Total CVEs

138,196

Critical Severity

3,545

High Severity

12,691

Last 7 Days

1,953
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 3,201 - 3,220 of 34,601 CVEs
CVE-2026-11636 HIGH - 7.5

Use after free in Autofill in Google Chrome on Windows prior to 149.0.7827.103 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)

Vendor: Google
Product: Chrome
Published: Jun 09, 2026
Source: NVD
CVE-2026-11635 HIGH - 8.3

Use after free in Bluetooth in Google Chrome on Mac prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)

Vendor: Google
Product: Chrome
Published: Jun 09, 2026
Source: NVD
CVE-2026-11634 CRITICAL - 9.6

Use after free in Gamepad in Google Chrome on Windows prior to 149.0.7827.103 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)

Vendor: Google
Product: Chrome
Published: Jun 09, 2026
Source: NVD
CVE-2026-11633 HIGH - 8.8

Use after free in Bluetooth in Google Chrome on Mac prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code via a malicious peripheral. (Chromium security severity: Critical)

Vendor: Google
Product: Chrome
Published: Jun 09, 2026
Source: NVD
CVE-2026-11632 HIGH - 7.5

Use after free in TabStrip in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who convinced a user to engage in specific UI gestures to execute arbitrary code via a crafted HTML page. (Chromium security severity: Critical)

Vendor: Google
Product: Chrome
Published: Jun 09, 2026
Source: NVD
CVE-2026-11631 HIGH - 8.3

Use after free in Aura in Google Chrome on Windows prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)

Vendor: Google
Product: Chrome
Published: Jun 09, 2026
Source: NVD
CVE-2026-11630 HIGH - 8.8

Use after free in File Input in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)

Vendor: Google
Product: Chrome
Published: Jun 09, 2026
Source: NVD
CVE-2026-11629 HIGH - 8.8

Use after free in Ozone in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)

Vendor: Google
Product: Chrome
Published: Jun 09, 2026
Source: NVD
CVE-2026-11628 MEDIUM - 6.8

Use after free in Ozone in Google Chrome prior to 149.0.7827.103 allowed a local attacker to potentially exploit heap corruption via physical access to the device. (Chromium security severity: Critical)

Vendor: Google
Product: Chrome
Published: Jun 09, 2026
Source: NVD
CVE-2026-47737 HIGH - 7.5

Puma PROXY Protocol v1 Accepts Repeated Protocol Headers on Persistent Connections

Vendor: rubygems
Product: puma
Published: Jun 09, 2026
Source: GitHub
CVE-2026-47736 HIGH - 7.5

Puma PROXY Protocol v1 Parser Allows Remote Memory Exhaustion

Vendor: rubygems
Product: puma
Published: Jun 08, 2026
Source: GitHub

Arc has an authenticated arbitrary local-file read via DuckDB I/O functions that bypasses RBAC table-level checks

Vendor: go
Product: github.com/basekick-labs/arc
Published: Jun 08, 2026
Source: GitHub
CVE-2026-47734 MEDIUM - 5.7

Dulwich is a pure-Python implementation of the Git file formats and protocols. Starting in version 0.1.0 and prior to version 1.2.5, a client with push access could push a tiny crafted thin pack (~174 bytes) whose delta header declares a huge dest_size. When dulwich ingested it via add_thin_pack...

Vendor: pip
Product: dulwich
Published: Jun 08, 2026
Source: GitHub

nebula-mesh: GET /api/v1/audit-log discloses all entries to any operator

Vendor: go
Product: github.com/juev/nebula-mesh
Published: Jun 08, 2026
Source: GitHub

bz2.BZ2Decompressor objects could be reused after a decompression error. If an application caught the resulting OSError and retried with the same decompressor, crafted input could cause the decompressor to resume from an invalid internal state and perform out-of-bounds writes to a stack buffer. This...

Published: Jun 08, 2026
Source: NVD

nebula-mesh's web UI lacks CSRF tokens on /ui/* mutating endpoints

Vendor: go
Product: github.com/juev/nebula-mesh
Published: Jun 08, 2026
Source: GitHub
CVE-2026-47724 CRITICAL - 9.9

nebula-mesh: API endpoints lack ownership checks, enabling cross-operator privilege escalation

Vendor: go
Product: github.com/juev/nebula-mesh
Published: Jun 08, 2026
Source: GitHub

nebula-mesh: Web UI and API responses lack security headers (CSP, X-Frame-Options, HSTS, etc.)

Vendor: go
Product: github.com/juev/nebula-mesh
Published: Jun 08, 2026
Source: GitHub

nebula-mesh: Host advanced overrides allow YAML injection into agent config.yml

Vendor: go
Product: github.com/juev/nebula-mesh
Published: Jun 08, 2026
Source: GitHub
CVE-2026-47721 MEDIUM - 6.3

FUXA's scheduler API missing admin check enables operator-to-admin escalation via scheduled device actions

Vendor: npm
Product: fuxa-server
Published: Jun 08, 2026
Source: GitHub