Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

158,556 CVEs · Medium severity

CVEs (158,556, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 476–500 of 158,556 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2026-8565 MEDIUM Patched 4.7 2026-05-14 Inappropriate implementation in Downloads in Google Chrome on Mac prior to 148.0.7778.168 allowed an attacker who convinced a user to install a malicious extension to perfo…
CVE-2026-8564 MEDIUM Patched 4.2 2026-05-14 Incorrect security UI in Downloads in Google Chrome on Android and Mac prior to 148.0.7778.168 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Ch…
CVE-2026-8563 MEDIUM Patched 4.3 2026-05-14 Insufficient policy enforcement in IFrame Sandbox in Google Chrome on Windows prior to 148.0.7778.168 allowed a remote attacker to bypass navigation restrictions via a craf…
CVE-2026-8562 MEDIUM Patched 4.3 2026-05-14 Side-channel information leakage in Navigation in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromi…
CVE-2026-8561 MEDIUM Patched 5.4 2026-05-14 Incorrect security UI in Fullscreen in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security se…
CVE-2026-8560 MEDIUM Patched 4.3 2026-05-14 Heap buffer overflow in SwiftShader in Google Chrome on Mac and iOS prior to 148.0.7778.168 allowed a remote attacker to perform an out of bounds memory read via a crafted …
CVE-2026-8559 MEDIUM Patched 4.3 2026-05-14 Integer overflow in Internationalization in Google Chrome on Windows prior to 148.0.7778.168 allowed a remote attacker to perform an out of bounds memory write via a crafte…
CVE-2026-8552 MEDIUM Patched 4.3 2026-05-14 Heap buffer overflow in GPU in Google Chrome on Android prior to 148.0.7778.168 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. …
CVE-2026-8550 MEDIUM Patched 6.5 2026-05-14 Use after free in Google Lens in Google Chrome prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive in…
CVE-2026-8546 MEDIUM Patched 5.3 2026-05-14 Out of bounds read in GPU in Google Chrome on Mac and Windows prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to obtain potential…
CVE-2026-8543 MEDIUM Patched 5.3 2026-05-14 Out of bounds read in FileSystem in Google Chrome on Mac prior to 148.0.7778.168 allowed a remote attacker who convinced a user to engage in specific UI gestures to obtain …
CVE-2026-8541 MEDIUM Patched 5.3 2026-05-14 Out of bounds read in UI in Google Chrome prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive informa…
CVE-2026-8539 MEDIUM Patched 5.4 2026-05-14 Script injection in SanitizerAPI in Google Chrome on Android prior to 148.0.7778.168 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted HTML…
CVE-2026-8538 MEDIUM Patched 5.3 2026-05-14 Insufficient validation of untrusted input in GPU in Google Chrome prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to perform a d…
CVE-2026-8537 MEDIUM Patched 4.3 2026-05-14 Insufficient policy enforcement in ViewTransitions in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Ch…
CVE-2026-8535 MEDIUM Patched 5.3 2026-05-14 Out of bounds read in Media in Google Chrome on Linux and ChromeOS prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to obtain pote…
CVE-2026-8528 MEDIUM Patched 4.3 2026-05-14 Insufficient validation of untrusted input in SiteIsolation in Google Chrome prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to b…
CVE-2026-8516 MEDIUM Patched 5.3 2026-05-14 Insufficient validation of untrusted input in DataTransfer in Google Chrome prior to 148.0.7778.168 allowed a remote attacker who convinced a user to engage in specific UI …
CVE-2026-8503 MEDIUM Patched 6.5 2026-05-15 Apache::Session::Generate::SHA256 versions before 1.3.19 for Perl create insecure session ids. Apache::Session::Generate::SHA256 generated session ids insecurely. The defa…
CVE-2026-8502 MEDIUM 5.3 2026-06-06 The LearnPress – WordPress LMS Plugin for Create and Sell Online Courses plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and inc…
CVE-2026-8499 MEDIUM 5.3 2026-06-09 The Helpfulcrowd Product Reviews plugin for WordPress is vulnerable to Authorization Bypass via PHP Type Juggling in versions up to, and including, 1.2.9. This is due to th…
CVE-2026-8496 MEDIUM 6.1 2026-05-13 A cross-site scripting (XSS) vulnerability exists in Alinto SOGo, version 5.12.7. A maliciously crafted ICS calendar invitation files allows arbitrary JavaScript execution…
CVE-2026-8493 MEDIUM Patched 5.4 2026-05-19 Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Colorbox Inline allows Cross-Site Scripting (XSS). This issue …
CVE-2026-8489 MEDIUM 6.4 2026-07-03 The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to Stored Cross-Site S…
CVE-2026-8488 MEDIUM Patched 4.3 2026-05-20 Allocation of resources without limits or throttling vulnerability in Progress Software MOVEit Automation allows Excessive Allocation. This issue affects MOVEit Automation…