Total CVEs

139,939

Critical Severity

3,664

High Severity

13,195

Last 7 Days

1,702
Quick preset (or use dates below)
Clear Filters
Showing 4,481 - 4,500 of 13,740 CVEs
CVE-2026-7939 MEDIUM - 5.4

Inappropriate implementation in SanitizerAPI in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page. (Chromium security severity: Medium)

Vendor: google
Product: chrome
Published: May 06, 2026
Source: NVD
CVE-2026-7936 MEDIUM - 4.3

Object lifecycle issue in V8 in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: Medium)

Vendor: google
Product: chrome
Published: May 06, 2026
Source: NVD
CVE-2026-7935 MEDIUM - 5.4

Inappropriate implementation in Speech in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)

Vendor: google
Product: chrome
Published: May 06, 2026
Source: NVD
CVE-2026-7934 MEDIUM - 4.2

Insufficient validation of untrusted input in Popup Blocker in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Medium)

Vendor: google
Product: chrome
Published: May 06, 2026
Source: NVD
CVE-2026-7933 MEDIUM - 4.3

Out of bounds read in WebCodecs in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to perform an out of bounds memory read via a crafted video file. (Chromium security severity: Medium)

Vendor: google
Product: chrome
Published: May 06, 2026
Source: NVD
CVE-2026-7932 MEDIUM - 4.4

Insufficient policy enforcement in Downloads in Google Chrome prior to 148.0.7778.96 allowed a local attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Medium)

Vendor: google
Product: chrome
Published: May 06, 2026
Source: NVD
CVE-2026-7931 MEDIUM - 5.4

Insufficient validation of untrusted input in iOS in Google Chrome on iOS prior to 148.0.7778.96 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)

Vendor: google
Product: chrome
Published: May 06, 2026
Source: NVD
CVE-2026-7924 MEDIUM - 6.5

Uninitialized Use in Dawn in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High)

Vendor: google
Product: chrome
Published: May 06, 2026
Source: NVD
CVE-2026-7915 MEDIUM - 4.3

Insufficient data validation in DevTools in Google Chrome on Android prior to 148.0.7778.96 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: High)

Vendor: google
Product: chrome
Published: May 06, 2026
Source: NVD
CVE-2026-7912 MEDIUM - 4.2

Integer overflow in GPU in Google Chrome on Android prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to perform arbitrary read/write via a crafted HTML page. (Chromium security severity: High)

Vendor: google
Product: chrome
Published: May 06, 2026
Source: NVD
CVE-2026-7904 MEDIUM - 4.3

Out of bounds read in Fonts in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: High)

Vendor: google
Product: chrome
Published: May 06, 2026
Source: NVD
CVE-2026-41931 MEDIUM - 5.3

Vvveb before version 1.0.8.2 contains an information disclosure vulnerability that allows unauthenticated attackers to obtain sensitive server information by triggering unhandled exceptions in the password-reset module. Attackers can access the admin password-reset endpoint to trigger a fatal error ...

Vendor: givanz
Product: Vvveb
Published: May 06, 2026
Source: NVD
CVE-2025-31960 MEDIUM - 5.3

HCL BigFix Service Management (SM) is vulnerable to information exposure due to improper error handling within its reporting module. It was observed that supplying an invalid or out-of-range value to the consumer_company parameter during a report-viewing request causes the application to trigger an ...

Vendor: HCL
Product: BigFix Service Management (SM)
Published: May 06, 2026
Source: NVD
CVE-2026-44305 MEDIUM - 6.8

Lemur manages TLS certificate creation. Prior to 1.9.0, when LDAP TLS is enabled (LDAP_USE_TLS = True), Lemur's LDAP authentication module unconditionally disables TLS certificate verification at the global ldap module level. This allows a man-in-the-middle attacker positioned between Lemur and...

Vendor: pip
Product: lemur
Published: May 06, 2026
Source: GitHub
CVE-2026-44226 MEDIUM - 5.3

pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev100, pyload-ng WebUI returns full Python traceback details to clients on unhandled exceptions. Because /web/<path:filename> is reachable without authentication and renders attacker-controlled template name...

Vendor: pip
Product: pyload-ng
Published: May 06, 2026
Source: GitHub
CVE-2026-20219 MEDIUM - 5.4

A vulnerability in the REST API of Cisco Slido could have allowed an authenticated, remote attacker to access the social profile data of other users or affect quiz and poll results. Cisco has addressed this vulnerability in Cisco Slido and no customer action is needed. This vulnerability existed ...

Vendor: Cisco
Product: Cisco Webex Meetings, Cisco Slido
Published: May 06, 2026
Source: NVD
CVE-2026-20195 MEDIUM - 5.3

A vulnerability in an identity management API endpoint of Cisco ISE could allow an unauthenticated, remote attacker to enumerate valid user accounts on an affected device. This vulnerability exists because error messages are observed when the affected API endpoint is called. An attacker could exp...

Vendor: Cisco
Product: Cisco Identity Services Engine Software
Published: May 06, 2026
Source: NVD
CVE-2026-20193 MEDIUM - 4.3

A vulnerability in the RADIUS Policy API endpoints of Cisco ISE could allow an&nbsp;authenticated, remote attacker with read-only Administrator privileges to gain unauthorized access to sensitive information on an affected device. This vulnerability is due to improper role-based access contro...

Vendor: Cisco
Product: Cisco Identity Services Engine Software
Published: May 06, 2026
Source: NVD
CVE-2026-20189 MEDIUM - 4.3

A vulnerability in the log file download functionality of Cisco Prime Infrastructure could allow an&nbsp;authenticated, remote attacker to download arbitrary log files from the server. This vulnerability is due to insufficient authorization checks on the download service API. An attacker coul...

Vendor: Cisco
Product: Cisco Prime Infrastructure
Published: May 06, 2026
Source: NVD
CVE-2026-20172 MEDIUM - 4.3

A vulnerability in the Lite Agent feature of Cisco Enterprise Chat and Email (ECE) could allow an authenticated, remote attacker to conduct browser-based attacks. To exploit this vulnerability, the attacker must have valid credentials for a user account with at least the role of Agent. This vulne...

Vendor: Cisco
Product: Cisco Enterprise Chat and Email
Published: May 06, 2026
Source: NVD