86,884 indexed
CVECVE vulnerabilities
86,884 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.
Showing 101–150 of 86,884 · page 3 of 1738
| ID | Title | Summary |
|---|---|---|
| CVE-2026-9899 | CVE-2026-9899 CVSS 8.3google | Use after free in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sa… |
| CVE-2026-9898 | CVE-2026-9898 CVSS 8.3google | Insufficient validation of untrusted input in GPU in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attacker who had compromised the rendere… |
| CVE-2026-9897 | CVE-2026-9897 CVSS 8.8google | Use after free in DOM in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (C… |
| CVE-2026-9896 | CVE-2026-9896 CVSS 8.8google | Out of bounds write in V8 in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page… |
| CVE-2026-9895 | CVE-2026-9895 CVSS 8.3google | Out of bounds read in GPU in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a … |
| CVE-2026-9894 | CVE-2026-9894 CVSS 8.3google | Use after free in GPU in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sand… |
| CVE-2026-9893 | CVE-2026-9893 CVSS 8.3google | Use after free in Skia in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a san… |
| CVE-2026-9892 | CVE-2026-9892 CVSS 8.3google | Inappropriate implementation in Skia in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to … |
| CVE-2026-9891 | CVE-2026-9891 CVSS 9.0google | Use after free in Extensions in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform… |
| CVE-2026-9890 | CVE-2026-9890 CVSS 8.3google | Use after free in XR in Google Chrome on Windows prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perf… |
| CVE-2026-9889 | CVE-2026-9889 CVSS 8.3google | Out of bounds read and write in Dawn in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attacker to potentially perform a sandbox escape via … |
| CVE-2026-9888 | CVE-2026-9888 CVSS 8.3google | Use after free in WebView in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially… |
| CVE-2026-9887 | CVE-2026-9887 CVSS 8.8google | Use after free in Proxy in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code via a crafted PAC script. (Chromium securi… |
| CVE-2026-9886 | CVE-2026-9886 CVSS 9.6google | Use after free in Base in Google Chrome on Mac prior to 148.0.7778.216 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML pag… |
| CVE-2026-9885 | CVE-2026-9885 CVSS 8.3google | Insufficient validation of untrusted input in UI in Google Chrome on Mac prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer pro… |
| CVE-2026-9884 | CVE-2026-9884 CVSS 8.8google | Use after free in Browser in Google Chrome on Mac prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromiu… |
| CVE-2026-9883 | CVE-2026-9883 CVSS 8.8google | Use after free in Base in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security… |
| CVE-2026-9882 | CVE-2026-9882 CVSS 6.5google | Integer overflow in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium secur… |
| CVE-2026-9881 | CVE-2026-9881 CVSS 9.0google | Use after free in Bluetooth in Google Chrome on Mac prior to 148.0.7778.216 allowed an attacker who convinced a user to install a malicious extension to potent… |
| CVE-2026-9880 | CVE-2026-9880 CVSS 8.3google | Insufficient validation of untrusted input in WebGL in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process… |
| CVE-2026-9879 | CVE-2026-9879 CVSS 8.8google | Out of bounds write in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium se… |
| CVE-2026-9878 | CVE-2026-9878 CVSS 8.8google | Use after free in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. … |
| CVE-2026-9877 | CVE-2026-9877 CVSS 8.3google | Use after free in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sa… |
| CVE-2026-9876 | CVE-2026-9876 CVSS 9.6google | Use after free in WebGL in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTM… |
| CVE-2026-9875 | CVE-2026-9875 CVSS 9.6google | Out of bounds read in WebGL in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attacker to potentially perform a sandbox escape via a crafted… |
| CVE-2026-9874 | CVE-2026-9874 CVSS 9.6google | Use after free in Dawn in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chr… |
| CVE-2026-9873 | CVE-2026-9873 CVSS 8.8google | Use after free in Network in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page… |
| CVE-2026-9872 | CVE-2026-9872 CVSS 9.6google | Out of bounds write in GPU in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attacker to potentially perform a sandbox escape via a crafted … |
| CVE-2026-9864 | CVE-2026-9864 CVSS 4.8 | Fortra BoKS Server Agent contains a predictable password generation vulnerability in the adjoin utility. Machine-account passwords generated during Active Dire… |
| CVE-2026-9863 | CVE-2026-9863 CVSS 7.5fortra | Fortra BoKS Manager contains an OS command injection vulnerability in the client upgrade and patch tooling for legacy tar-based client installations. A malicio… |
| CVE-2026-9862 | CVE-2026-9862 CVSS 9.8fortra | Fortra's Core Privileged Access Manager (BoKS) contains an OS command injection vulnerability in the boks_autoregisterd service. A remote attacker with networ… |
| CVE-2026-9860 | CVE-2026-9860 CVSS 8.8 | The Offload, AI & Optimize with Cloudflare Images plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.10.2 via … |
| CVE-2026-9859 | CVE-2026-9859 CVSS 6.5mattermost | Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21, 11.8.x <= 11.8.3 fail to enforce PermissionManageBoardRoles on the channelId field of the batch endp… |
| CVE-2026-9858 | CVE-2026-9858 CVSS 4.3 | The Partial Shipment for Woocommerce plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 3.4 via the wxp_order_shipme… |
| CVE-2026-9857 | CVE-2026-9857 CVSS 4.3 | The Invoice123 plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.7.0. This is due to the plugin not properly v… |
| CVE-2026-9856 | CVE-2026-9856 CVSS 7.1 | A vulnerability in huggingface/transformers versions <=5.8.0.dev0 allows an attacker to perform arbitrary file writes via path traversal. The issue resides in … |
| CVE-2026-9855 | CVE-2026-9855 CVSS 6.5 | The Custom Field Template plugin for WordPress is vulnerable to generic SQL Injection via the 'post_ID' parameter in all versions up to, and including, 2.7.8 d… |
| CVE-2026-9854 | CVE-2026-9854 CVSS 7.8hitachienergy | A vulnerability exists in SYS600 RBAC mechanism where users having access to the engineering tools could elevate their privileges to administrator level on the… |
| CVE-2026-9853 | CVE-2026-9853 CVSS 7.8hitachienergy | A vulnerability exists in SYS600 which allows any user authenticated to the operating system of the server hosting the application to read and modify applicati… |
| CVE-2026-9852 | CVE-2026-9852 CVSS 7.8hitachienergy | A CSV injection vulnerability exists in SYS600. Injected malicious formulas can add or modify data to the spreadsheet, insert links, exfiltrate data, and in so… |
| CVE-2026-9851 | CVE-2026-9851 CVSS 7.2 | The Booking Package plugin for WordPress is vulnerable to Privilege Escalation via Account Takeover in versions up to, and including, 1.7.16. This is due to a … |
| CVE-2026-9848 | CVE-2026-9848 CVSS 7.5 | The WP Ticket plugin for WordPress is vulnerable to SQL Injection via the WordPress search query parameter (`s`) in versions up to, and including, 6.0.4 The pl… |
| CVE-2026-9844 | CVE-2026-9844 | Use of default credentials vulnerability in Roche Diagnostics navify Digital Pathology (RabbitMQ Management interface modules) allows Default Usernames and Pas… |
| CVE-2026-9843 | CVE-2026-9843 CVSS 8.1 | The Database for Contact Form 7, WPforms, Elementor forms plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validatio… |
| CVE-2026-9842 | CVE-2026-9842 CVSS 7.5 | The Backstage - Customizer Demo Access plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.4.2. This is due to t… |
| CVE-2026-9838 | CVE-2026-9838 CVSS 6.1 | The ICS Calendar plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'htmltagtitle' parameter in all versions up to, and including, 12… |
| CVE-2026-9836 | CVE-2026-9836 CVSS 3.5ibm | IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 is affected by an information disclosure vulnerability. |
| CVE-2026-9834 | CVE-2026-9834 CVSS 7.2 | The WP Database Backup – Unlimited Database & Files Backup by Backup for WP plugin for WordPress is vulnerable to OS Command Injection in all versions up to an… |
| CVE-2026-9833 | CVE-2026-9833 CVSS 7.1 | The Tag Groups is the Advanced Way to Display Your Taxonomy Terms WordPress plugin before 2.2.0 does not properly escape one of its AJAX parameters before refl… |
| CVE-2026-9832 | CVE-2026-9832 CVSS 5.3 | The Payment Gateway of Stripe for WooCommerce plugin for WordPress is vulnerable to Improper Verification of Cryptographic Signature in all versions up to, and… |