 high 7.5 7.5 FIX debian debian 7d ago Music Player Daemon (MPD) before version 0.24.11 contains a path traversal vulnerability in LocalStorage::MapFSOrThrow and LocalStorage::MapUTF8 within the local storage plugin, where the on-disk pat…
CVE-2026-49127 high 8.6 8.6 FIX debian debian 7d ago Music Player Daemon (MPD) before version 0.24.11 contains a stack buffer overflow vulnerability in the pcm_unpack_24be function in src/pcm/Pack.cxx that allows unauthenticated attackers to corrupt st…
CVE-2026-33590 unknown 7d ago Insecure default settings of Portainer CE grant regular (non-admin) users privileges that allow host filesystem access and host-level code execution. An authenticated non-administrative user with end…
CVE-2026-33462 high 7.3 7.3 elastic 7d ago A path traversal vulnerability was identified in Kibana's dashboard management functionality. An authenticated user with limited permissions could create a dashboard with a specially crafted identifi…
CVE-2026-32847 high 7.5 7.5 hkuds 7d ago DeepCode through commit c991dc2 contains a path traversal vulnerability in the SPA catch-all route in new_ui/backend/main.py that allows unauthenticated attackers to read arbitrary files by supplying…
CVE-2026-47144 unknown 7d ago Shamefile has an arbitrary file read via shamefile.yaml in shame next
CVE-2026-47128 unknown 7d ago nono: Sandbox escape on Linux via D-Bus: `systemd-run --user`
CVE-2026-49093 high 7.7 7.7 elastic 7d ago Server-Side Request Forgery (CWE-918) in Kibana can allow an authenticated user with connector management privileges to bypass the operator-configured connector allowlist, causing the Kibana server t…
CVE-2026-42398 high 7.7 7.7 elastic 7d ago Server-Side Request Forgery (CWE-918) in Kibana allows authenticated users with connector management privileges to bypass the operator-configured connection allowlist. By configuring a Webhook connec…
CVE-2026-4944 high 8.8 8.8 7d ago vllm-project/vllm version 0.14.1 contains a vulnerability where the `trust_remote_code=True` parameter is hardcoded in two model implementation files (`vllm/model_executor/models/nemotron_vl.py` and …
CVE-2026-47333 high 7.8 7.8 FIX debian debian 7d ago Ubuntu Linux 6.8, 6.17 and 7.0 contain AppArmor SAUCE patches which can potentially incorrectly compute the size of an internal buffer, leading to a heap memory out-of-bounds read in notification han…
CVE-2026-47331 high 7.8 7.8 FIX debian debian 7d ago Ubuntu Linux 6.8 contains AppArmor SAUCE patches which fail to acquire a lock when modifying a linked list. An unprivileged local user could trigger the race condition that can lead to a use-after-fr…
CVE-2026-47136 unknown 7d ago RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.2, the RustFS console endpoint GET /rustfs/console/license returns parsed license metadata without requiring authentic…
CVE-2026-46685 unknown 7d ago RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.2, when RUSTFS_CORS_ALLOWED_ORIGINS is unset, the RustFS S3 listener's ConditionalCorsLayer reflects any request Origi…
CVE-2026-45044 unknown 7d ago RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.2, the admin router explicitly whitelists /profile/cpu and /profile/memory from the authentication layer, allowing any…
CVE-2026-45042 unknown 7d ago RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.2, improper authorization in the UploadPartCopy operation allows copying objects across buckets without enforcing dest…
CVE-2026-45041 unknown 7d ago RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.2, crates/appauth/src/token.rs ships a 2048-bit RSA private key as a string constant named TEST_PRIVATE_KEY and uses i…
CVE-2026-45040 unknown 7d ago RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.2, RustFS suffers from sensitive information leakage in log outputs. When the server is run with RUST_LOG=debug sensit…
CVE-2026-44394 high 8.1 8.1 FIX debian debian openstack 7d ago An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone federated token rescoping mechanism does not propagate the original token's expiry to the newly issued token. When a federate…
CVE-2026-43000 high 8.8 8.8 FIX debian debian openstack 7d ago An issue was discovered in OpenStack Keystone before 29.0.2. When combined with an application credential impersonation vulnerability, an attacker with the member role on a project can escalate to ad…
CVE-2026-42999 high 8.8 8.8 FIX debian debian openstack 7d ago An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone RBAC policy enforcer in enforce_call unconditionally merges the raw JSON request body into the policy enforcement dictionary …
CVE-2026-42998 high 8.8 8.8 FIX debian debian openstack 7d ago An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone application credential authentication plugin does not verify that the user supplied in the authentication request matches the…
CVE-2026-30761 high 7.3 7.3 7d ago An arbitrary file upload vulnerability in the pages/admin.uploadmapimg.php component of SourceBans Material Admin v1.1.6 allows attackers to execute arbitrary code via uploading a crafted image file.
CVE-2026-30760 high 7.3 7.3 7d ago An issue in SourceBans Material Admin before v.1.1.6 (3ecd95e) allows attackers to manipulate arbitrary user data in the web app via a crafted XAJAX call.
CVE-2026-46439 unknown 7d ago compliance-trestle Vulnerable to Remote Code Execution via Recursive Server-Side Template Injection (SSTI)
CVE-2026-46405 unknown 7d ago OpenBao's Kerberos Auth Method Accumulates Unaccessible Tokens
CVE-2026-46380 unknown 7d ago compliance-trestle Vulnerable to SSRF in Remote Fetching Subsystem
CVE-2026-45297 unknown 7d ago OpenReplay is a self-hosted session replay suite. Prior to 1.26.0, there is a cross-tenant IDOR on feature-flag and assist-stats routes via {project_id} case mismatch. ProjectAuthorizer.__call__ (OSS…
CVE-2026-45296 high 7.7 7.7 7d ago OpenReplay is a self-hosted session replay suite. Prior to 1.26.0, OpenReplay's Python API exposes several app_apikey routes that trust a caller-provided projectKey after validating only that the API…
CVE-2026-34126 high 7.5 7.5 tp-link 7d ago TP-Link has identified a vulnerability in Tapo L535E v1.0 and v3.0, Tapo P300 v1.0, and Tapo D100C v1.0, where Bluetooth communication during the initial setup phase is transmitted in cleartext witho…
CVE-2026-46358 unknown 7d ago OpenBao's Inline Auth Incorrectly Redacted Headers
CVE-2026-46345 unknown 7d ago compliance-trestle - jinja has an Arbitrary File Write via Path Traversal
CVE-2026-45808 unknown 7d ago OpenBao's cross-namespace lease revocation via legacy sys/revoke path bypasses ACL
CVE-2026-45774 unknown 7d ago compliance-trestle Profile Import has an Arbitrary File Read via trestle:// URI and Relative Path Traversal
CVE-2026-45287 unknown 7d ago OpenTelemetry-Go is the Go implementation of OpenTelemetry. Prior to version 0.0.17, `go.opentelemetry.io/otel/schema/v1.0` and `go.opentelemetry.io/otel/schema/v1.1` leaks one file descriptor on eac…
CVE-2026-9096 high 7.5 7.5 7d ago Casdoor versions 2.362.0 and earlier do not enforce SAML assertion time bounds. The gosaml2 library reports all time-validation results, including NotOnOrAfter and NotBefore, in the assertionInfo.War…
CVE-2026-9095 high 8.1 8.1 7d ago Casdoor versions 2.362.0 and earlier map SAML assertions to user sessions without replay protection. The ParseSamlResponse() function in object/saml_sp.go calls sp.RetrieveAssertionInfo() and immedia…
CVE-2026-8697 high 8.8 8.8 tp-link 7d ago Due to improper enforcement of authentication rate-limiting on a debug SSH service in Archer C64 v1, the SSH service allows unlimited authentication attempts and uses the same credentials as the web …