Search
133,513 CVEs · High severity
CVEs (133,513, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 76–100 of 133,513 (capped at 500)
| CVE ID ↓ | Severity | Patch | CVSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-9893 | HIGH | Patched | 8.3 | 2026-05-28 | Use after free in Skia in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape v… |
| CVE-2026-9892 | HIGH | Patched | 8.3 | 2026-05-28 | Inappropriate implementation in Skia in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially p… |
| CVE-2026-9890 | HIGH | Patched | 8.3 | 2026-05-28 | Use after free in XR in Google Chrome on Windows prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox… |
| CVE-2026-9889 | HIGH | Patched | 8.3 | 2026-05-28 | Out of bounds read and write in Dawn in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTM… |
| CVE-2026-9888 | HIGH | Patched | 8.3 | 2026-05-28 | Use after free in WebView in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sa… |
| CVE-2026-9887 | HIGH | Patched | 8.8 | 2026-05-28 | Use after free in Proxy in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code via a crafted PAC script. (Chromium security severity: … |
| CVE-2026-9885 | HIGH | Patched | 8.3 | 2026-05-28 | Insufficient validation of untrusted input in UI in Google Chrome on Mac prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to poten… |
| CVE-2026-9884 | HIGH | Patched | 8.8 | 2026-05-28 | Use after free in Browser in Google Chrome on Mac prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security se… |
| CVE-2026-9883 | HIGH | Patched | 8.8 | 2026-05-28 | Use after free in Base in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: Critical) |
| CVE-2026-9880 | HIGH | Patched | 8.3 | 2026-05-28 | Insufficient validation of untrusted input in WebGL in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potential… |
| CVE-2026-9879 | HIGH | Patched | 8.8 | 2026-05-28 | Out of bounds write in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severi… |
| CVE-2026-9878 | HIGH | Patched | 8.8 | 2026-05-28 | Use after free in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium sec… |
| CVE-2026-9877 | HIGH | Patched | 8.3 | 2026-05-28 | Use after free in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape … |
| CVE-2026-9873 | HIGH | Patched | 8.8 | 2026-05-28 | Use after free in Network in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium s… |
| CVE-2026-9863 | HIGH | Patched | 7.5 | 2026-06-15 | Fortra BoKS Manager contains an OS command injection vulnerability in the client upgrade and patch tooling for legacy tar-based client installations. A malicious or comprom… |
| CVE-2026-9860 | HIGH | 8.8 | 2026-06-18 | The Offload, AI & Optimize with Cloudflare Images plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.10.2 via the 'account-… | |
| CVE-2026-9851 | HIGH | 7.2 | 2026-06-06 | The Booking Package plugin for WordPress is vulnerable to Privilege Escalation via Account Takeover in versions up to, and including, 1.7.16. This is due to a missing capab… | |
| CVE-2026-9848 | HIGH | 7.5 | 2026-06-13 | The WP Ticket plugin for WordPress is vulnerable to SQL Injection via the WordPress search query parameter (`s`) in versions up to, and including, 6.0.4 The plugin hooks Wo… | |
| CVE-2026-9843 | HIGH | 8.1 | 2026-06-20 | The Database for Contact Form 7, WPforms, Elementor forms plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the view… | |
| CVE-2026-9842 | HIGH | 7.5 | 2026-07-08 | The Backstage - Customizer Demo Access plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.4.2. This is due to the plugin ass… | |
| CVE-2026-9834 | HIGH | 7.2 | 2026-07-02 | The WP Database Backup – Unlimited Database & Files Backup by Backup for WP plugin for WordPress is vulnerable to OS Command Injection in all versions up to and including 7… | |
| CVE-2026-9833 | HIGH | Patched | 7.1 | 2026-07-20 | The Tag Groups is the Advanced Way to Display Your Taxonomy Terms WordPress plugin before 2.2.0 does not properly escape one of its AJAX parameters before reflecting it in … |
| CVE-2026-9809 | HIGH | 7.6 | 2026-05-29 | A stored Cross-Site Scripting (XSS) vulnerability exists in the Projects component of Mautic 7. When displaying project tags and popovers on administrative detail views (su… | |
| CVE-2026-9808 | HIGH | 7.1 | 2026-05-29 | An authorization bypass vulnerability exists in the Mautic 7 API v2 endpoints (utilizing API Platform). Under certain conditions, roles configured with owner-scope restrict… | |
| CVE-2026-9804 | HIGH | 7.7 | 2026-05-28 | A flaw was found in KubeVirt's virt-exportserver component. An attacker with specific namespace-level access can exploit a path traversal vulnerability in the VMExport dire… |