Total CVEs

138,502

Critical Severity

3,573

High Severity

12,821

Last 7 Days

2,008
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 4,001 - 4,020 of 34,907 CVEs
CVE-2026-10732 MEDIUM - 6.4

All versions of the package decompress are vulnerable to Arbitrary File Write via Archive Extraction (Zip Slip) when extracting a ZIP archive containing two entries with the same path - the first being a symlink to an arbitrary target and the second being a regular file - the file content is written...

Product: decompress
Published: Jun 05, 2026
Source: NVD
CVE-2026-50593 HIGH - 7.3

Graphite before 1.3.15 has an integer underflow and resultant out-of-bounds write via Graphite actions, because slotat does not ensure that an offset is within the allowed slot-map range.

Vendor: Graphite project
Product: Graphite
Published: Jun 05, 2026
Source: NVD
CVE-2026-7763 CRITICAL - 9.8

A heap-based buffer overflow vulnerability in the morse.ko HaLow Wi-Fi kernel driver in Morse Micro HaLowLink 2 software versions prior to 2.11.13 allows an unauthenticated attacker within radio range to cause a Denial of Service (kernel panic) or potentially achieve Remote Code Execution via a craf...

Published: Jun 05, 2026
Source: NVD
CVE-2026-7762 CRITICAL - 9.8

A heap-based buffer overflow vulnerability in the dot11ah.ko HaLow Wi-Fi kernel driver in Morse Micro HaLowLink 2 software versions prior to 2.11.13 allows an unauthenticated attacker within radio range to cause a Denial of Service (kernel panic) or potentially achieve Remote Code Execution via a cr...

Published: Jun 05, 2026
Source: NVD
CVE-2026-50592 MEDIUM - 6.4

In Znuny LTS before 6.5.21 and Znuny before 7.3.3, there is reflected XSS in AdminCommunicationLog (aka the communication log administration view).

Vendor: Znuny
Product: Znuny
Published: Jun 05, 2026
Source: NVD
CVE-2026-50591 MEDIUM - 5.4

IN Znuny LTS before 6.5.21 and Znuny before 7.3.3, XSS can occur via stored user preferences.

Vendor: Znuny
Product: Znuny
Published: Jun 05, 2026
Source: NVD
CVE-2026-50590 MEDIUM - 4.5

In Mimecast Incydr before 2.6.0, arbitrary file access can occur.

Vendor: Mimecast
Product: Incydr
Published: Jun 05, 2026
Source: NVD

OpenAI Atlas before 1.2025.288.15 exposed privileged browser APIs to web content on *.openai.com origins. A cross-site scripting vulnerability in forum.openai.com could be used to access these functions, allowing access to browser history information and the ability to open or close tabs. OpenAI Atl...

Vendor: OpenAI
Product: OpenAI Atlas
Published: Jun 05, 2026
Source: NVD

A vulnerability was found in bytedance InfiniStore up to 0.2.33. The impacted element is the function purge_kv_map in the library /src/infinistore.h of the component KV Map Handler. Performing a manipulation results in inefficient algorithmic complexity. The attack requires a local approach. The exp...

Vendor: bytedance
Product: InfiniStore
Published: Jun 05, 2026
Source: NVD
CVE-2026-50589 MEDIUM - 5.3

In OpenStack Ironic 32 through 35.0.1, an unauthenticated malicious user could submit a crafted JSON string to some endpoints on the API or JSON-RPC service and effect a service crash.

Vendor: OpenStack
Product: Ironic
Published: Jun 05, 2026
Source: NVD
CVE-2026-11309 MEDIUM - 4.3

Insufficient policy enforcement in History in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)

Vendor: Google
Product: Chrome
Published: Jun 05, 2026
Source: NVD
CVE-2026-11308 MEDIUM - 6.3

Inappropriate implementation in Extensions in Google Chrome prior to 149.0.7827.53 allowed an attacker who convinced a user to install a malicious extension to perform privilege escalation via a crafted Chrome Extension. (Chromium security severity: Low)

Vendor: Google
Product: Chrome
Published: Jun 05, 2026
Source: NVD
CVE-2026-11307 HIGH - 8.8

Use after free in PDFium in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted PDF file. (Chromium security severity: Low)

Vendor: Google
Product: Chrome
Published: Jun 05, 2026
Source: NVD
CVE-2026-11306 HIGH - 8.8

Use after free in PDFium in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted PDF file. (Chromium security severity: Low)

Vendor: Google
Product: Chrome
Published: Jun 05, 2026
Source: NVD
CVE-2026-11305 HIGH - 8.8

Use after free in PDFium in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted PDF file. (Chromium security severity: Low)

Vendor: Google
Product: Chrome
Published: Jun 05, 2026
Source: NVD
CVE-2026-11304 HIGH - 8.8

Use after free in PDFium in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file. (Chromium security severity: Low)

Vendor: Google
Product: Chrome
Published: Jun 05, 2026
Source: NVD
CVE-2026-11303 HIGH - 8.8

Use after free in PDFium in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted PDF file. (Chromium security severity: Low)

Vendor: Google
Product: Chrome
Published: Jun 05, 2026
Source: NVD
CVE-2026-11302 MEDIUM - 4.3

Insufficient policy enforcement in Chrome for iOS in Google Chrome on iOS prior to 149.0.7827.53 allowed a remote attacker to bypass discretionary access control via a crafted HTML page. (Chromium security severity: Low)

Vendor: Google
Product: Chrome
Published: Jun 05, 2026
Source: NVD
CVE-2026-11301 HIGH - 8.8

Inappropriate implementation in LiveCaption in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially perform out of bounds memory access via malicious network traffic. (Chromium security severity: Low)

Vendor: Google
Product: Chrome
Published: Jun 05, 2026
Source: NVD
CVE-2026-11300 MEDIUM - 4.3

Inappropriate implementation in Permissions in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)

Vendor: Google
Product: Chrome
Published: Jun 05, 2026
Source: NVD