Search
9,831 CVEs
CVEs (9,831, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 401–425 of 9,831 (capped at 500)
| CVE ID | Severity | Patch | CVSS | Published ↑ | Description |
|---|---|---|---|---|---|
| CVE-2026-13033 | HIGH | Patched | 8.8 | 2026-06-24 | Out of bounds read and write in Blink>InterestGroups in Google Chrome prior to 149.0.7827.197 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (… |
| CVE-2026-13034 | MEDIUM | Patched | 4.7 | 2026-06-24 | Inappropriate implementation in Passwords in Google Chrome prior to 149.0.7827.197 allowed a remote attacker who had compromised the renderer process to bypass site isolati… |
| CVE-2026-13035 | HIGH | Patched | 8.8 | 2026-06-24 | Use after free in Bluetooth in Google Chrome on Mac prior to 149.0.7827.197 allowed a remote attacker to execute arbitrary code via a malicious peripheral. (Chromium securi… |
| CVE-2026-13036 | HIGH | Patched | 8.8 | 2026-06-24 | Use after free in Blink in Google Chrome prior to 149.0.7827.197 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium sec… |
| CVE-2026-13037 | HIGH | Patched | 7.8 | 2026-06-24 | Use after free in WebView in Google Chrome on Android prior to 149.0.7827.197 allowed a local attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (… |
| CVE-2026-13038 | HIGH | Patched | 8.8 | 2026-06-24 | Use after free in Autofill in Google Chrome on Windows prior to 149.0.7827.197 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium securi… |
| CVE-2026-48793 | HIGH | Patched | 8.8 | 2026-06-24 | Jellyfin is an open source self hosted media server. Prior to 10.11.10, a potential FFmpeg argument injection vulnerability exists in the subtitle conversion code path. Sub… |
| CVE-2026-49220 | MEDIUM | Patched | 5.7 | 2026-06-24 | Jellyfin is an open source self hosted media server. Prior to 10.11.9, a potential XSS attack exists in Jellyfin which can allow a non-privileged user to execute arbitrary … |
| CVE-2026-49246 | NONE | Patched | — | 2026-06-24 | Jellyfin is an open source self hosted media server. Prior to 10.11.10, a specifically crafted MKV file containing forged filename tags can be leveraged to exploit missing … |
| CVE-2026-49247 | HIGH | Patched | 8.8 | 2026-06-24 | Jellyfin is an open source self hosted media server. From 10.9.0 until 10.11.10, the POST /ClientLog/Document endpoint accepts the Authorization header's Client and Version… |
| CVE-2026-49980 | CRITICAL | Patched | 9.8 | 2026-06-24 | Rclone is a command-line program to sync files and directories to and from different cloud storage providers. From 1.46.0 until 1.74.3, rclone rcd --rc-serve accepts unauth… |
| CVE-2026-53943 | CRITICAL | Patched | 9.6 | 2026-06-24 | Ghost is a Node.js content management system. From until 6.37.0, when Ghost is behind a shared caching layer that results in cached content being shared between different … |
| CVE-2026-53944 | MEDIUM | Patched | 5.8 | 2026-06-24 | Ghost is a Node.js content management system. From 6.0.9 until 6.21.1, when making an external request, it is possible to bypass the IP filter that ensures the request isn'… |
| CVE-2026-53945 | MEDIUM | Patched | 4.0 | 2026-06-24 | Ghost is a Node.js content management system. From 6.0.9 until 6.21.1, Ghost’s private-IP check for outbound HTTP requests could be bypassed via DNS rebinding, allowing an … |
| CVE-2026-53946 | MEDIUM | Patched | 5.4 | 2026-06-24 | Ghost is a Node.js content management system. From 6.19.4 until 6.21.1, when re-rendering posts, Ghost would refetch missing image dimensions by issuing an outbound HTTP re… |
| CVE-2026-53947 | MEDIUM | Patched | 5.3 | 2026-06-24 | Ghost is a Node.js content management system. From 5.18.0 until 6.21.1, a discrepancy in responses from the members signin endpoints made it possible for an unauthenticated… |
| CVE-2026-53948 | MEDIUM | Patched | 5.4 | 2026-06-24 | Ghost is a Node.js content management system. From 6.19.4 until 6.21.1, insufficient validation of the client-supplied Content-Type on Ghost's Admin API file upload endpoin… |
| CVE-2026-53949 | MEDIUM | Patched | 5.3 | 2026-06-24 | Ghost is a Node.js content management system. From 5.46.1 until 6.21.2, the validation applied to filters on the public API endpoints could be partially bypassed, making it… |
| CVE-2026-53950 | HIGH | Patched | 7.5 | 2026-06-24 | @tryghost/activitypub is Ghost’s social/federation client app. Prior to 3.1.0, the ActivityPub client in Ghost was vulnerable to JavaScript injection on posts shared by a m… |
| CVE-2026-23879 | HIGH | Patched | 8.0 | 2026-06-24 | py7zr is a Python-based library and utility to support 7zip archive compression, decompression, encryption and decryption. Versions 1.1.2 and below contain an an arbitrary … |
| CVE-2026-27708 | NONE | Patched | — | 2026-06-24 | FOSSBilling is a free, open-source billing and client management system. In versions 0.7.2 and prior, the Servicecustom Client API's __call method accepts an order_id param… |
| CVE-2026-46348 | NONE | Patched | — | 2026-06-24 | Mastodon is a free, open-source social network server based on ActivityPub. Prior to 4.5.10, 4.4.17, and 4.3.23, the list of disallowed IP address ranges was lacking an IP … |
| CVE-2026-46349 | MEDIUM | Patched | 5.3 | 2026-06-24 | Mastodon is a free, open-source social network server based on ActivityPub. Prior to 4.5.10, 4.4.17, and 4.3.23, Mastodon's normalization of incoming activities signed with… |
| CVE-2026-47389 | HIGH | Patched | 8.6 | 2026-06-24 | Mastodon is a free, open-source social network server based on ActivityPub. Prior to 4.5.10, 4.4.17, and 4.3.23, when using Ruby versions older than 3.4, PrivateAddressChec… |
| CVE-2026-48028 | MEDIUM | Patched | 6.5 | 2026-06-24 | Mastodon is a free, open-source social network server based on ActivityPub. Prior to 4.5.10, 4.4.17, and 4.3.23, Mastodon's normalization of incoming activities signed with… |