Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
24801
Total
1759
Critical
7594
High
7792
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-55790 | UNKNOWN | — | Craft CMS is a content management system (CMS). In versions 5.0.0-RC1 through 5.9.22 and 4.0.0-RC1 through 4.17.15, an attacker with only a GitHub account can … | Jul 01, 2026 |
| CVE-2026-50284 | UNKNOWN | — | Craft CMS is a content management system (CMS). In versions 5.0.0-RC1 through 5.9.21 and 4.0.0-RC1 through 4.17.14, theAssetsController::actionDeleteFolder() only requires the deleteAssets:<volume-uid> permission for the … | Jul 01, 2026 |
| CVE-2026-50283 | UNKNOWN | — | Craft CMS is a content management system (CMS). Versions 5.0.0-RC1 through 5.9.20, and 4.0.0-RC1 through 4.17.13 contain an authorization issue in the AssetsController::actionReplaceFile that can … | Jul 01, 2026 |
| CVE-2026-14440 | MEDIUM | 6.8 | Description: To issue and renew TLS certificates on behalf of customers, Cloudflare's Universal SSL feature automatically manages the CAA RRset for the customer's zone. This … | Jul 01, 2026 |
| CVE-2026-14439 | UNKNOWN | — | A path traversal vulnerability exists in the Git Service component shared by Altium Enterprise Server and Altium 365. The service accepts a sequence of post-clone … | Jul 01, 2026 |
| CVE-2026-14432 | HIGH | 8.8 | Use after free in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted … | Jul 01, 2026 |
| CVE-2026-14431 | HIGH | 8.8 | Type Confusion in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML … | Jul 01, 2026 |
| CVE-2026-14430 | HIGH | 8.8 | Integer overflow in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML … | Jul 01, 2026 |
| CVE-2026-14429 | HIGH | 8.3 | Insufficient validation of untrusted input in Skia in Google Chrome prior to 150.0.7871.46 allowed a remote attacker who had compromised the renderer process to potentially … | Jul 01, 2026 |
| CVE-2026-14428 | HIGH | 8.3 | Insufficient validation of untrusted input in Dawn in Google Chrome on Android prior to 150.0.7871.46 allowed a remote attacker who had compromised the renderer process … | Jul 01, 2026 |
| CVE-2026-14427 | HIGH | 8.3 | Heap buffer overflow in Skia in Google Chrome prior to 150.0.7871.46 allowed a remote attacker who had compromised the renderer process to potentially perform a … | Jul 01, 2026 |
| CVE-2026-14426 | HIGH | 7.5 | Use after free in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker who convinced a user to engage in specific UI gestures … | Jul 01, 2026 |
| CVE-2026-14425 | CRITICAL | 9.6 | Use after free in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML … | Jul 01, 2026 |
| CVE-2026-14424 | CRITICAL | 9.6 | Use after free in Dawn in Google Chrome on Mac prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a … | Jul 01, 2026 |
| CVE-2026-14423 | CRITICAL | 9.6 | Type Confusion in Tint in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. … | Jul 01, 2026 |
| CVE-2026-14422 | HIGH | 8.8 | Out of bounds read and write in Tint in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform out of bounds memory … | Jul 01, 2026 |
| CVE-2026-14421 | MEDIUM | 6.5 | Uninitialized Use in Dawn in Google Chrome on ChromeOS prior to 150.0.7871.46 allowed a remote attacker to obtain potentially sensitive information from process memory via … | Jul 01, 2026 |
| CVE-2026-14420 | CRITICAL | 9.6 | Out of bounds read and write in Dawn in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via … | Jul 01, 2026 |
| CVE-2026-14419 | CRITICAL | 9.6 | Use after free in Skia in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML … | Jul 01, 2026 |
| CVE-2026-14418 | MEDIUM | 4.3 | Uninitialized Use in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security … | Jul 01, 2026 |
| CVE-2026-14417 | CRITICAL | 9.6 | Use after free in Dawn in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML … | Jul 01, 2026 |
| CVE-2026-14416 | CRITICAL | 9.6 | Out of bounds read in Dawn in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted … | Jul 01, 2026 |
| CVE-2026-14415 | HIGH | 8.8 | Inappropriate implementation in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker who convinced a user to engage in specific UI gestures to … | Jul 01, 2026 |
| CVE-2026-14414 | MEDIUM | 5.3 | Insufficient validation of untrusted input in Skia in Google Chrome prior to 150.0.7871.46 allowed a remote attacker who had compromised the renderer process to obtain … | Jul 01, 2026 |
| CVE-2026-14413 | HIGH | 8.3 | Uninitialized Use in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox … | Jul 01, 2026 |