Total CVEs

138,591

Critical Severity

3,578

High Severity

12,841

Last 7 Days

1,647
Quick preset (or use dates below)
Clear Filters
Showing 1,501 - 1,520 of 12,841 CVEs
CVE-2026-11645 HIGH - 8.8

Out of bounds read and write in V8 in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

Vendor: Google
Product: Chrome
Published: Jun 09, 2026
Source: NVD
CVE-2026-11644 HIGH - 7.5

Use after free in Views in Google Chrome on Linux prior to 149.0.7827.103 allowed an attacker who convinced a user to install a malicious extension to execute arbitrary code via a crafted Chrome Extension. (Chromium security severity: Critical)

Vendor: Google
Product: Chrome
Published: Jun 09, 2026
Source: NVD
CVE-2026-11643 HIGH - 8.1

Use after free in Proxy in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code via malicious network traffic. (Chromium security severity: Critical)

Vendor: Google
Product: Chrome
Published: Jun 09, 2026
Source: NVD
CVE-2026-11642 HIGH - 8.3

Use after free in Web Apps in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)

Vendor: Google
Product: Chrome
Published: Jun 09, 2026
Source: NVD
CVE-2026-11641 HIGH - 7.5

Use after free in Bluetooth in Google Chrome on Windows prior to 149.0.7827.103 allowed a remote attacker who convinced a user to engage in specific UI gestures to execute arbitrary code via a crafted HTML page. (Chromium security severity: Critical)

Vendor: Google
Product: Chrome
Published: Jun 09, 2026
Source: NVD
CVE-2026-11640 HIGH - 8.3

Integer overflow in libyuv in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)

Vendor: Google
Product: Chrome
Published: Jun 09, 2026
Source: NVD
CVE-2026-11639 HIGH - 7.5

Use after free in Compositing in Google Chrome on Mac prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: Critical)

Vendor: Google
Product: Chrome
Published: Jun 09, 2026
Source: NVD
CVE-2026-11637 HIGH - 8.8

Use after free in Views in Google Chrome on Mac prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: Critical)

Vendor: Google
Product: Chrome
Published: Jun 09, 2026
Source: NVD
CVE-2026-11636 HIGH - 7.5

Use after free in Autofill in Google Chrome on Windows prior to 149.0.7827.103 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)

Vendor: Google
Product: Chrome
Published: Jun 09, 2026
Source: NVD
CVE-2026-11635 HIGH - 8.3

Use after free in Bluetooth in Google Chrome on Mac prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)

Vendor: Google
Product: Chrome
Published: Jun 09, 2026
Source: NVD
CVE-2026-11633 HIGH - 8.8

Use after free in Bluetooth in Google Chrome on Mac prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code via a malicious peripheral. (Chromium security severity: Critical)

Vendor: Google
Product: Chrome
Published: Jun 09, 2026
Source: NVD
CVE-2026-11632 HIGH - 7.5

Use after free in TabStrip in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who convinced a user to engage in specific UI gestures to execute arbitrary code via a crafted HTML page. (Chromium security severity: Critical)

Vendor: Google
Product: Chrome
Published: Jun 09, 2026
Source: NVD
CVE-2026-11631 HIGH - 8.3

Use after free in Aura in Google Chrome on Windows prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)

Vendor: Google
Product: Chrome
Published: Jun 09, 2026
Source: NVD
CVE-2026-11630 HIGH - 8.8

Use after free in File Input in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)

Vendor: Google
Product: Chrome
Published: Jun 09, 2026
Source: NVD
CVE-2026-11629 HIGH - 8.8

Use after free in Ozone in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)

Vendor: Google
Product: Chrome
Published: Jun 09, 2026
Source: NVD
CVE-2026-47737 HIGH - 7.5

Puma PROXY Protocol v1 Accepts Repeated Protocol Headers on Persistent Connections

Vendor: rubygems
Product: puma
Published: Jun 09, 2026
Source: GitHub
CVE-2026-47736 HIGH - 7.5

Puma PROXY Protocol v1 Parser Allows Remote Memory Exhaustion

Vendor: rubygems
Product: puma
Published: Jun 08, 2026
Source: GitHub

Arc has an authenticated arbitrary local-file read via DuckDB I/O functions that bypasses RBAC table-level checks

Vendor: go
Product: github.com/basekick-labs/arc
Published: Jun 08, 2026
Source: GitHub

nebula-mesh: GET /api/v1/audit-log discloses all entries to any operator

Vendor: go
Product: github.com/juev/nebula-mesh
Published: Jun 08, 2026
Source: GitHub

nebula-mesh's web UI lacks CSRF tokens on /ui/* mutating endpoints

Vendor: go
Product: github.com/juev/nebula-mesh
Published: Jun 08, 2026
Source: GitHub