Total CVEs

150,998

Critical Severity

5,040

High Severity

17,683

Last 7 Days

2,039
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 2,821 - 2,840 of 47,403 CVEs
CVE-2026-63145 MEDIUM - 4.3

Incorrect Authorization (CWE-863) in Kibana can lead to integrity compromise of Machine Learning audit and notification records via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). A vulnerability exists in Kibana's Machine Learning functionality where a Machine Learning man...

Vendor: Elastic
Product: Kibana
Published: Jul 21, 2026
Source: NVD
CVE-2026-63144 MEDIUM - 6.5

Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to denial of service via a specially crafted search request submitted by a low-privileged authenticated user. A user with read-level index access can submit a request that triggers unbounded recursive processing within the Elasticsearch quer...

Vendor: Elastic
Product: Elasticsearch
Published: Jul 21, 2026
Source: NVD
CVE-2026-63143 MEDIUM - 4.3

Missing Authorization (CWE-862) in Kibana can lead to unauthorized information disclosure via Privilege Abuse (CAPEC-122). A user with limited feature privileges can access workflow execution outputs in their Kibana space without the authorization required to do so through the documented API. The ac...

Vendor: Elastic
Product: Kibana
Published: Jul 21, 2026
Source: NVD
CVE-2026-63142 MEDIUM - 5.0

Incomplete List of Disallowed Inputs (CWE-184) in Kibana can allow an authenticated attacker with access to the Reporting feature to bypass outbound request restrictions configured by an administrator, causing the reporting service to send requests to network destinations that should be denied by th...

Vendor: Elastic
Product: Kibana
Published: Jul 21, 2026
Source: NVD
CVE-2026-56820 HIGH - 7.4

Netty is a network application framework for development of protocol servers and clients. In versions 4.2.0.Final through 4.2.15.Final and prior to 4.1.135.Final, `OcspClient` does not validate that the `CertificateID` in an OCSP response matches the requested `CertificateID`, which can lead to repl...

Vendor: netty
Product: netty
Published: Jul 21, 2026
Source: NVD
CVE-2026-56819 HIGH - 7.5

Netty is a network application framework for development of protocol servers and clients. In versions 4.2.0.Final through 4.2.15.Final and 4.1.0.Final through 4.1.135.Final, a remote unauthenticated peer can leak one direct `ByteBuf` per HTTP/2 `DATA` frame in applications that enable HTTP/2 content...

Vendor: netty
Product: netty
Published: Jul 21, 2026
Source: NVD

Netty is a network application framework for development of protocol servers and clients. In versions 4.2.0.Final through 4.2.15.Final and 4.1.0.Final through 4.1.135.Final, any caller that can deliver bytes to a Netty channel pipeline containing `XmlDecoder` can send XML with a `DOCTYPE` declaratio...

Vendor: netty
Product: netty
Published: Jul 21, 2026
Source: NVD

A signed integer overflow vulnerability was found in libarchive's ZIP writer. In the archive_write_zip_header function in archive_write_set_format_zip.c, when ZIP encryption is enabled and the entry file size is close to INT64_MAX, the addition of the encryption overhead to the entry size overf...

Vendor: Red Hat
Product: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9, Red Hat Hardened Images, Red Hat OpenShift Container Platform 4
Published: Jul 21, 2026
Source: NVD
CVE-2026-16486 MEDIUM - 4.3

A vulnerability was found in SourceCodester Class and Exam Timetabling System 1.0. This affects an unknown part of the file /BSIS.php. Performing a manipulation of the argument day results in cross site scripting. The attack may be initiated remotely. The exploit has been made public and could be us...

Vendor: SourceCodester
Product: Class and Exam Timetabling System
Published: Jul 21, 2026
Source: NVD
CVE-2026-16485 MEDIUM - 4.3

A vulnerability has been found in SourceCodester Class and Exam Timetabling System 1.0. Affected by this issue is some unknown functionality of the file /class.php. Such manipulation of the argument day leads to cross site scripting. The attack can be launched remotely. The exploit has been disclose...

Vendor: SourceCodester
Product: Class and Exam Timetabling System
Published: Jul 21, 2026
Source: NVD
CVE-2026-16424 CRITICAL - 9.6

Use after free in GPU in Google Chrome on Android prior to 150.0.7871.182 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

Vendor: Google
Product: Chrome
Published: Jul 21, 2026
Source: NVD
CVE-2026-16423 HIGH - 8.8

Use after free in UI in Google Chrome prior to 150.0.7871.182 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

Vendor: Google
Product: Chrome
Published: Jul 21, 2026
Source: NVD
CVE-2026-16422 HIGH - 7.5

Insufficient validation of untrusted input in Certificate in Google Chrome on Linux prior to 150.0.7871.182 allowed an attacker in a privileged network position to perform domain spoofing via malicious network traffic. (Chromium security severity: High)

Vendor: Google
Product: Chrome
Published: Jul 21, 2026
Source: NVD
CVE-2026-16421 HIGH - 8.8

Inappropriate implementation in WebAudio in Google Chrome prior to 150.0.7871.182 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

Vendor: Google
Product: Chrome
Published: Jul 21, 2026
Source: NVD
CVE-2026-16420 HIGH - 8.8

Type Confusion in WebAudio in Google Chrome prior to 150.0.7871.182 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

Vendor: Google
Product: Chrome
Published: Jul 21, 2026
Source: NVD
CVE-2026-16419 CRITICAL - 9.6

Out of bounds read and write in ANGLE in Google Chrome on Android prior to 150.0.7871.182 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

Vendor: Google
Product: Chrome
Published: Jul 21, 2026
Source: NVD
CVE-2026-16418 HIGH - 8.8

Stack buffer overflow in V8 in Google Chrome prior to 150.0.7871.182 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

Vendor: Google
Product: Chrome
Published: Jul 21, 2026
Source: NVD

Uninitialized Use in Skia in Google Chrome prior to 150.0.7871.182 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)

Vendor: Google
Product: Chrome
Published: Jul 21, 2026
Source: NVD
CVE-2026-16416 HIGH - 8.3

Integer overflow in Chromecast in Google Chrome prior to 150.0.7871.182 allowed a local attacker to potentially perform a sandbox escape via malicious network traffic. (Chromium security severity: High)

Vendor: Google
Product: Chrome
Published: Jul 21, 2026
Source: NVD
CVE-2026-16415 MEDIUM - 5.4

Insufficient validation of untrusted input in Extensions in Google Chrome prior to 150.0.7871.182 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. (Chromium security severity: High)

Vendor: Google
Product: Chrome
Published: Jul 21, 2026
Source: NVD