Search
1,463 CVEs
CVEs (1,463, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 476–500 of 1,463 (capped at 500)
| CVE ID | Severity ↑ | Patch | CVSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-11243 | MEDIUM | Patched | 5.4 | 2026-06-05 | Inappropriate implementation in Downloads in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chro… |
| CVE-2026-11245 | MEDIUM | Patched | 4.3 | 2026-06-05 | Inappropriate implementation in Payments in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium securit… |
| CVE-2026-11246 | MEDIUM | Patched | 5.3 | 2026-06-05 | Insufficient validation of untrusted input in IndexedDB in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to bypass… |
| CVE-2026-10876 | MEDIUM | 6.3 | 2026-06-05 | A weakness has been identified in SourceCodester Ship Ferry Ticket Reservation System 1.0. This affects an unknown function of the file /admin/. This manipulation of the ar… | |
| CVE-2026-10878 | MEDIUM | 6.3 | 2026-06-05 | A vulnerability was detected in D-Link DWR-M920 1.1.50/1.1.70. Affected is the function sub_41C8E8 of the file /boafrm/formSmsManage. Performing a manipulation of the argum… | |
| CVE-2026-11238 | MEDIUM | Patched | 5.9 | 2026-06-05 | Inappropriate implementation in DevTools in Google Chrome prior to 149.0.7827.53 allowed an attacker who convinced a user to install a malicious extension to obtain potenti… |
| CVE-2026-42824 | MEDIUM | 6.5 | 2026-06-04 | Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unauthorized attacker to disclose information over a network. | |
| CVE-2026-47644 | MEDIUM | 6.5 | 2026-06-04 | Improper neutralization of special elements in output used by a downstream component ('injection') in Copilot Chat (Microsoft Edge) allows an unauthorized attacker to discl… | |
| CVE-2026-47655 | MEDIUM | 6.5 | 2026-06-04 | Exposure of sensitive information to an unauthorized actor in Microsoft Graph allows an authorized attacker to disclose information over a network. | |
| CVE-2026-11232 | MEDIUM | 5.4 | 2026-06-04 | Inappropriate implementation in TabGroups in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to perform UI spoofing via malicious network traffic. (Chromium … | |
| CVE-2026-11233 | MEDIUM | 4.7 | 2026-06-04 | Insufficient policy enforcement in FoldableAPIs in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to bypass same or… | |
| CVE-2026-11234 | MEDIUM | 4.3 | 2026-06-04 | Inappropriate implementation in FoldableAPIs in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to bypass site isola… | |
| CVE-2026-11223 | MEDIUM | Patched | 6.5 | 2026-06-04 | Insufficient validation of untrusted input in Network in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to bypass s… |
| CVE-2026-11225 | MEDIUM | Patched | 6.5 | 2026-06-04 | Inappropriate implementation in WebUI in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to perform domain spoofing via a crafted domain name. (Chromium secu… |
| CVE-2026-11226 | MEDIUM | Patched | 6.5 | 2026-06-04 | Insufficient policy enforcement in PreviewTab in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker who convinced a user to engage in specific UI ges… |
| CVE-2026-11227 | MEDIUM | Patched | 6.5 | 2026-06-04 | Incorrect security UI in Tab Hover Cards in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to perform domain spoofing via a crafted domain name. (Chromium s… |
| CVE-2026-11228 | MEDIUM | 4.3 | 2026-06-04 | Inappropriate implementation in File Input in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who convinced a user to engage in specific UI gestures to perfo… | |
| CVE-2026-11229 | MEDIUM | 6.1 | 2026-06-04 | Inappropriate implementation in Enterprise in Google Chrome prior to 149.0.7827.53 allowed a local attacker to perform privilege escalation via physical access to the devic… | |
| CVE-2026-11215 | MEDIUM | Patched | 6.5 | 2026-06-04 | Inappropriate implementation in Cronet in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker to perform domain spoofing via a crafted domain name. (C… |
| CVE-2026-11216 | MEDIUM | Patched | 4.3 | 2026-06-04 | Incorrect security UI in File Input in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI s… |
| CVE-2026-11217 | MEDIUM | Patched | 6.5 | 2026-06-04 | Inappropriate implementation in Fenced Frames in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to bypass site isol… |
| CVE-2026-11218 | MEDIUM | Patched | 6.8 | 2026-06-04 | Inappropriate implementation in PlatformIntegration in Google Chrome on Windows prior to 149.0.7827.53 allowed a remote attacker who convinced a user to engage in specific … |
| CVE-2026-11219 | MEDIUM | Patched | 4.3 | 2026-06-04 | Inappropriate implementation in Navigation in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chr… |
| CVE-2026-11220 | MEDIUM | Patched | 6.5 | 2026-06-04 | Insufficient validation of untrusted input in Navigation in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to bypas… |
| CVE-2026-11221 | MEDIUM | Patched | 4.3 | 2026-06-04 | Insufficient validation of untrusted input in PointerLock in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to perf… |