Total CVEs

150,998

Critical Severity

5,040

High Severity

17,683

Last 7 Days

2,039
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 2,841 - 2,860 of 47,403 CVEs
CVE-2026-16414 HIGH - 7.8

Insufficient validation of untrusted input in Chromecast in Google Chrome prior to 150.0.7871.182 allowed a local attacker to potentially perform a sandbox escape via malicious network traffic. (Chromium security severity: High)

Vendor: Google
Product: Chrome
Published: Jul 21, 2026
Source: NVD
CVE-2026-16413 HIGH - 8.3

Out of bounds write in ANGLE in Google Chrome prior to 150.0.7871.182 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

Vendor: Google
Product: Chrome
Published: Jul 21, 2026
Source: NVD

Autel Maxi Charger Single firmware through V1.03.51 permits unrestricted access to the NXP i.MX6 recovery mode through exposed hardware recovery pins. An attacker with physical access can boot attacker-controlled code in memory and modify or extract firmware and other sensitive data.

Published: Jul 21, 2026
Source: NVD

Autel Maxi Charger Single firmware through V1.03.51 exposes an accessible UART interface that permits interruption of the boot process and access to the U-Boot bootloader. An attacker with physical access can modify the boot configuration or file system to obtain operating system access.

Published: Jul 21, 2026
Source: NVD

Autel Maxi Charger Single firmware through V1.03.51 contains a heap-based buffer overflow in the set_ap_param command handled by the /localcfg endpoint. An authenticated attacker can supply oversized input, resulting in denial of service and potentially arbitrary code execution.

Published: Jul 21, 2026
Source: NVD

Autel Maxi Charger Single firmware through V1.03.51 is vulnerable to OS command injection when processing OCPP GetDiagnostics requests. A malicious or compromised OCPP server can supply a crafted diagnostics URL that results in arbitrary command execution on the charging station.

Published: Jul 21, 2026
Source: NVD

Autel Maxi Charger Single firmware through V1.03.51 is vulnerable to OS command injection in the /test endpoint exposed on TCP port 9002. An unauthenticated attacker can supply crafted input in the url parameter to execute arbitrary operating system commands.

Published: Jul 21, 2026
Source: NVD

Autel Maxi Charger Single firmware through V1.03.51 allows unauthenticated remote code execution via the service listening on TCP port 9002. A crafted request to the /test endpoint can cause the device to download, extract, and execute attacker-controlled files with root privileges.

Published: Jul 21, 2026
Source: NVD
CVE-2026-65319 HIGH - 7.5

Feedbin (commit 739884a) contains an unauthenticated information disclosure vulnerability that allows unauthenticated attackers to retrieve private article content by sending requests to the entries text API endpoint, which skips the authorization before-action filter entirely. Attackers can iterate...

Vendor: Feedbin
Product: Feedbin
Published: Jul 21, 2026
Source: NVD
CVE-2026-65318 HIGH - 8.6

Verba RAG application version 2.1.3 contains an unauthenticated server-side request forgery vulnerability that allows unauthenticated attackers to cause the backend to issue arbitrary HTTP GET requests by supplying attacker-controlled URLs through the WebSocket import endpoint. Attackers can connect...

Vendor: Weaviate
Product: Verba
Published: Jul 21, 2026
Source: NVD
CVE-2026-65317 HIGH - 8.6

Verba RAG application version 2.1.3 contains a server-side request forgery vulnerability combined with a same-origin middleware bypass that allows unauthenticated remote attackers to make the server issue arbitrary HTTP requests by supplying a crafted Origin header and attacker-controlled host and p...

Vendor: Weaviate
Product: Verba
Published: Jul 21, 2026
Source: NVD
CVE-2026-65316 MEDIUM - 6.5

XXL-Job version 2.4.2 contains an insecure direct object reference vulnerability that allows authenticated users to read execution log content from job groups they are not authorized to access by supplying arbitrary sequential log IDs to the logDetailCat endpoint. Attackers can enumerate log records...

Vendor: xuxueli
Product: xxl-job
Published: Jul 21, 2026
Source: NVD
CVE-2026-65315 HIGH - 7.5

Ollama (HEAD f0078ae) contains an uncontrolled memory allocation vulnerability in the GGUF metadata parser that allows remote attackers to crash the server by supplying a crafted GGUF file with attacker-controlled length and count fields in string lengths, tensor dimension counts, and metadata array...

Vendor: Ollama
Product: Ollama
Published: Jul 21, 2026
Source: NVD
CVE-2026-65314 MEDIUM - 4.3

Electric Postgres Sync versions below 1.6.10 contains an information disclosure vulnerability that allows attackers to infer the values of excluded columns by crafting subset where clause conditions against shape responses. Attackers can observe whether subset where conditions match rows to deduce s...

Vendor: ElectricSQL
Product: Electric Postgres Sync
Published: Jul 21, 2026
Source: NVD
CVE-2026-63141 MEDIUM - 6.3

Missing Authorization (CWE-862) in Kibana allows an authenticated user to access and modify Cloud Connect configuration and service settings without the required feature privileges, via direct requests to insufficiently protected product endpoints.

Vendor: Elastic
Product: Kibana
Published: Jul 21, 2026
Source: NVD
CVE-2026-62574 HIGH - 7.8

Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Install). Supported versions that are affected are Oracle Java SE: 8u491, 11.0.31, 17.0.19, 21.0.11, 25.0.3, 26.0.1; Oracle GraalVM for JDK: 17.0.19 and 21.0.11; Ora...

Published: Jul 21, 2026
Source: NVD
CVE-2026-62567 HIGH - 7.7

Vulnerability in the Oracle HRMS (UK) product of Oracle E-Business Suite (component: UK Payroll). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle HRMS (UK). While the vulnerab...

Vendor: oracle
Product: human_resources_management_system
Published: Jul 21, 2026
Source: NVD
CVE-2026-62565 HIGH - 7.1

Vulnerability in the Oracle HRMS (US) product of Oracle E-Business Suite (component: US Payroll Year End). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle HRMS (US). Successfu...

Vendor: oracle
Product: human_resources_management_system
Published: Jul 21, 2026
Source: NVD
CVE-2026-62563 MEDIUM - 5.4

Vulnerability in the Oracle Work in Process product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.5-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Work in Process...

Published: Jul 21, 2026
Source: NVD
CVE-2026-62562 MEDIUM - 6.5

Vulnerability in the Oracle HRMS (US) product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle HRMS (US). Successfu...

Vendor: oracle
Product: human_resources_management_system
Published: Jul 21, 2026
Source: NVD