Search
9,825 CVEs
EOL hidden · Show all products
CVEs (9,825, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 1–25 of 9,825 (capped at 500)
| CVE ID | Severity ↑ | Patch | CVSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-16804 | NONE | — | 2026-07-23 | Use after free in Input in Google Chrome prior to 150.0.7871.186 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape … | |
| CVE-2026-16805 | NONE | — | 2026-07-23 | Use after free in Blink in Google Chrome prior to 150.0.7871.186 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium sec… | |
| CVE-2026-16806 | NONE | — | 2026-07-23 | Use after free in WebMCP in Google Chrome prior to 150.0.7871.186 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium se… | |
| CVE-2026-16807 | NONE | — | 2026-07-23 | Out of bounds write in Codecs in Google Chrome prior to 150.0.7871.186 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium … | |
| CVE-2026-52439 | NONE | — | 2026-07-23 | An issue in xiandafu beetl 3.20.2 allows a remote attacker to execute arbitrary code via the type.new function and the property reflection mechanism | |
| CVE-2026-6924 | NONE | — | 2026-07-23 | A bug in the entropy initialization for SiWx917 causes the DRBG to use a predictable seed. As such, all random numbers generated in the Matter code use the same stream of n… | |
| CVE-2026-38764 | NONE | — | 2026-07-23 | An issue in Unistal Systems Pvt. Ltd.Protegent 360 v2.0.0.4 allows a local attacker to escalate privileges via the kernel driver pgsecdl.sys | |
| CVE-2026-39155 | NONE | Patched | — | 2026-07-23 | Knot DNS before 3.4.10 and 3.5.x before 3.5.4 contains a vulnerability in mod-onlinesign where the next NSEC owner name can be computed incorrectly. This can create an over… |
| CVE-2026-47723 | NONE | — | 2026-07-23 | nebula-mesh is a self-hosted control plane for Slack Nebula mesh virtual private network. Prior to version 0.3.1, none of the response paths in `internal/web/` or `internal… | |
| CVE-2026-21653 | NONE | — | 2026-07-23 | Victor SSRF vulnerability in Johnson Controls CCure 9000 and victor application server allows Server Side Request Forgery. This issue affects CCure 9000 and victor applica… | |
| CVE-2026-21655 | NONE | Patched | — | 2026-07-23 | Deserialization of untrusted data vulnerability in Johnson Control victor on Windows allows capec-586. This issue affects victor: from 2.9 before 3.0. |
| CVE-2026-34496 | NONE | Patched | — | 2026-07-23 | Cwe-269 vulnerability in Johnson Controls victor Web on Windows allows capec-233. This issue affects victor Web: before 7.1. |
| CVE-2026-15630 | NONE | — | 2026-07-23 | A non-global organization admin in one tenant can bypass tenant boundaries to delete, create, or modify resources in any other tenant by exploiting a mismatch between autho… | |
| CVE-2026-64785 | NONE | Patched | — | 2026-07-23 | SwiftNIO HTTP/2 was missing validation on inbound HEADERS frames that let CR, LF, NUL, SP and other control characters reach an HTTP/1.1 backend through NIOHTTP2's HTTP/2-t… |
| CVE-2026-47669 | NONE | — | 2026-07-23 | DbGate is cross-platform database manager. In versions 7.1.8 and prior, the `unzipDirectory()` function in `packages/api/src/shell/unzipDirectory.js` (line 27) does not val… | |
| CVE-2026-47670 | NONE | — | 2026-07-23 | DbGate is cross-platform database manager. Versions 7.1.8 and prior are vulnerable to authenticated Remote Code Execution (RCE). Any user with valid DbGate credentials can … | |
| CVE-2026-47722 | NONE | — | 2026-07-23 | nebula-mesh is a self-hosted control plane for Slack Nebula mesh virtual private network. Prior to version 0.3.2, `internal/configgen/generator.go:86,108,119` interpolates … | |
| CVE-2026-65763 | NONE | — | 2026-07-23 | Joomla Extension - phoca.cz - Reflected XSS vulnerability in Phoca Maps 1.0.0-6.0.9 - Improper validation of user inputs lead to a reflective XSS vulnerability. | |
| CVE-2026-65762 | NONE | — | 2026-07-23 | Joomla Extension - phoca.cz - Reflected XSS vulnerability in Phoca Guestbook 1.0.0-6.1.0 - Improper validation of user inputs lead to a reflective XSS vulnerability. | |
| CVE-2026-44210 | NONE | — | 2026-07-23 | Kata Containers is an open source project focusing on a standard implementation of lightweight Virtual Machines (VMs) that perform like containers. Versions prior to 3.31.0… | |
| CVE-2026-65759 | NONE | — | 2026-07-23 | Joomla Extension - joomshaper.com - unauthenticated payment/order forgery in Easy Store extension 1.0.0-2.0.1 - Critical order and payment information, including states, ar… | |
| CVE-2026-65760 | NONE | — | 2026-07-23 | Joomla Extension - joomshaper.com - cross-customer order and personal information disclosure in Easy Store extension 1.0.0-2.0.1 - Improper access checks allow logged in us… | |
| CVE-2026-65761 | NONE | — | 2026-07-23 | Joomla Extension - joomshaper.com - Unauthenticated SQL injection in Easy Store extension 1.0.0-2.0.1 - Improper validation of order parameters lead to an unauthenticated S… | |
| CVE-2026-48533 | NONE | — | 2026-07-23 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | |
| CVE-2026-15612 | NONE | — | 2026-07-23 | Logto bypasses OIDC nonce validation when the nonce claim is absent from the id_token, enabling replay of authentication tokens and weakening session-binding. |