Total CVEs

139,442

Critical Severity

3,643

High Severity

13,079

Last 7 Days

1,297
Quick preset (or use dates below)
Clear Filters
📅 Showing Year: 2026 (January 1 - December 31, 2026) View All Years →
Showing 981 - 1,000 of 2,903 CVEs
CVE-2026-8535 MEDIUM - 5.3

Out of bounds read in Media in Google Chrome on Linux and ChromeOS prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted JPEG file. (Chromium security severity: High)

Vendor: google
Product: chrome
Published: May 14, 2026
Source: NVD
CVE-2026-8534 HIGH - 8.3

Integer overflow in GPU in Google Chrome on Linux and ChromeOS prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

Vendor: google
Product: chrome
Published: May 14, 2026
Source: NVD

mdserver-web is a simple Linux panel. From 0.18.0 to 0.18.4, mdserver-web has a front-end unauthorized remote command execution vulnerability. Due to the lack of authentication on the /modify_crond and /start_task interfaces, it is possible to modify the default built-in scheduled tasks and start th...

Vendor: midoks
Product: mdserver-web
Published: May 14, 2026
Source: NVD
CVE-2026-26191 MEDIUM - 9.8

Fleet is open source device management software. Prior to version 4.81.0, a vulnerability in Fleet's software installer pipeline could allow a crafted software package to execute arbitrary commands as root (macOS/Linux) or SYSTEM (Windows) on managed endpoints when an uninstall is triggered. Wh...

Vendor: go
Product: github.com/fleetdm/fleet/v4
Published: May 14, 2026
Source: GitHub
CVE-2026-32991 HIGH - 7.1

Improper authorization checks of team members privileges allow a team member to escalate privileges to the team owner account.

Vendor: WebPros
Product: cPanel, WP Squared, cPanel (CloudLinux 6, CentOS 6)
Published: May 13, 2026
Source: NVD
CVE-2026-29206 HIGH - 8.1

Insufficient sanitization of SQL queries in the `sqloptimizer` utility script allows SQL Injections on behalf of the root user if Slow Query logging is enabled.

Vendor: WebPros
Product: cPanel, WP Squared, cPanel (CloudLinux 6, CentOS 6)
Published: May 13, 2026
Source: NVD

Multiple local privilege escalation vulnerabilities in the Palo Alto Networks GlobalProtect™ app allow a local user to escalate their privileges to NT AUTHORITY\SYSTEM on Windows and root on macOS and Linux. This enables a non-administrative user to execute arbitrary commands with administrative pri...

Published: May 13, 2026
Source: NVD

Multiple improper certificate validation vulnerabilities in the Palo Alto Networks GlobalProtect™ app enables an attacker to intercept encrypted communications and potentially compromise the endpoint. This can enable a local non-administrative operating system user or an attacker on the same subnet ...

Published: May 13, 2026
Source: NVD

An improper certificate validation vulnerability in the Prisma Access Agent® for Android and Chrome OS enables an attacker to perform a man-in-the-middle (MitM) attack to intercept VPN traffic. By presenting a certificate for any domain issued by a trusted Certificate Authority, the attacker can cap...

Published: May 13, 2026
Source: NVD

A vulnerability with a privilege management mechanism in the Palo Alto Networks Prisma Access Agent® enables a locally authenticated non-administrative user to escalate their privileges to root on macOS and Linux or NT AUTHORITY\SYSTEM on Windows. This allows the user to execute arbitrary code and r...

Published: May 13, 2026
Source: NVD

Multiple information disclosure vulnerabilities in Prisma Access Agent® allow a local user to access sensitive configuration data and credentials. The Prisma Access Agent on Linux, ChromeOS, Android, and iOS are not affected.

Published: May 13, 2026
Source: NVD

In the Linux kernel, the following vulnerability has been resolved: liveupdate: luo_file: remember retrieve() status LUO keeps track of successful retrieve attempts on a LUO file. It does so to avoid multiple retrievals of the same file. Multiple retrievals cause problems because once the file i...

Vendor: Linux
Product: Linux
Published: May 13, 2026
Source: NVD

In the Linux kernel, the following vulnerability has been resolved: usb: xhci: Prevent interrupt storm on host controller error (HCE) The xHCI controller reports a Host Controller Error (HCE) in UAS Storage Device plug/unplug scenarios on Android devices. HCE is checked in xhci_irq() function and ...

Vendor: Linux
Product: Linux
Published: May 13, 2026
Source: NVD

In the Linux kernel, the following vulnerability has been resolved: ata: libata-core: Disable LPM on ST1000DM010-2EP102 According to a user report, the ST1000DM010-2EP102 has problems with LPM, causing random system freezes. The drive belongs to the same BarraCuda family as the ST2000DM008-2FR102 ...

Vendor: Linux
Product: Linux
Published: May 13, 2026
Source: NVD

In the Linux kernel, the following vulnerability has been resolved: arm64: contpte: fix set_access_flags() no-op check for SMMU/ATS faults contpte_ptep_set_access_flags() compared the gathered ptep_get() value against the requested entry to detect no-ops. ptep_get() ORs AF/dirty from all sub-PTEs ...

Vendor: Linux
Product: Linux
Published: May 13, 2026
Source: NVD

In the Linux kernel, the following vulnerability has been resolved: nouveau/gsp: drop WARN_ON in ACPI probes These WARN_ONs seem to trigger a lot, and we don't seem to have a plan to fix them, so just drop them, as they are most likely harmless.

Vendor: Linux
Product: Linux
Published: May 13, 2026
Source: NVD

In the Linux kernel, the following vulnerability has been resolved: mmc: core: Avoid bitfield RMW for claim/retune flags Move claimed and retune control flags out of the bitfield word to avoid unrelated RMW side effects in asynchronous contexts. The host->claimed bit shared a word with retune ...

Vendor: Linux
Product: Linux
Published: May 13, 2026
Source: NVD

In the Linux kernel, the following vulnerability has been resolved: KVM: SVM: Set/clear CR8 write interception when AVIC is (de)activated Explicitly set/clear CR8 write interception when AVIC is (de)activated to fix a bug where KVM leaves the interception enabled after AVIC is activated. E.g. if ...

Vendor: Linux
Product: Linux
Published: May 13, 2026
Source: NVD

In the Linux kernel, the following vulnerability has been resolved: sched_ext: Disable preemption between scx_claim_exit() and kicking helper work scx_claim_exit() atomically sets exit_kind, which prevents scx_error() from triggering further error handling. After claiming exit, the caller must kic...

Vendor: Linux
Product: Linux
Published: May 13, 2026
Source: NVD
CVE-2026-43481 HIGH - 7.8

In the Linux kernel, the following vulnerability has been resolved: net-shapers: don't free reply skb after genlmsg_reply() genlmsg_reply() hands the reply skb to netlink, and netlink_unicast() consumes it on all return paths, whether the skb is queued successfully or freed on an error path. ...

Vendor: Linux
Product: Linux
Published: May 13, 2026
Source: NVD