Total CVEs

137,241

Critical Severity

3,307

High Severity

12,254

Last 7 Days

1,426
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 1,081 - 1,100 of 11,951 CVEs
CVE-2026-50257 HIGH - 7.8

A use-after-free flaw was found in the X.Org X server and Xwayland in miSyncDestroyFence(). A client that sets up multiple fence triggers can trigger a use-after-free function pointer call. An attacker would connect to the X server to set up a fence and await that fence, then a second X connection d...

Vendor: Red Hat
Product: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9
Published: Jun 05, 2026
Source: NVD
CVE-2026-50256 HIGH - 7.8

A stack-based buffer overflow flaw was found in the X.Org X server and Xwayland. A mismatch between the X server and the libXfont2 library's maximum font name length can cause a stack buffer overflow during font alias resolution. The server allocates a 256 byte stack buffer but libXfont2's...

Vendor: Red Hat
Product: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9
Published: Jun 05, 2026
Source: NVD
CVE-2026-50265 HIGH - 7.0

A flaw was found in libinput. A local attacker with access to /dev/uinput can inject arbitrary udev properties through the libinput-device-group helper. This injection can lead to root code execution, for example, by exploiting REMOVE_CMD properties that are executed when a device is removed. This v...

Vendor: Red Hat
Product: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9
Published: Jun 05, 2026
Source: NVD
CVE-2026-21033 HIGH - 7.1

Improper export of android application components in ExpressHomeWidgetReceiver of Samsung Assistant prior to version 9.3.14 allows local attacker to execute arbitrary script.

Vendor: Samsung Mobile
Product: Samsung Assistant
Published: Jun 05, 2026
Source: NVD
CVE-2026-21032 HIGH - 7.1

Improper export of android application components in SmartHomeWidgetReceiver of Samsung Assistant prior to version 9.3.14 allows local attacker to execute arbitrary script.

Vendor: Samsung Mobile
Product: Samsung Assistant
Published: Jun 05, 2026
Source: NVD
CVE-2026-21031 HIGH - 7.8

Improper authorization in AppBlock prior to SMR Jun-2026 Release 1 allows local attacker to launch arbitrary activity. User interaction is required for triggering this vulnerability.

Vendor: Samsung Mobile
Product: Samsung Mobile Devices
Published: Jun 05, 2026
Source: NVD
CVE-2026-21030 HIGH - 7.8

Improper access control in MediaTek Audio HAL prior to SMR Jun-2026 Release 1 allows local attackers to trigger privileged functions.

Vendor: Samsung Mobile
Product: Samsung Mobile Devices
Published: Jun 05, 2026
Source: NVD
CVE-2026-21029 HIGH - 7.8

Improper export of android application components in Galaxy Editing Service prior to SMR Jun-2026 Release 1 allows local attacker to execute privileged operations.

Vendor: Samsung Mobile
Product: Samsung Mobile Devices
Published: Jun 05, 2026
Source: NVD
CVE-2026-11332 HIGH - 7.8

A flaw was found in ansible-core. The ansible-galaxy role install command processes dependency specifications from a role's meta/requirements.yml file. Due to improper neutralization of argument delimiters, a malicious role author can inject arbitrary git configuration flags through the src fie...

Vendor: Red Hat
Product: Red Hat Ansible Automation Platform 2
Published: Jun 05, 2026
Source: NVD
CVE-2026-21837 HIGH - 8.8

HCL Digital Experience is affected by an OS command injection vulnerability in the Digital Asset Management API.ย  An attacker may execute arbitrary operating system commands, typically inheriting the privileges of the vulnerable application, which could possibly lead to a complete system takeover an...

Vendor: HCLSoftware
Product: Digital Experience
Published: Jun 05, 2026
Source: NVD
CVE-2026-50593 HIGH - 7.3

Graphite before 1.3.15 has an integer underflow and resultant out-of-bounds write via Graphite actions, because slotat does not ensure that an offset is within the allowed slot-map range.

Vendor: Graphite project
Product: Graphite
Published: Jun 05, 2026
Source: NVD
CVE-2026-11307 HIGH - 8.8

Use after free in PDFium in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted PDF file. (Chromium security severity: Low)

Vendor: Google
Product: Chrome
Published: Jun 05, 2026
Source: NVD
CVE-2026-11306 HIGH - 8.8

Use after free in PDFium in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted PDF file. (Chromium security severity: Low)

Vendor: Google
Product: Chrome
Published: Jun 05, 2026
Source: NVD
CVE-2026-11305 HIGH - 8.8

Use after free in PDFium in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted PDF file. (Chromium security severity: Low)

Vendor: Google
Product: Chrome
Published: Jun 05, 2026
Source: NVD
CVE-2026-11304 HIGH - 8.8

Use after free in PDFium in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file. (Chromium security severity: Low)

Vendor: Google
Product: Chrome
Published: Jun 05, 2026
Source: NVD
CVE-2026-11303 HIGH - 8.8

Use after free in PDFium in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted PDF file. (Chromium security severity: Low)

Vendor: Google
Product: Chrome
Published: Jun 05, 2026
Source: NVD
CVE-2026-11301 HIGH - 8.8

Inappropriate implementation in LiveCaption in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially perform out of bounds memory access via malicious network traffic. (Chromium security severity: Low)

Vendor: Google
Product: Chrome
Published: Jun 05, 2026
Source: NVD
CVE-2026-11297 HIGH - 7.7

Insufficient validation of untrusted input in Reader Mode in Google Chrome on Android prior to 149.0.7827.53 allowed a local attacker to bypass navigation restrictions via a malicious file. (Chromium security severity: Low)

Vendor: Google
Product: Chrome
Published: Jun 05, 2026
Source: NVD
CVE-2026-11296 HIGH - 7.5

Inappropriate implementation in ImageCapture in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to perform privilege escalation via a crafted HTML page. (Chromium security severity: Low)

Vendor: Google
Product: Chrome
Published: Jun 05, 2026
Source: NVD
CVE-2026-11295 HIGH - 8.8

Inappropriate implementation in WebView in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker to perform privilege escalation via a crafted HTML page. (Chromium security severity: Low)

Vendor: Google
Product: Chrome
Published: Jun 05, 2026
Source: NVD