Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

51698
Total
4098
Critical
15338
High
14987
Medium
CVE ID Severity Score Description Published
CVE-2026-63145 MEDIUM 4.3 Incorrect Authorization (CWE-863) in Kibana can lead to integrity compromise of Machine Learning audit and notification records via Accessing Functionality Not Properly Constrained by ACLs … Jul 21, 2026
CVE-2026-63144 MEDIUM 6.5 Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to denial of service via a specially crafted search request submitted by a low-privileged authenticated user. A user … Jul 21, 2026
CVE-2026-63143 MEDIUM 4.3 Missing Authorization (CWE-862) in Kibana can lead to unauthorized information disclosure via Privilege Abuse (CAPEC-122). A user with limited feature privileges can access workflow execution … Jul 21, 2026
CVE-2026-63142 MEDIUM 5.0 Incomplete List of Disallowed Inputs (CWE-184) in Kibana can allow an authenticated attacker with access to the Reporting feature to bypass outbound request restrictions configured … Jul 21, 2026
CVE-2026-56820 HIGH 7.4 Netty is a network application framework for development of protocol servers and clients. In versions 4.2.0.Final through 4.2.15.Final and prior to 4.1.135.Final, `OcspClient` does not … Jul 21, 2026
CVE-2026-56819 HIGH 7.5 Netty is a network application framework for development of protocol servers and clients. In versions 4.2.0.Final through 4.2.15.Final and 4.1.0.Final through 4.1.135.Final, a remote unauthenticated … Jul 21, 2026
CVE-2026-56817 UNKNOWN — Netty is a network application framework for development of protocol servers and clients. In versions 4.2.0.Final through 4.2.15.Final and 4.1.0.Final through 4.1.135.Final, any caller that … Jul 21, 2026
CVE-2026-16517 LOW 2.9 A signed integer overflow vulnerability was found in libarchive's ZIP writer. In the archive_write_zip_header function in archive_write_set_format_zip.c, when ZIP encryption is enabled and the entry … Jul 21, 2026
CVE-2026-16486 MEDIUM 4.3 A vulnerability was found in SourceCodester Class and Exam Timetabling System 1.0. This affects an unknown part of the file /BSIS.php. Performing a manipulation of … Jul 21, 2026
CVE-2026-16485 MEDIUM 4.3 A vulnerability has been found in SourceCodester Class and Exam Timetabling System 1.0. Affected by this issue is some unknown functionality of the file /class.php. … Jul 21, 2026
CVE-2026-16424 CRITICAL 9.6 Use after free in GPU in Google Chrome on Android prior to 150.0.7871.182 allowed a remote attacker who had compromised the renderer process to potentially … Jul 21, 2026
CVE-2026-16423 HIGH 8.8 Use after free in UI in Google Chrome prior to 150.0.7871.182 allowed a remote attacker who convinced a user to engage in specific UI gestures … Jul 21, 2026
CVE-2026-16422 HIGH 7.5 Insufficient validation of untrusted input in Certificate in Google Chrome on Linux prior to 150.0.7871.182 allowed an attacker in a privileged network position to perform … Jul 21, 2026
CVE-2026-16421 UNKNOWN — Inappropriate implementation in WebAudio in Google Chrome prior to 150.0.7871.182 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML … Jul 21, 2026
CVE-2026-16420 UNKNOWN — Type Confusion in WebAudio in Google Chrome prior to 150.0.7871.182 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML … Jul 21, 2026
CVE-2026-16419 UNKNOWN — Out of bounds read and write in ANGLE in Google Chrome on Android prior to 150.0.7871.182 allowed a remote attacker to potentially perform a sandbox … Jul 21, 2026
CVE-2026-16418 UNKNOWN — Stack buffer overflow in V8 in Google Chrome prior to 150.0.7871.182 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted … Jul 21, 2026
CVE-2026-16417 UNKNOWN — Uninitialized Use in Skia in Google Chrome prior to 150.0.7871.182 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via … Jul 21, 2026
CVE-2026-16416 UNKNOWN — Integer overflow in Chromecast in Google Chrome prior to 150.0.7871.182 allowed a local attacker to potentially perform a sandbox escape via malicious network traffic. (Chromium … Jul 21, 2026
CVE-2026-16415 UNKNOWN — Insufficient validation of untrusted input in Extensions in Google Chrome prior to 150.0.7871.182 allowed a remote attacker to spoof the contents of the Omnibox (URL … Jul 21, 2026
CVE-2026-16414 UNKNOWN — Insufficient validation of untrusted input in Chromecast in Google Chrome prior to 150.0.7871.182 allowed a local attacker to potentially perform a sandbox escape via malicious … Jul 21, 2026
CVE-2026-16413 UNKNOWN — Out of bounds write in ANGLE in Google Chrome prior to 150.0.7871.182 allowed a remote attacker who had compromised the renderer process to potentially perform … Jul 21, 2026
CVE-2026-60394 MEDIUM 5.3 Vulnerability in Oracle GoldenGate (component: Admin Server Executable). Supported versions that are affected are 21.3-21.21 and 23.4-23.26.1. Easily exploitable vulnerability allows unauthenticated attacker with network … Jul 21, 2026
CVE-2026-60389 CRITICAL 10.0 Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable … Jul 21, 2026
CVE-2026-60388 CRITICAL 9.8 Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable … Jul 21, 2026