Total CVEs

137,266

Critical Severity

3,307

High Severity

12,261

Last 7 Days

1,334
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 1,281 - 1,300 of 11,958 CVEs
CVE-2026-10887 HIGH - 8.1

Use after free in Chromoting in Google Chrome on Mac prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code via malicious network traffic. (Chromium security severity: Critical)

Vendor: Google
Product: Chrome
Published: Jun 04, 2026
Source: NVD
CVE-2026-10885 HIGH - 8.8

Use after free in Chrome for iOS in Google Chrome on iOS prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: Critical)

Vendor: Google
Product: Chrome
Published: Jun 04, 2026
Source: NVD
CVE-2026-10884 HIGH - 8.3

Use after free in Chromecast in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)

Vendor: Google
Product: Chrome
Published: Jun 04, 2026
Source: NVD
CVE-2026-10883 HIGH - 8.8

Type Confusion in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)

Vendor: Google
Product: Chrome
Published: Jun 04, 2026
Source: NVD
CVE-2026-10882 HIGH - 8.8

Use after free in Network in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: Critical)

Vendor: Google
Product: Chrome
Published: Jun 04, 2026
Source: NVD
CVE-2026-10873 HIGH - 7.2

A vulnerability was determined in Shibby Tomato 1.28.0000. Impacted is the function rstats_path of the file /bin/rstats of the component Web UI. Executing a manipulation can lead to os command injection. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized...

Vendor: Shibby
Product: Tomato
Published: Jun 04, 2026
Source: NVD
CVE-2026-10872 HIGH - 7.2

A vulnerability was found in Shibby Tomato 1.28.0000. This issue affects the function start_vpnserver of the file /sbin/rc of the component Web UI. Performing a manipulation results in os command injection. The attack can be initiated remotely. The exploit has been made public and could be used. Thi...

Vendor: Shibby
Product: Tomato
Published: Jun 04, 2026
Source: NVD
CVE-2025-8873 HIGH - 7.5

On affected platforms running Arista EOS with IPsec configured, a specially crafted packet can cause the dataplane to stop processing all IPsec traffic. The control plane may detect this condition, and attempt to reset the IPsec processing pipeline. After reset traffic may not resume being processed...

Published: Jun 04, 2026
Source: NVD
CVE-2026-10871 HIGH - 7.2

A vulnerability has been found in Shibby Tomato 1.28.0000. This vulnerability affects the function start_6rd_tunnel of the file /sbin/rc of the component Web UI. Such manipulation of the argument ipv6_6rd_borderrelay leads to os command injection. It is possible to launch the attack remotely. The ex...

Vendor: Shibby
Product: Tomato
Published: Jun 04, 2026
Source: NVD
CVE-2026-10870 HIGH - 7.2

A flaw has been found in Shibby Tomato 1.28.0000. This affects the function start_dhcpc of the file /sbin/rc of the component Web UI. This manipulation causes os command injection. It is possible to initiate the attack remotely. The exploit has been published and may be used. This project is superse...

Vendor: Shibby
Product: Tomato
Published: Jun 04, 2026
Source: NVD
CVE-2026-41518 HIGH - 7.6

Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create charts. In versions 4.9.0 through 5.0.0, an authenticated user with project-editor permissions can store arbitrary HTML/JavaScript in the `ChartDatasetConfig.legend` field. The payl...

Vendor: chartbrew
Product: chartbrew
Published: Jun 04, 2026
Source: NVD

WWBN AVideo: Stored XSS via autoEvalCodeOnHTML Bypass in MessageSQLite WebSocket Handler (CVE-2026-43874 Bypass)

Vendor: composer
Product: wwbn/avideo
Published: Jun 04, 2026
Source: GitHub
CVE-2026-50292 HIGH - 7.4

In libinput before 1.30.4 and 1.31.x before 1.31.3, libinput-device-group unescaped phys output can inject udev properties leading to arbitrary root code execution

Vendor: freedesktop
Product: libinput
Published: Jun 04, 2026
Source: NVD
CVE-2026-25551 HIGH - 7.8

Seagull Software BarTender 2021 R1 through 12.0.1ย contains an insecure deserialization vulnerability that allows low-privileged local users to escalate privileges. The DataServiceSingleton .NET Remoting endpoint is bound to localhost on TCP port 7375 via BtSystem.Service.exe, limiting the attack sur...

Vendor: Seagull Software, LLC.
Product: BarTender 2021
Published: Jun 04, 2026
Source: NVD
CVE-2026-10796 HIGH - 7.5

nvm (Node Version Manager) through 0.40.4 executes arbitrary commands from version strings supplied by the configured Node.js/io.js mirror. Commands such as `nvm install` read the available versions from the mirror's index.tab and use the selected version, without sanitization, to build downloa...

Vendor: nvm-sh
Product: nvm
Published: Jun 04, 2026
Source: NVD
CVE-2025-69755 HIGH - 8.2

An issue in Neterbit NW-431F Router vNW-431F-20241014-IR03 allows a remote attacker to obtain sensitive information and execute arbitrary code via a crafted command to the at_command.asp interface

Published: Jun 04, 2026
Source: NVD
CVE-2025-67448 HIGH - 7.1

The SMS module in Neterbit NW-431F Router 20241014-IR03 and before is vulnerable to stored XSS. The application does not properly sanitize user input in SMS messages before storing and displaying them. An attacker can send an SMS containing a malicious XSS payload, which will be executed in the cont...

Published: Jun 04, 2026
Source: NVD
CVE-2026-49942 HIGH - 7.3

Net::CIDR::Set versions through 0.20 for Perl did not validate network masks. The mask portion of a network mask could contain Unicode digits such as the Arabic-Indic One (U+0661), or non-digits, which were ignored. This could allow network masks to accept larger networks. Leading zeros were als...

Vendor: RRWO
Product: Net::CIDR::Set
Published: Jun 04, 2026
Source: NVD
CVE-2026-49941 HIGH - 7.5

Net::CIDR::Set versions through 0.20 for Perl did not validate IP addresses. The add method called the _encode method to parse addresses. If the addresses did not look like netmasks or network ranges, then they were assumed to single IP addresses and passed back to itself as a 32-bit or 128-bit net...

Vendor: RRWO
Product: Net::CIDR::Set
Published: Jun 04, 2026
Source: NVD
CVE-2026-46741 HIGH - 7.5

Etsy::StatsD versions through 1.002002 for Perl allow metric injections. The metric names and values are not checked for newlines, colons or pipes. Metrics generated from untrusted sources could inject additional statsd metrics. Note that the git repository contains an unreleased version with the ...

Vendor: SANBEG
Product: Etsy::StatsD
Published: Jun 04, 2026
Source: NVD