Total CVEs

149,286

Critical Severity

4,762

High Severity

17,012

Last 7 Days

2,837
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 9,961 - 9,980 of 45,691 CVEs
CVE-2026-13028 CRITICAL - 9.6

Use after free in WebGL in Google Chrome on Android prior to 149.0.7827.197 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)

Vendor: Google
Product: Chrome
Published: Jun 24, 2026
Source: NVD
CVE-2026-13027 HIGH - 8.8

Use after free in FileSystem in Google Chrome prior to 149.0.7827.197 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

Vendor: Google
Product: Chrome
Published: Jun 24, 2026
Source: NVD
CVE-2026-13026 HIGH - 8.8

Use after free in Digital Credentials in Google Chrome on Mac prior to 149.0.7827.197 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

Vendor: Google
Product: Chrome
Published: Jun 24, 2026
Source: NVD
CVE-2026-13025 HIGH - 8.3

Race in DevTools in Google Chrome prior to 149.0.7827.197 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

Vendor: Google
Product: Chrome
Published: Jun 24, 2026
Source: NVD
CVE-2026-13024 MEDIUM - 4.2

Insufficient validation of untrusted input in Navigation in Google Chrome prior to 149.0.7827.197 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: High)

Vendor: Google
Product: Chrome
Published: Jun 24, 2026
Source: NVD
CVE-2026-13023 MEDIUM - 5.3

Uninitialized Use in GPU in Google Chrome prior to 149.0.7827.197 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High)

Vendor: Google
Product: Chrome
Published: Jun 24, 2026
Source: NVD
CVE-2026-13022 MEDIUM - 6.5

Inappropriate implementation in Autofill in Google Chrome prior to 149.0.7827.197 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)

Vendor: Google
Product: Chrome
Published: Jun 24, 2026
Source: NVD
CVE-2026-13021 MEDIUM - 4.3

Inappropriate implementation in DeviceBoundSessionCredentials in Google Chrome prior to 149.0.7827.197 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium security severity: High)

Vendor: Google
Product: Chrome
Published: Jun 24, 2026
Source: NVD
CVE-2026-12760 MEDIUM - 6.5

A denial-of-service (DoS) vulnerability has been identified in Tapo C200 v3 in the network packet handling logic due to improper handling of IPv4 fragmented packets.ย  An unauthenticated adjacent attacker can send crafted packets to cause excessive resource consumption, leading to instability of the ...

Vendor: TP-Link Systems Inc.
Product: Tapo C200 v3
Published: Jun 24, 2026
Source: NVD
CVE-2025-60471 MEDIUM - 5.5

A use-after-free in the gf_filter_pid_reconfigure_task_discard function (/filter_core/filter_pid.c) of GPAC Project/MP4Box before 26.02.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted media file.

Vendor: gpac
Product: gpac
Published: Jun 24, 2026
Source: NVD

AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. From 1.11.1 until 1.14.1, userId/workspaceId scoping to the parsed-files read/delete paths was added. However, the POST /api/workspace/:slug/embed-parsed-file/:fileId flow stil...

Vendor: Mintplex-Labs
Product: anything-llm
Published: Jun 24, 2026
Source: NVD
CVE-2026-54699 HIGH - 7.7

Warp is an agentic development environment. From 0.2024.03.12.08.02.stable_01 until 0.2026.05.06.15.42.stable_01, Warp contains an OS command injection vulnerability in the WSL URL-opening fallback. When Warp is running under WSL and cannot open a URL through wslview, it falls back to a Windows comm...

Vendor: warpdotdev
Product: warp
Published: Jun 24, 2026
Source: NVD
CVE-2026-54686 MEDIUM - 4.3

Warp is an agentic development environment. From 0.2021.04.25.23.05.stable_00 until 0.2026.05.06.15.42.stable_01, Warp accepted certain state-mutating terminal lifecycle hooks from the PTY stream without verifying that the hooks were emitted by Warp's shell integration for the active session. A...

Vendor: warpdotdev
Product: warp
Published: Jun 24, 2026
Source: NVD
CVE-2026-49851 HIGH - 7.5

Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.3.0, Mistune is vulnerable to a CPU exhaustion DoS due to superlinear (approximately O(nยฒ)) behavior in parse_link_text. When parsing Markdown containing many consecutive [ characters, parse_link_text repeatedly scans the inp...

Vendor: lepture
Product: mistune
Published: Jun 24, 2026
Source: NVD
CVE-2026-48789 MEDIUM - 4.3

AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. Prior to 1.13.0, on Windows, the document folder listing route can accept an encoded absolute Windows path that resolves outside the intended documents directory. The shared pa...

Vendor: Mintplex-Labs
Product: anything-llm
Published: Jun 24, 2026
Source: NVD
CVE-2026-48732 HIGH - 8.8

Warp is an agentic development environment. From 0.2023.03.21.08.02.stable_00 until 0.2026.05.06.15.42.stable_01, Warp contains a command injection issue in the legacy SSH background command path. Warp used the remote working directory reported by the session when building helper commands for SSH-ba...

Vendor: warpdotdev
Product: warp
Published: Jun 24, 2026
Source: NVD
CVE-2026-48731 HIGH - 7.8

Warp is an agentic development environment. From 0.2024.02.20.08.01.stable_01 until 0.2026.05.06.15.42.stable_01, Warp contains a command injection issue in the Linux external editor launcher. Warp expanded freedesktop .desktop Exec templates for affected editor integrations and executed the expande...

Vendor: warpdotdev
Product: warp
Published: Jun 24, 2026
Source: NVD
CVE-2026-48725 HIGH - 8.1

Warp is an agentic development environment. From 0.2021.04.25.23.05.stable_00 until 0.2026.05.06.15.42.stable_01, Warp allows terminal output to request access to the local system clipboard. A malicious remote host, remote program, or other attacker-controlled terminal output source can trigger clip...

Vendor: warpdotdev
Product: warp
Published: Jun 24, 2026
Source: NVD
CVE-2026-48721 HIGH - 8.6

Warp is an agentic development environment. From 0.2025.10.08.08.12.stable_00 until 0.2026.05.06.15.42.stable_01, Warp contains a command execution permission-check bypass in the default unsandboxed CLI agent profile. The CLI profile is non-interactive and relies on a command denylist as a safety bo...

Vendor: warpdotdev
Product: warp
Published: Jun 24, 2026
Source: NVD
CVE-2026-48720 HIGH - 8.8

Warp is an agentic development environment. From 0.2025.03.05.08.02.stable_00 until 0.2026.05.06.15.42.stable_01, Warp accepts non-inline `OSC 1337;File` payloads from terminal output and materialize the decoded payload as a local file without an additional confirmation step. This vulnerability is f...

Vendor: warpdotdev
Product: warp
Published: Jun 24, 2026
Source: NVD