Total CVEs

137,241

Critical Severity

3,307

High Severity

12,254

Last 7 Days

1,434
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 381 - 400 of 11,951 CVEs
CVE-2026-48610 HIGH - 8.1

Under certain network configurations, a malicious actor with access to network could exploit an Improper Access Control vulnerability found in certain devices running UniFi OS to make unauthorized changes to such UniFi OS devices.

Vendor: Ubiquiti Inc
Product: UDM, UDM-Pro, UDM-SE, UDM-Pro-Max, UDM-Beast, EFG, UDW, UDR, UDR7, UDR-5G, Express 7, UCG-Ultra, UCG-Max, UCG-Fiber, UCG-Industrial
Published: Jun 12, 2026
Source: NVD
CVE-2026-47368 HIGH - 8.6

A malicious actor with access to the network could exploit a Path Traversal vulnerability found in certain devices running UniFi OS to obtain data from such UniFi OS devices or instances.

Published: Jun 12, 2026
Source: NVD
CVE-2026-47366 HIGH - 7.2

Improper verification of access permissions when modifying permissions through the Administration Control Panel (ACP) allowed an authenticated administrator to grant permissions beyond the level authorized for their account, resulting in privilege escalation within the administrative interface.

Vendor: phpBB
Product: phpBB
Published: Jun 12, 2026
Source: NVD
CVE-2026-11933 HIGH - 8.8

A use-after-free vulnerability exists in MongoDB Server's server-side JavaScript engine when converting BSON documents to JavaScript arrays. An authenticated user with read privileges who is able to run server-side JavaScript (for example, via $where or $function) can cause the server to access...

Vendor: MongoDB
Product: MongoDB
Published: Jun 12, 2026
Source: NVD
CVE-2026-45418 HIGH - 8.8

ClipBucket v5 is an open source video sharing platform. Prior to version 5.5.3 - #132, any authenticated user who can upload videos can add multiple subtitles from different files and change their title (English, Spanish...). The POST /actions/subtitle_edit.php request used to change their title inc...

Vendor: MacWarrior
Product: clipbucket-v5
Published: Jun 11, 2026
Source: NVD
CVE-2026-6250 HIGH - 8.1

An authenticated format string vulnerability exists in the ONVIF service of Tapo C110 v2 due to improper handling of user-controlled input.ย  Externally controlled data is interpreted as a format string, which can be used to manipulate stack memory, including control flow data such as return addresse...

Vendor: tp-link
Product: tapo_c110_firmware
Published: Jun 11, 2026
Source: NVD
CVE-2026-42653 HIGH - 7.1

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in iova.Mihai SliceWP allows Stored XSS. This issue affects SliceWP: from n/a through 1.2.6.

Vendor: iova.mihai
Product: SliceWP
Published: Jun 11, 2026
Source: NVD
CVE-2026-12035 HIGH - 8.8

Use after free in Views in Google Chrome on Windows prior to 149.0.7827.115 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

Vendor: Google
Product: Chrome
Published: Jun 11, 2026
Source: NVD
CVE-2026-12034 HIGH - 8.3

Insufficient validation of untrusted input in Linux Toolkit Theming in Google Chrome on Linux prior to 149.0.7827.115 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a malicious file. (Chromium security severity: High)

Vendor: Google
Product: Chrome
Published: Jun 11, 2026
Source: NVD
CVE-2026-12031 HIGH - 8.3

Inappropriate implementation in Views in Google Chrome on Windows prior to 149.0.7827.115 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

Vendor: Google
Product: Chrome
Published: Jun 11, 2026
Source: NVD
CVE-2026-12030 HIGH - 8.3

Out of bounds write in GPU in Google Chrome on Android prior to 149.0.7827.115 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

Vendor: Google
Product: Chrome
Published: Jun 11, 2026
Source: NVD
CVE-2026-12029 HIGH - 8.3

Use after free in Video in Google Chrome on Windows prior to 149.0.7827.115 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

Vendor: Google
Product: Chrome
Published: Jun 11, 2026
Source: NVD
CVE-2026-12028 HIGH - 8.3

Use after free in GPU in Google Chrome on Android prior to 149.0.7827.115 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

Vendor: Google
Product: Chrome
Published: Jun 11, 2026
Source: NVD
CVE-2026-12023 HIGH - 8.3

Use after free in GPU in Google Chrome on Mac prior to 149.0.7827.115 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

Vendor: Google
Product: Chrome
Published: Jun 11, 2026
Source: NVD
CVE-2026-12022 HIGH - 8.3

Race in Safe Browsing in Google Chrome on Mac prior to 149.0.7827.115 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a malicious file. (Chromium security severity: High)

Vendor: Google
Product: Chrome
Published: Jun 11, 2026
Source: NVD
CVE-2026-12020 HIGH - 8.8

Use after free in Autofill in Google Chrome on Mac prior to 149.0.7827.115 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

Vendor: Google
Product: Chrome
Published: Jun 11, 2026
Source: NVD
CVE-2026-12019 HIGH - 8.3

Heap buffer overflow in Codecs in Google Chrome on Linux and ChromeOS prior to 149.0.7827.115 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

Vendor: Google
Product: Chrome
Published: Jun 11, 2026
Source: NVD
CVE-2026-12018 HIGH - 8.8

Inappropriate implementation in Mojo in Google Chrome on Windows prior to 149.0.7827.115 allowed a local attacker to perform OS-level privilege escalation via a malicious file. (Chromium security severity: High)

Vendor: Google
Product: Chrome
Published: Jun 11, 2026
Source: NVD
CVE-2026-12016 HIGH - 8.3

Inappropriate implementation in DevTools in Google Chrome prior to 149.0.7827.115 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

Vendor: Google
Product: Chrome
Published: Jun 11, 2026
Source: NVD
CVE-2026-12014 HIGH - 8.3

Use after free in Cast in Google Chrome prior to 149.0.7827.115 allowed an attacker on the local network segment to potentially perform a sandbox escape via malicious network traffic. (Chromium security severity: High)

Vendor: Google
Product: Chrome
Published: Jun 11, 2026
Source: NVD