86,884 indexed

CVECVE vulnerabilities

86,884 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.

Showing 101–150 of 86,884 · page 3 of 1738

IDTitleSummary
CVE-2026-9899CVE-2026-9899
CVSS 8.3google
Use after free in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sa…
CVE-2026-9898CVE-2026-9898
CVSS 8.3google
Insufficient validation of untrusted input in GPU in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attacker who had compromised the rendere…
CVE-2026-9897CVE-2026-9897
CVSS 8.8google
Use after free in DOM in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (C…
CVE-2026-9896CVE-2026-9896
CVSS 8.8google
Out of bounds write in V8 in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page…
CVE-2026-9895CVE-2026-9895
CVSS 8.3google
Out of bounds read in GPU in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a …
CVE-2026-9894CVE-2026-9894
CVSS 8.3google
Use after free in GPU in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sand…
CVE-2026-9893CVE-2026-9893
CVSS 8.3google
Use after free in Skia in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a san…
CVE-2026-9892CVE-2026-9892
CVSS 8.3google
Inappropriate implementation in Skia in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to …
CVE-2026-9891CVE-2026-9891
CVSS 9.0google
Use after free in Extensions in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform…
CVE-2026-9890CVE-2026-9890
CVSS 8.3google
Use after free in XR in Google Chrome on Windows prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perf…
CVE-2026-9889CVE-2026-9889
CVSS 8.3google
Out of bounds read and write in Dawn in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attacker to potentially perform a sandbox escape via …
CVE-2026-9888CVE-2026-9888
CVSS 8.3google
Use after free in WebView in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially…
CVE-2026-9887CVE-2026-9887
CVSS 8.8google
Use after free in Proxy in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code via a crafted PAC script. (Chromium securi…
CVE-2026-9886CVE-2026-9886
CVSS 9.6google
Use after free in Base in Google Chrome on Mac prior to 148.0.7778.216 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML pag…
CVE-2026-9885CVE-2026-9885
CVSS 8.3google
Insufficient validation of untrusted input in UI in Google Chrome on Mac prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer pro…
CVE-2026-9884CVE-2026-9884
CVSS 8.8google
Use after free in Browser in Google Chrome on Mac prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromiu…
CVE-2026-9883CVE-2026-9883
CVSS 8.8google
Use after free in Base in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security…
CVE-2026-9882CVE-2026-9882
CVSS 6.5google
Integer overflow in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium secur…
CVE-2026-9881CVE-2026-9881
CVSS 9.0google
Use after free in Bluetooth in Google Chrome on Mac prior to 148.0.7778.216 allowed an attacker who convinced a user to install a malicious extension to potent…
CVE-2026-9880CVE-2026-9880
CVSS 8.3google
Insufficient validation of untrusted input in WebGL in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process…
CVE-2026-9879CVE-2026-9879
CVSS 8.8google
Out of bounds write in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium se…
CVE-2026-9878CVE-2026-9878
CVSS 8.8google
Use after free in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. …
CVE-2026-9877CVE-2026-9877
CVSS 8.3google
Use after free in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sa…
CVE-2026-9876CVE-2026-9876
CVSS 9.6google
Use after free in WebGL in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTM…
CVE-2026-9875CVE-2026-9875
CVSS 9.6google
Out of bounds read in WebGL in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attacker to potentially perform a sandbox escape via a crafted…
CVE-2026-9874CVE-2026-9874
CVSS 9.6google
Use after free in Dawn in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chr…
CVE-2026-9873CVE-2026-9873
CVSS 8.8google
Use after free in Network in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page…
CVE-2026-9872CVE-2026-9872
CVSS 9.6google
Out of bounds write in GPU in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attacker to potentially perform a sandbox escape via a crafted …
CVE-2026-9864CVE-2026-9864
CVSS 4.8
Fortra BoKS Server Agent contains a predictable password generation vulnerability in the adjoin utility. Machine-account passwords generated during Active Dire…
CVE-2026-9863CVE-2026-9863
CVSS 7.5fortra
Fortra BoKS Manager contains an OS command injection vulnerability in the client upgrade and patch tooling for legacy tar-based client installations. A malicio…
CVE-2026-9862CVE-2026-9862
CVSS 9.8fortra
Fortra's  Core Privileged Access Manager (BoKS) contains an OS command injection vulnerability in the boks_autoregisterd service. A remote attacker with networ…
CVE-2026-9860CVE-2026-9860
CVSS 8.8
The Offload, AI & Optimize with Cloudflare Images plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.10.2 via …
CVE-2026-9859CVE-2026-9859
CVSS 6.5mattermost
Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21, 11.8.x <= 11.8.3 fail to enforce PermissionManageBoardRoles on the channelId field of the batch endp…
CVE-2026-9858CVE-2026-9858
CVSS 4.3
The Partial Shipment for Woocommerce plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 3.4 via the wxp_order_shipme…
CVE-2026-9857CVE-2026-9857
CVSS 4.3
The Invoice123 plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.7.0. This is due to the plugin not properly v…
CVE-2026-9856CVE-2026-9856
CVSS 7.1
A vulnerability in huggingface/transformers versions <=5.8.0.dev0 allows an attacker to perform arbitrary file writes via path traversal. The issue resides in …
CVE-2026-9855CVE-2026-9855
CVSS 6.5
The Custom Field Template plugin for WordPress is vulnerable to generic SQL Injection via the 'post_ID' parameter in all versions up to, and including, 2.7.8 d…
CVE-2026-9854CVE-2026-9854
CVSS 7.8hitachienergy
A vulnerability exists in SYS600 RBAC mechanism where users having access to the engineering tools could elevate their privileges to administrator level on the…
CVE-2026-9853CVE-2026-9853
CVSS 7.8hitachienergy
A vulnerability exists in SYS600 which allows any user authenticated to the operating system of the server hosting the application to read and modify applicati…
CVE-2026-9852CVE-2026-9852
CVSS 7.8hitachienergy
A CSV injection vulnerability exists in SYS600. Injected malicious formulas can add or modify data to the spreadsheet, insert links, exfiltrate data, and in so…
CVE-2026-9851CVE-2026-9851
CVSS 7.2
The Booking Package plugin for WordPress is vulnerable to Privilege Escalation via Account Takeover in versions up to, and including, 1.7.16. This is due to a …
CVE-2026-9848CVE-2026-9848
CVSS 7.5
The WP Ticket plugin for WordPress is vulnerable to SQL Injection via the WordPress search query parameter (`s`) in versions up to, and including, 6.0.4 The pl…
CVE-2026-9844CVE-2026-9844Use of default credentials vulnerability in Roche Diagnostics navify Digital Pathology (RabbitMQ Management interface modules) allows Default Usernames and Pas…
CVE-2026-9843CVE-2026-9843
CVSS 8.1
The Database for Contact Form 7, WPforms, Elementor forms plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validatio…
CVE-2026-9842CVE-2026-9842
CVSS 7.5
The Backstage - Customizer Demo Access plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.4.2. This is due to t…
CVE-2026-9838CVE-2026-9838
CVSS 6.1
The ICS Calendar plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'htmltagtitle' parameter in all versions up to, and including, 12…
CVE-2026-9836CVE-2026-9836
CVSS 3.5ibm
IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 is affected by an information disclosure vulnerability.
CVE-2026-9834CVE-2026-9834
CVSS 7.2
The WP Database Backup – Unlimited Database & Files Backup by Backup for WP plugin for WordPress is vulnerable to OS Command Injection in all versions up to an…
CVE-2026-9833CVE-2026-9833
CVSS 7.1
The Tag Groups is the Advanced Way to Display Your Taxonomy Terms WordPress plugin before 2.2.0 does not properly escape one of its AJAX parameters before refl…
CVE-2026-9832CVE-2026-9832
CVSS 5.3
The Payment Gateway of Stripe for WooCommerce plugin for WordPress is vulnerable to Improper Verification of Cryptographic Signature in all versions up to, and…
Sourced from NVD + CISA KEV + FIRST EPSS. Curated by Adam Lundqvist, Founder at SQUR.