Search
153,531 CVEs · Medium severity
CVEs (153,531, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 176–200 of 153,531 (capped at 500)
| CVE ID | Severity | Patch | CVSS | Published ↓ | Description |
|---|---|---|---|---|---|
| CVE-2026-11270 | MEDIUM | Patched | 6.5 | 2026-06-05 | Inappropriate implementation in UI in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium… |
| CVE-2026-11268 | MEDIUM | 6.5 | 2026-06-05 | Uninitialized Use in ANGLE in Google Chrome on Windows prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium securit… | |
| CVE-2026-11267 | MEDIUM | Patched | 4.3 | 2026-06-05 | Insufficient policy enforcement in Extensions in Google Chrome prior to 149.0.7827.53 allowed an attacker who convinced a user to install a malicious extension to bypass co… |
| CVE-2026-11266 | MEDIUM | Patched | 4.3 | 2026-06-05 | Inappropriate implementation in SafeBrowsing in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to bypass Safe Browsing via a malicious file. (Chromium secur… |
| CVE-2026-11264 | MEDIUM | Patched | 4.3 | 2026-06-05 | Policy bypass in Content Security Policy in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to bypass content security policy via a crafted HTML page. (Chrom… |
| CVE-2026-11263 | MEDIUM | Patched | 6.5 | 2026-06-05 | Insufficient policy enforcement in WebAuthentication in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process t… |
| CVE-2026-11261 | MEDIUM | Patched | 4.3 | 2026-06-05 | Inappropriate implementation in PDF in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to perform UI spoofing via a … |
| CVE-2026-11260 | MEDIUM | Patched | 4.3 | 2026-06-05 | Inappropriate implementation in Permissions in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to bypass content security policy via a crafted HTML page. (Ch… |
| CVE-2026-11259 | MEDIUM | Patched | 4.3 | 2026-06-05 | Insufficient validation of untrusted input in Cast in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (… |
| CVE-2026-11258 | MEDIUM | Patched | 6.5 | 2026-06-05 | Inappropriate implementation in File System Access in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who convinced a user to engage in specific UI gestures … |
| CVE-2026-11257 | MEDIUM | Patched | 4.3 | 2026-06-05 | Inappropriate implementation in Browser in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromi… |
| CVE-2026-11254 | MEDIUM | Patched | 4.3 | 2026-06-05 | Inappropriate implementation in Permissions in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium secu… |
| CVE-2026-11253 | MEDIUM | Patched | 4.3 | 2026-06-05 | Inappropriate implementation in Permissions in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium s… |
| CVE-2026-11252 | MEDIUM | Patched | 4.3 | 2026-06-05 | Insufficient policy enforcement in Content Settings in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to bypass discretionary access control via a crafted H… |
| CVE-2026-11249 | MEDIUM | Patched | 4.7 | 2026-06-05 | Use after free in Network in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive informa… |
| CVE-2026-11246 | MEDIUM | Patched | 5.3 | 2026-06-05 | Insufficient validation of untrusted input in IndexedDB in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to bypass… |
| CVE-2026-11245 | MEDIUM | Patched | 4.3 | 2026-06-05 | Inappropriate implementation in Payments in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium securit… |
| CVE-2026-11243 | MEDIUM | Patched | 5.4 | 2026-06-05 | Inappropriate implementation in Downloads in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chro… |
| CVE-2026-11238 | MEDIUM | Patched | 5.9 | 2026-06-05 | Inappropriate implementation in DevTools in Google Chrome prior to 149.0.7827.53 allowed an attacker who convinced a user to install a malicious extension to obtain potenti… |
| CVE-2026-10878 | MEDIUM | 6.3 | 2026-06-05 | A vulnerability was detected in D-Link DWR-M920 1.1.50/1.1.70. Affected is the function sub_41C8E8 of the file /boafrm/formSmsManage. Performing a manipulation of the argum… | |
| CVE-2026-10876 | MEDIUM | 6.3 | 2026-06-05 | A weakness has been identified in SourceCodester Ship Ferry Ticket Reservation System 1.0. This affects an unknown function of the file /admin/. This manipulation of the ar… | |
| CVE-2026-47655 | MEDIUM | 6.5 | 2026-06-04 | Exposure of sensitive information to an unauthorized actor in Microsoft Graph allows an authorized attacker to disclose information over a network. | |
| CVE-2026-47644 | MEDIUM | 6.5 | 2026-06-04 | Improper neutralization of special elements in output used by a downstream component ('injection') in Copilot Chat (Microsoft Edge) allows an unauthorized attacker to discl… | |
| CVE-2026-42824 | MEDIUM | 6.5 | 2026-06-04 | Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unauthorized attacker to disclose information over a network. | |
| CVE-2026-11234 | MEDIUM | 4.3 | 2026-06-04 | Inappropriate implementation in FoldableAPIs in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to bypass site isola… |