Total CVEs

138,466

Critical Severity

3,569

High Severity

12,817

Last 7 Days

1,987
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 3,161 - 3,180 of 12,514 CVEs
CVE-2026-9123 HIGH - 7.5

Heap buffer overflow in Chromecast in Google Chrome on Android, Linux, ChromeOS prior to 148.0.7778.179 allowed a local attacker to execute arbitrary code inside a sandbox via malicious network traffic. (Chromium security severity: Medium)

Vendor: google
Product: chrome
Published: May 20, 2026
Source: NVD
CVE-2026-9121 HIGH - 8.8

Out of bounds read in GPU in Google Chrome on prior to 148.0.7778.179 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)

Vendor: google
Product: chrome
Published: May 20, 2026
Source: NVD
CVE-2026-9120 HIGH - 8.8

Use after free in WebRTC in Google Chrome prior to 148.0.7778.179 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)

Vendor: google
Product: chrome
Published: May 20, 2026
Source: NVD
CVE-2026-9119 HIGH - 8.8

Heap buffer overflow in WebRTC in Google Chrome on prior to 148.0.7778.179 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

Vendor: google
Product: chrome
Published: May 20, 2026
Source: NVD
CVE-2026-9118 HIGH - 8.8

Use after free in XR in Google Chrome on Windows prior to 148.0.7778.179 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)

Vendor: google
Product: chrome
Published: May 20, 2026
Source: NVD
CVE-2026-9117 HIGH - 7.5

Type Confusion in GFX in Google Chrome on Linux, ChromeOS prior to 148.0.7778.179 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted video file. (Chromium security severity: High)

Vendor: google
Product: chrome
Published: May 20, 2026
Source: NVD
CVE-2026-9114 HIGH - 8.8

Use after free in QUIC in Google Chrome on prior to 148.0.7778.179 allowed a remote attacker to execute arbitrary code inside a sandbox via malicious network traffic. (Chromium security severity: High)

Vendor: google
Product: chrome
Published: May 20, 2026
Source: NVD
CVE-2026-9112 HIGH - 8.8

Use after free in GPU in Google Chrome on Windows prior to 148.0.7778.179 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

Vendor: google
Product: chrome
Published: May 20, 2026
Source: NVD
CVE-2026-9111 HIGH - 8.8

Use after free in WebRTC in Google Chrome on Linux prior to 148.0.7778.179 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: Critical)

Vendor: google
Product: chrome
Published: May 20, 2026
Source: NVD
CVE-2026-39310 HIGH - 8.6

Trilium Notes is a cross-platform, hierarchical note taking application focused on building large personal knowledge bases. In versions 0.102.1 and prior, the Clipper API in Trilium Desktop (v0.101.3) allows full authentication bypass when running in an Electron environment. When Trilium detects an ...

Vendor: TriliumNext
Product: Trilium
Published: May 20, 2026
Source: NVD
CVE-2026-24218 HIGH - 8.1

NVIDIA DGX OS contains a vulnerability in the factory provisioning process, where the cloning of a base image causes identical SSH host keys to be deployed across multiple systems. The sharing of cryptographic identifiers across all similarly provisioned systems enables host impersonation or attack...

Vendor: NVIDIA
Product: DGX Spark
Published: May 20, 2026
Source: NVD
CVE-2026-24217 HIGH - 8.8

NVIDIA BioNeMo Core for Linux contains a vulnerability where a user could cause a path traversal by loading a malicious file. A successful exploit of this vulnerability might lead to code execution, denial of service, information disclosure, and data tampering.

Vendor: NVIDIA
Product: BioNeMo Framework
Published: May 20, 2026
Source: NVD
CVE-2026-24216 HIGH - 7.8

NVIDIA BioNemo for Linux contains a vulnerability where a user could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, denial of service, information disclosure, and data tampering.

Vendor: NVIDIA
Product: BioNeMo Framework
Published: May 20, 2026
Source: NVD
CVE-2026-24188 HIGH - 8.2

NVIDIA TensorRT contains a vulnerability where an attacker could cause an out-of-bounds write. A successful exploit of this vulnerability might lead to data tampering.

Vendor: NVIDIA
Product: TensorRT
Published: May 20, 2026
Source: NVD
CVE-2026-20239 HIGH - 7.5

In Splunk Enterprise versions below 10.2.2 and 10.0.5, and Splunk Cloud Platform versions below 10.3.2512.8, 10.2.2510.11, 10.1.2507.21, and 10.0.2503.13, a user with a role that has access to the `_internal` index could view session cookies and response bodies that contain sensitive data.

Vendor: Splunk
Product: Splunk Enterprise, Splunk Cloud Platform
Published: May 20, 2026
Source: NVD
CVE-2026-7613 HIGH - 7.2

The Cost of Goods by PixelYourSite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'csvdata[0][cost_of_goods_value]' parameter in versions up to, and including, 1.2.12 due to insufficient input sanitization and output escaping. This makes it possible for unauthent...

Published: May 20, 2026
Source: NVD
CVE-2026-44926 HIGH - 8.8

InfoScale CmdServer before 7.4.2 mishandles access control.

Published: May 20, 2026
Source: NVD
CVE-2026-44925 HIGH - 8.8

Cross-Site Request Forgery (CSRF) vulnerability in InfoScale v.9.1.3 Operations Manager (VIOM) allows an attacker to force the user with an active session into clicking a malicious HTML link, which triggers unintended modifications on VIOM web application without the user's knowledge.

Vendor: veritas
Product: infoscale_operations_manager
Published: May 20, 2026
Source: NVD
CVE-2026-5783 HIGH - 7.6

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Beyaz Computer Software Design Industry and Trade Ltd. Co. CityPLus allows Reflected XSS. This issue affects CityPLus: before V24.29750.1.0.

Published: May 20, 2026
Source: NVD
CVE-2026-39047 HIGH - 7.5

Buffer Overflow vulnerability in EPSON L14150 FL27PB allows a remote attacker to execute arbitrary code via the RAW Printing Service (JetDirect) on TCP port 9100

Published: May 20, 2026
Source: NVD