Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

140,640 CVEs · High severity

CVEs (140,640, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 76–100 of 140,640 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2026-9893 HIGH Patched 8.3 2026-05-28 Use after free in Skia in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape v…
CVE-2026-9892 HIGH Patched 8.3 2026-05-28 Inappropriate implementation in Skia in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially p…
CVE-2026-9890 HIGH Patched 8.3 2026-05-28 Use after free in XR in Google Chrome on Windows prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox…
CVE-2026-9889 HIGH Patched 8.3 2026-05-28 Out of bounds read and write in Dawn in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTM…
CVE-2026-9888 HIGH Patched 8.3 2026-05-28 Use after free in WebView in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sa…
CVE-2026-9887 HIGH Patched 8.8 2026-05-28 Use after free in Proxy in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code via a crafted PAC script. (Chromium security severity: …
CVE-2026-9885 HIGH Patched 8.3 2026-05-28 Insufficient validation of untrusted input in UI in Google Chrome on Mac prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to poten…
CVE-2026-9884 HIGH Patched 8.8 2026-05-28 Use after free in Browser in Google Chrome on Mac prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security se…
CVE-2026-9883 HIGH Patched 8.8 2026-05-28 Use after free in Base in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: Critical)
CVE-2026-9880 HIGH Patched 8.3 2026-05-28 Insufficient validation of untrusted input in WebGL in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potential…
CVE-2026-9879 HIGH Patched 8.8 2026-05-28 Out of bounds write in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severi…
CVE-2026-9878 HIGH Patched 8.8 2026-05-28 Use after free in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium sec…
CVE-2026-9877 HIGH Patched 8.3 2026-05-28 Use after free in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape …
CVE-2026-9873 HIGH Patched 8.8 2026-05-28 Use after free in Network in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium s…
CVE-2026-9863 HIGH Patched 7.5 2026-06-15 Fortra BoKS Manager contains an OS command injection vulnerability in the client upgrade and patch tooling for legacy tar-based client installations. A malicious or comprom…
CVE-2026-9860 HIGH 8.8 2026-06-18 The Offload, AI & Optimize with Cloudflare Images plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.10.2 via the 'account-…
CVE-2026-9856 HIGH 7.1 2026-08-02 A vulnerability in huggingface/transformers versions <=5.8.0.dev0 allows an attacker to perform arbitrary file writes via path traversal. The issue resides in the `save_pre&hellip;
CVE-2026-9851 HIGH 7.2 2026-06-06 The Booking Package plugin for WordPress is vulnerable to Privilege Escalation via Account Takeover in versions up to, and including, 1.7.16. This is due to a missing capab&hellip;
CVE-2026-9848 HIGH 7.5 2026-06-13 The WP Ticket plugin for WordPress is vulnerable to SQL Injection via the WordPress search query parameter (`s`) in versions up to, and including, 6.0.4 The plugin hooks Wo&hellip;
CVE-2026-9843 HIGH 8.1 2026-06-20 The Database for Contact Form 7, WPforms, Elementor forms plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the view&hellip;
CVE-2026-9842 HIGH 7.5 2026-07-08 The Backstage - Customizer Demo Access plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.4.2. This is due to the plugin ass&hellip;
CVE-2026-9834 HIGH 7.2 2026-07-02 The WP Database Backup – Unlimited Database & Files Backup by Backup for WP plugin for WordPress is vulnerable to OS Command Injection in all versions up to and including 7&hellip;
CVE-2026-9833 HIGH Patched 7.1 2026-07-20 The Tag Groups is the Advanced Way to Display Your Taxonomy Terms WordPress plugin before 2.2.0 does not properly escape one of its AJAX parameters before reflecting it in &hellip;
CVE-2026-9830 HIGH Patched 8.2 2026-07-27 The bookingpress-appointment-booking-pro WordPress plugin before 5.7.3 does not correctly invoke its REST permission callback, leaving every route in one of its API namespa&hellip;
CVE-2026-9816 HIGH Patched 8.3 2026-08-17 Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21, 11.8.x <= 11.8.3 fail to validate BoardMember.Scheme* fields server-side on insert and archive-import paths which&hellip;