Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
26101
Total
1954
Critical
7968
High
8216
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-13036 | HIGH | 8.8 | Use after free in Blink in Google Chrome prior to 149.0.7827.197 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted … | Jun 24, 2026 |
| CVE-2026-13035 | HIGH | 8.8 | Use after free in Bluetooth in Google Chrome on Mac prior to 149.0.7827.197 allowed a remote attacker to execute arbitrary code via a malicious peripheral. … | Jun 24, 2026 |
| CVE-2026-13034 | MEDIUM | 4.7 | Inappropriate implementation in Passwords in Google Chrome prior to 149.0.7827.197 allowed a remote attacker who had compromised the renderer process to bypass site isolation via … | Jun 24, 2026 |
| CVE-2026-13033 | HIGH | 8.8 | Out of bounds read and write in Blink>InterestGroups in Google Chrome prior to 149.0.7827.197 allowed a remote attacker to execute arbitrary code via a crafted … | Jun 24, 2026 |
| CVE-2026-13032 | CRITICAL | 9.6 | Use after free in WebGL in Google Chrome on Android prior to 149.0.7827.197 allowed a remote attacker to potentially perform a sandbox escape via a … | Jun 24, 2026 |
| CVE-2026-13031 | HIGH | 8.8 | Use after free in Blink in Google Chrome prior to 149.0.7827.197 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted … | Jun 24, 2026 |
| CVE-2026-13030 | MEDIUM | 5.3 | Uninitialized Use in GPU in Google Chrome on Android prior to 149.0.7827.197 allowed a remote attacker to obtain potentially sensitive information from process memory via … | Jun 24, 2026 |
| CVE-2026-13029 | HIGH | 7.5 | Use after free in Web Authentication in Google Chrome prior to 149.0.7827.197 allowed an attacker who convinced a user to install a malicious extension to … | Jun 24, 2026 |
| CVE-2026-13028 | CRITICAL | 9.6 | Use after free in WebGL in Google Chrome on Android prior to 149.0.7827.197 allowed a remote attacker to potentially perform a sandbox escape via a … | Jun 24, 2026 |
| CVE-2026-13027 | HIGH | 8.8 | Use after free in FileSystem in Google Chrome prior to 149.0.7827.197 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. … | Jun 24, 2026 |
| CVE-2026-13026 | HIGH | 8.8 | Use after free in Digital Credentials in Google Chrome on Mac prior to 149.0.7827.197 allowed a remote attacker to potentially exploit heap corruption via a … | Jun 24, 2026 |
| CVE-2026-13025 | HIGH | 8.3 | Race in DevTools in Google Chrome prior to 149.0.7827.197 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape … | Jun 24, 2026 |
| CVE-2026-13024 | MEDIUM | 4.2 | Insufficient validation of untrusted input in Navigation in Google Chrome prior to 149.0.7827.197 allowed a remote attacker who had compromised the renderer process to bypass … | Jun 24, 2026 |
| CVE-2026-13023 | MEDIUM | 5.3 | Uninitialized Use in GPU in Google Chrome prior to 149.0.7827.197 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information … | Jun 24, 2026 |
| CVE-2026-13022 | UNKNOWN | — | Inappropriate implementation in Autofill in Google Chrome prior to 149.0.7827.197 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via … | Jun 24, 2026 |
| CVE-2026-13021 | MEDIUM | 4.3 | Inappropriate implementation in DeviceBoundSessionCredentials in Google Chrome prior to 149.0.7827.197 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium … | Jun 24, 2026 |
| CVE-2026-12760 | UNKNOWN | — | A denial-of-service (DoS) vulnerability has been identified in Tapo C200 v3 in the network packet handling logic due to improper handling of IPv4 fragmented packets. … | Jun 24, 2026 |
| CVE-2025-60471 | MEDIUM | 5.5 | A use-after-free in the gf_filter_pid_reconfigure_task_discard function (/filter_core/filter_pid.c) of GPAC Project/MP4Box before 26.02.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted … | Jun 24, 2026 |
| CVE-2026-55611 | NONE | — | AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. From 1.11.1 until 1.14.1, userId/workspaceId … | Jun 24, 2026 |
| CVE-2026-54699 | HIGH | 7.7 | Warp is an agentic development environment. From 0.2024.03.12.08.02.stable_01 until 0.2026.05.06.15.42.stable_01, Warp contains an OS command injection vulnerability in the WSL URL-opening fallback. When Warp is … | Jun 24, 2026 |
| CVE-2026-54686 | MEDIUM | 4.3 | Warp is an agentic development environment. From 0.2021.04.25.23.05.stable_00 until 0.2026.05.06.15.42.stable_01, Warp accepted certain state-mutating terminal lifecycle hooks from the PTY stream without verifying that the … | Jun 24, 2026 |
| CVE-2026-49851 | UNKNOWN | — | Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.3.0, Mistune is vulnerable to a CPU exhaustion DoS due to superlinear (approximately … | Jun 24, 2026 |
| CVE-2026-48789 | MEDIUM | 4.3 | AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. Prior to 1.13.0, on Windows, … | Jun 24, 2026 |
| CVE-2026-48732 | HIGH | 8.8 | Warp is an agentic development environment. From 0.2023.03.21.08.02.stable_00 until 0.2026.05.06.15.42.stable_01, Warp contains a command injection issue in the legacy SSH background command path. Warp used … | Jun 24, 2026 |
| CVE-2026-48731 | HIGH | 7.8 | Warp is an agentic development environment. From 0.2024.02.20.08.01.stable_01 until 0.2026.05.06.15.42.stable_01, Warp contains a command injection issue in the Linux external editor launcher. Warp expanded freedesktop … | Jun 24, 2026 |