Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

32,470 CVEs · Critical severity

EOL hidden · Show all products

CVEs (32,470, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 1–25 of 32,470 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2026-9967 CRITICAL Patched 9.6 2026-05-28 Out of bounds write in GPU in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium sec…
CVE-2026-9918 CRITICAL Patched 9.6 2026-05-28 Inappropriate implementation in Tint in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Ch…
CVE-2026-9891 CRITICAL Patched 9.0 2026-05-28 Use after free in Extensions in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox es…
CVE-2026-9886 CRITICAL Patched 9.6 2026-05-28 Use after free in Base in Google Chrome on Mac prior to 148.0.7778.216 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium …
CVE-2026-9881 CRITICAL Patched 9.0 2026-05-28 Use after free in Bluetooth in Google Chrome on Mac prior to 148.0.7778.216 allowed an attacker who convinced a user to install a malicious extension to potentially perform…
CVE-2026-9876 CRITICAL Patched 9.6 2026-05-28 Use after free in WebGL in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chro…
CVE-2026-9875 CRITICAL Patched 9.6 2026-05-28 Out of bounds read in WebGL in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (…
CVE-2026-9874 CRITICAL Patched 9.6 2026-05-28 Use after free in Dawn in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium securit…
CVE-2026-9872 CRITICAL Patched 9.6 2026-05-28 Out of bounds write in GPU in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (C…
CVE-2026-9862 CRITICAL Patched 9.8 2026-06-15 Fortra's  Core Privileged Access Manager (BoKS) contains an OS command injection vulnerability in the boks_autoregisterd service. A remote attacker with network access to t…
CVE-2026-9813 CRITICAL Patched 9.9 2026-05-28 FlowIntel up to version 3.3.0 contains a server-side request forgery (SSRF) vulnerability in the external reference URL probe functionality in app/case/task.py. An attacker…
CVE-2026-9810 CRITICAL Patched 9.8 2026-07-17 The AI Copilot WordPress plugin before 1.5.4 does not bind OAuth access tokens to a WordPress user, and accepts any valid token as an administrator session, allowing unaut…
CVE-2026-9733 CRITICAL 9.1 2026-06-23 Mojolicious::Plugin::Web::Auth::OAuth2 versions through 0.17 for Perl have an insecure default state parameter. When no state generator is specified in the constructor, th…
CVE-2026-9726 CRITICAL 9.8 2026-07-10 Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal AlternativeCommerce (Basket) allows Object Injection. This iss…
CVE-2026-9725 CRITICAL 9.1 2026-07-03 The Printcart Web to Print Product Designer for WooCommerce plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up to, and including, 2.5.2 This is du…
CVE-2026-9711 CRITICAL 9.8 2026-06-30 The EventON - WordPress Virtual Event Calendar Plugin plugin for WordPress (full) is vulnerable to SQL Injection via the WordPress 'search' parameter in versions up to, and…
CVE-2026-9701 CRITICAL 9.8 2026-07-08 The Eventer plugin for WordPress is vulnerable to an insecure password reset mechanism in all versions up to, and including, 4.4.2. The plugin stores a plaintext copy of th…
CVE-2026-9698 CRITICAL Patched 9.8 2026-06-09 DBI versions before 1.648 for Perl saved errors in a limited-sized buffer. Error messages that were returned when RaiseError, PrintError or HandleError were set were writt…
CVE-2026-9695 CRITICAL 9.8 2026-07-08 An Improper Authentication vulnerability affecting DELMIA Apriso from Release 2020 through Release 2026 could allow an attacker to gain privileged access to the server.
CVE-2026-9691 CRITICAL 9.8 2026-06-15 Unauthenticated PHP Object Injection in Integration for ActiveCampaign and Contact Form 7, WPForms, Elementor, Ninja Forms <= 1.1.1 versions.
CVE-2026-9648 CRITICAL 9.1 2026-06-11 The crypton-x509-validation Haskell library fails to enforce X.509 NameConstraints, allowing TLS clients to accept certificates whose Subject Alternative Names fall outside&hellip;
CVE-2026-9645 CRITICAL 9.9 2026-05-28 Exposed methods allow authenticated users to create and execute arbitrary JavaScript code on the server. The scripts execute with full access, enabling complete system comp&hellip;
CVE-2026-9559 CRITICAL 9.9 2026-05-29 A path traversal vulnerability exists in the campaign import feature of Mautic 7. When extracting uploaded ZIP files during campaign imports, a flaw in the validation logic&hellip;
CVE-2026-9558 CRITICAL 9.9 2026-05-29 A Server-Side Template Injection (SSTI) vulnerability exists in Mautic's theme engine. The platform renders uploaded Twig templates without a sandbox or strict function res&hellip;
CVE-2026-9543 CRITICAL 9.8 2026-05-26 A vulnerability has been found in Totolink N300RH 6.1c.1353_B20190305. Affected is the function setPasswordCfg of the file /cgi-bin/cstecgi.cgi of the component Web Managem&hellip;