Total CVEs

125,728

Critical Severity

2,261

High Severity

7,831

Last 7 Days

1,199
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 261 - 280 of 22,133 CVEs
CVE-2026-7339 HIGH - 8.8

Heap buffer overflow in WebRTC in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)

Published: Apr 28, 2026
Source: NVD
CVE-2026-7338 HIGH - 7.5

Use after free in Cast in Google Chrome prior to 147.0.7727.138 allowed an attacker on the local network segment to potentially exploit heap corruption via malicious network traffic. (Chromium security severity: High)

Published: Apr 28, 2026
Source: NVD
CVE-2026-7337 HIGH - 8.8

Type Confusion in V8 in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

Published: Apr 28, 2026
Source: NVD
CVE-2026-7336 HIGH - 8.8

Use after free in WebRTC in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

Published: Apr 28, 2026
Source: NVD
CVE-2026-7335 HIGH - 8.8

Use after free in media in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

Published: Apr 28, 2026
Source: NVD
CVE-2026-7334 HIGH - 8.8

Use after free in Views in Google Chrome on Mac prior to 147.0.7727.138 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

Published: Apr 28, 2026
Source: NVD
CVE-2026-7333 CRITICAL - 9.6

Use after free in GPU in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

Published: Apr 28, 2026
Source: NVD

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Published: Apr 28, 2026
Source: NVD
CVE-2026-42167 HIGH - 8.1

mod_sql in ProFTPD before 1.3.10rc1 allows remote attackers to execute arbitrary code via a username, in scenarios where there is logging of USER requests with an expansion such as %U, and the SQL backend allows commands (e.g., COPY TO PROGRAM).

Vendor: ProFTPD
Product: ProFTPD
Published: Apr 28, 2026
Source: NVD
CVE-2026-40296 MEDIUM - 5.4

PhpSpreadsheet has XSS via number format code with @ text placeholder bypasses htmlspecialchars in HTML writer

Vendor: composer
Product: phpoffice/phpspreadsheet
Published: Apr 28, 2026
Source: GitHub
CVE-2026-35579 HIGH - 7.5

CoreDNS has TSIG authentication bypass on gRPC and QUIC transports

Vendor: go
Product: github.com/coredns/coredns
Published: Apr 28, 2026
Source: GitHub

PhpSpreadsheet has XSS via NumberFormat @ Text Substitution in HTML Writer

Vendor: composer
Product: phpoffice/phpspreadsheet
Published: Apr 28, 2026
Source: GitHub
CVE-2026-33190 HIGH - 7.5

CoreDNS has TSIG authentication bypass on DoT, DoH, DoH3, DoQ, and gRPC

Vendor: go
Product: github.com/coredns/coredns
Published: Apr 28, 2026
Source: GitHub
CVE-2026-33489 HIGH - 7.5

CoreDNS' transfer stanza selection uses lexicographic compare (subzone ACL bypass)

Vendor: go
Product: github.com/coredns/coredns
Published: Apr 28, 2026
Source: GitHub
CVE-2026-32936 HIGH - 7.5

CoreDNS DoH GET oversized dns= query parameter causes pre-validation CPU and memory amplification

Vendor: go
Product: github.com/coredns/coredns
Published: Apr 28, 2026
Source: GitHub
CVE-2026-32934 HIGH - 7.5

CoreDNS' DoQ worker pool does not bound stream backlog

Vendor: go
Product: github.com/coredns/coredns
Published: Apr 28, 2026
Source: GitHub
CVE-2026-32699 MEDIUM - 4.3

FacturaScripts has Insecure Parameter Handling: Unauthorized Modification of Immutable 'nick' Field

Vendor: composer
Product: facturascripts/facturascripts
Published: Apr 28, 2026
Source: GitHub
CVE-2026-30246 MEDIUM - 6.5

Fiber's cache middleware default key generator ignores query string, causing response mix-up across distinct query parameters

Vendor: go
Product: github.com/gofiber/fiber/v3
Published: Apr 28, 2026
Source: GitHub
CVE-2026-7319 HIGH - 7.3

A flaw has been found in elinsky execution-system-mcp 0.1.0. The impacted element is the function _get_context_file_path of the file src/execution_system_mcp/server.py of the component add_action Tool. This manipulation of the argument context causes path traversal. The attack can be initiated remot...

Published: Apr 28, 2026
Source: NVD
CVE-2026-7318 MEDIUM - 5.9

A vulnerability was detected in elie mcp-project 0.1.0. The affected element is the function search_papers of the file research_server.py. The manipulation of the argument topic results in path traversal. Attacking locally is a requirement. The exploit is now public and may be used. The project was ...

Published: Apr 28, 2026
Source: NVD