Total CVEs

138,502

Critical Severity

3,573

High Severity

12,821

Last 7 Days

1,988
Quick preset (or use dates below)
Clear Filters
Showing 1,101 - 1,120 of 13,341 CVEs
CVE-2026-11685 MEDIUM - 4.3

Inappropriate implementation in MediaCapture in Google Chrome on Mac prior to 149.0.7827.103 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)

Vendor: Google
Product: Chrome
Published: Jun 09, 2026
Source: NVD
CVE-2026-11678 MEDIUM - 5.3

Integer overflow in libyuv in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High)

Vendor: Google
Product: Chrome
Published: Jun 09, 2026
Source: NVD
CVE-2026-11669 MEDIUM - 5.3

Out of bounds read in Media in Google Chrome on ChromeOS prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High)

Vendor: Google
Product: Chrome
Published: Jun 09, 2026
Source: NVD
CVE-2026-11668 MEDIUM - 4.3

Uninitialized Use in Codecs in Google Chrome on Linux, ChromeOS prior to 149.0.7827.103 allowed a remote attacker to leak cross-origin data via a crafted video file. (Chromium security severity: High)

Vendor: Google
Product: Chrome
Published: Jun 09, 2026
Source: NVD
CVE-2026-11666 MEDIUM - 5.4

Insufficient validation of untrusted input in Input in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: High)

Vendor: Google
Product: Chrome
Published: Jun 09, 2026
Source: NVD
CVE-2026-11665 MEDIUM - 4.3

Out of bounds read in Dawn in Google Chrome on Windows prior to 149.0.7827.103 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)

Vendor: Google
Product: Chrome
Published: Jun 09, 2026
Source: NVD
CVE-2026-11658 MEDIUM - 6.5

Insufficient validation of untrusted input in Extensions in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: High)

Vendor: Google
Product: Chrome
Published: Jun 09, 2026
Source: NVD
CVE-2026-11653 MEDIUM - 6.5

Inappropriate implementation in Extensions in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: High)

Vendor: Google
Product: Chrome
Published: Jun 09, 2026
Source: NVD
CVE-2026-11628 MEDIUM - 6.8

Use after free in Ozone in Google Chrome prior to 149.0.7827.103 allowed a local attacker to potentially exploit heap corruption via physical access to the device. (Chromium security severity: Critical)

Vendor: Google
Product: Chrome
Published: Jun 09, 2026
Source: NVD
CVE-2026-47734 MEDIUM - 5.7

Dulwich is a pure-Python implementation of the Git file formats and protocols. Starting in version 0.1.0 and prior to version 1.2.5, a client with push access could push a tiny crafted thin pack (~174 bytes) whose delta header declares a huge dest_size. When dulwich ingested it via add_thin_pack...

Vendor: pip
Product: dulwich
Published: Jun 08, 2026
Source: GitHub
CVE-2026-47721 MEDIUM - 6.3

FUXA's scheduler API missing admin check enables operator-to-admin escalation via scheduled device actions

Vendor: npm
Product: fuxa-server
Published: Jun 08, 2026
Source: GitHub
CVE-2026-47720 MEDIUM - 5.3

FUXA has SQL Injection in its TDengine DAQ connector via backslash bypass of escapeTdString

Vendor: npm
Product: fuxa-server
Published: Jun 08, 2026
Source: GitHub
CVE-2026-47693 MEDIUM - 6.9

Poweradmin: CSV Injection in log export endpoints allows formula execution in spreadsheet applications

Vendor: composer
Product: poweradmin/poweradmin
Published: Jun 08, 2026
Source: GitHub
CVE-2026-47244 MEDIUM - 5.3

Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, DefaultHttp2Connection.DefaultEndpoint initialises maxActiveStreams/maxStreams to Integer.MAX_VALUE, and Http2Settings never inserts SETTINGS_MAX_CONCURRENT_STR...

Vendor: maven
Product: io.netty:netty-codec-http2
Published: Jun 08, 2026
Source: GitHub
CVE-2026-45673 MEDIUM - 6.8

Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, Netty's DNS resolver uses a predictable PRNG for generating DNS transaction IDs and defaults to a static UDP source port. This combination reduces the entr...

Vendor: maven
Product: io.netty:netty-resolver-dns
Published: Jun 08, 2026
Source: GitHub
CVE-2026-45536 MEDIUM - 4.0

Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, netty_unix_socket_recvFd sets msg_control to `char control[CMSG_SPACE(sizeof(int))]` (line 940) โ€” 24 bytes on 64-bit Linux. A peer-sent SCM_RIGHTS cmsg carrying...

Vendor: maven
Product: io.netty:netty-transport-native-epoll
Published: Jun 08, 2026
Source: GitHub
CVE-2026-11585 MEDIUM - 6.3

A vulnerability was determined in CodeAstro Student Attendance Management System 1.0. Affected is an unknown function of the file /attendance-php/Admin/createClassArms.php. This manipulation of the argument classId causes sql injection. The attack can be initiated remotely. The exploit has been publ...

Vendor: CodeAstro
Product: Student Attendance Management System
Published: Jun 08, 2026
Source: NVD

Namespace attributes are not encoded correctly during HTML serialization. This allows bypassing the cross-site scripting prevention mechanism of typo3/html-sanitizer before version 2.3.2.

Vendor: TYPO3
Product: HTML Sanitizer
Published: Jun 08, 2026
Source: NVD
CVE-2026-11584 MEDIUM - 6.3

A vulnerability was found in CodeAstro Student Attendance Management System 1.0. This impacts an unknown function of the file /attendance-php/Admin/createClass.php?action=edit. The manipulation of the argument ID results in sql injection. It is possible to launch the attack remotely. The exploit has...

Vendor: CodeAstro
Product: Student Attendance Management System
Published: Jun 08, 2026
Source: NVD
CVE-2026-11583 MEDIUM - 6.3

A vulnerability has been found in CodeAstro Student Attendance Management System 1.0. This affects an unknown function of the file /attendance-php/Admin/createClass.php. The manipulation of the argument className leads to sql injection. It is possible to initiate the attack remotely. The exploit has...

Vendor: CodeAstro
Product: Student Attendance Management System
Published: Jun 08, 2026
Source: NVD