Search
153,552 CVEs · Medium severity
CVEs (153,552, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 326–350 of 153,552 (capped at 500)
| CVE ID ↓ | Severity | Patch | CVSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-8563 | MEDIUM | Patched | 4.3 | 2026-05-14 | Insufficient policy enforcement in IFrame Sandbox in Google Chrome on Windows prior to 148.0.7778.168 allowed a remote attacker to bypass navigation restrictions via a craf… |
| CVE-2026-8562 | MEDIUM | Patched | 4.3 | 2026-05-14 | Side-channel information leakage in Navigation in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromi… |
| CVE-2026-8561 | MEDIUM | Patched | 5.4 | 2026-05-14 | Incorrect security UI in Fullscreen in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security se… |
| CVE-2026-8560 | MEDIUM | Patched | 4.3 | 2026-05-14 | Heap buffer overflow in SwiftShader in Google Chrome on Mac and iOS prior to 148.0.7778.168 allowed a remote attacker to perform an out of bounds memory read via a crafted … |
| CVE-2026-8559 | MEDIUM | Patched | 4.3 | 2026-05-14 | Integer overflow in Internationalization in Google Chrome on Windows prior to 148.0.7778.168 allowed a remote attacker to perform an out of bounds memory write via a crafte… |
| CVE-2026-8552 | MEDIUM | Patched | 4.3 | 2026-05-14 | Heap buffer overflow in GPU in Google Chrome on Android prior to 148.0.7778.168 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. … |
| CVE-2026-8550 | MEDIUM | Patched | 6.5 | 2026-05-14 | Use after free in Google Lens in Google Chrome prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive in… |
| CVE-2026-8546 | MEDIUM | Patched | 5.3 | 2026-05-14 | Out of bounds read in GPU in Google Chrome on Mac and Windows prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to obtain potential… |
| CVE-2026-8543 | MEDIUM | Patched | 5.3 | 2026-05-14 | Out of bounds read in FileSystem in Google Chrome on Mac prior to 148.0.7778.168 allowed a remote attacker who convinced a user to engage in specific UI gestures to obtain … |
| CVE-2026-8541 | MEDIUM | Patched | 5.3 | 2026-05-14 | Out of bounds read in UI in Google Chrome prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive informa… |
| CVE-2026-8539 | MEDIUM | Patched | 5.4 | 2026-05-14 | Script injection in SanitizerAPI in Google Chrome on Android prior to 148.0.7778.168 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted HTML… |
| CVE-2026-8538 | MEDIUM | Patched | 5.3 | 2026-05-14 | Insufficient validation of untrusted input in GPU in Google Chrome prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to perform a d… |
| CVE-2026-8537 | MEDIUM | Patched | 4.3 | 2026-05-14 | Insufficient policy enforcement in ViewTransitions in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Ch… |
| CVE-2026-8535 | MEDIUM | Patched | 5.3 | 2026-05-14 | Out of bounds read in Media in Google Chrome on Linux and ChromeOS prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to obtain pote… |
| CVE-2026-8528 | MEDIUM | Patched | 4.3 | 2026-05-14 | Insufficient validation of untrusted input in SiteIsolation in Google Chrome prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to b… |
| CVE-2026-8516 | MEDIUM | Patched | 5.3 | 2026-05-14 | Insufficient validation of untrusted input in DataTransfer in Google Chrome prior to 148.0.7778.168 allowed a remote attacker who convinced a user to engage in specific UI … |
| CVE-2026-8503 | MEDIUM | Patched | 6.5 | 2026-05-15 | Apache::Session::Generate::SHA256 versions before 1.3.19 for Perl create insecure session ids. Apache::Session::Generate::SHA256 generated session ids insecurely. The defa… |
| CVE-2026-8502 | MEDIUM | 5.3 | 2026-06-06 | The LearnPress – WordPress LMS Plugin for Create and Sell Online Courses plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and inc… | |
| CVE-2026-8496 | MEDIUM | 6.1 | 2026-05-13 | A cross-site scripting (XSS) vulnerability exists in Alinto SOGo, version 5.12.7. A maliciously crafted ICS calendar invitation files allows arbitrary JavaScript execution… | |
| CVE-2026-8493 | MEDIUM | Patched | 5.4 | 2026-05-19 | Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Colorbox Inline allows Cross-Site Scripting (XSS). This issue … |
| CVE-2026-8488 | MEDIUM | Patched | 4.3 | 2026-05-20 | Allocation of resources without limits or throttling vulnerability in Progress Software MOVEit Automation allows Excessive Allocation. This issue affects MOVEit Automation… |
| CVE-2026-8487 | MEDIUM | Patched | 6.5 | 2026-05-20 | Incorrect default permissions vulnerability in Progress Software MOVEit Automation allows Retrieve Embedded Sensitive Data. This issue affects MOVEit Automation: before 20… |
| CVE-2026-8486 | MEDIUM | Patched | 5.3 | 2026-05-20 | Allocation of resources without limits or throttling vulnerability in Progress Software MOVEit Automation allows Flooding. This issue affects MOVEit Automation: before 202… |
| CVE-2026-8485 | MEDIUM | Patched | 5.9 | 2026-05-20 | Uncontrolled Memory Allocation vulnerability in Progress Software MOVEit Automation allows Excessive Allocation. This issue affects MOVEit Automation: before 2025.0.11, fr… |
| CVE-2026-8474 | MEDIUM | 5.3 | 2026-06-01 | A vulnerability was discovered on Stormshield Network Security * 4.3.0 to 4.3.41, * 4.8.0 to 4.8.15, * 5.0.0 to 5.0.5 It is possible to execute a r… |