Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

26379
Total
1954
Critical
7969
High
8218
Medium
CVE ID Severity Score Description Published
CVE-2026-48793 HIGH 8.8 Jellyfin is an open source self hosted media server. Prior to 10.11.10, a potential FFmpeg argument injection vulnerability exists in the subtitle conversion code path. … Jun 24, 2026
CVE-2026-13038 HIGH 8.8 Use after free in Autofill in Google Chrome on Windows prior to 149.0.7827.197 allowed a remote attacker to execute arbitrary code via a crafted HTML … Jun 24, 2026
CVE-2026-13037 HIGH 7.8 Use after free in WebView in Google Chrome on Android prior to 149.0.7827.197 allowed a local attacker to execute arbitrary code inside a sandbox via … Jun 24, 2026
CVE-2026-13036 HIGH 8.8 Use after free in Blink in Google Chrome prior to 149.0.7827.197 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted … Jun 24, 2026
CVE-2026-13035 HIGH 8.8 Use after free in Bluetooth in Google Chrome on Mac prior to 149.0.7827.197 allowed a remote attacker to execute arbitrary code via a malicious peripheral. … Jun 24, 2026
CVE-2026-13034 MEDIUM 4.7 Inappropriate implementation in Passwords in Google Chrome prior to 149.0.7827.197 allowed a remote attacker who had compromised the renderer process to bypass site isolation via … Jun 24, 2026
CVE-2026-13033 HIGH 8.8 Out of bounds read and write in Blink>InterestGroups in Google Chrome prior to 149.0.7827.197 allowed a remote attacker to execute arbitrary code via a crafted … Jun 24, 2026
CVE-2026-13032 CRITICAL 9.6 Use after free in WebGL in Google Chrome on Android prior to 149.0.7827.197 allowed a remote attacker to potentially perform a sandbox escape via a … Jun 24, 2026
CVE-2026-13031 HIGH 8.8 Use after free in Blink in Google Chrome prior to 149.0.7827.197 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted … Jun 24, 2026
CVE-2026-13030 MEDIUM 5.3 Uninitialized Use in GPU in Google Chrome on Android prior to 149.0.7827.197 allowed a remote attacker to obtain potentially sensitive information from process memory via … Jun 24, 2026
CVE-2026-13029 HIGH 7.5 Use after free in Web Authentication in Google Chrome prior to 149.0.7827.197 allowed an attacker who convinced a user to install a malicious extension to … Jun 24, 2026
CVE-2026-13028 CRITICAL 9.6 Use after free in WebGL in Google Chrome on Android prior to 149.0.7827.197 allowed a remote attacker to potentially perform a sandbox escape via a … Jun 24, 2026
CVE-2026-13027 HIGH 8.8 Use after free in FileSystem in Google Chrome prior to 149.0.7827.197 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. … Jun 24, 2026
CVE-2026-13026 HIGH 8.8 Use after free in Digital Credentials in Google Chrome on Mac prior to 149.0.7827.197 allowed a remote attacker to potentially exploit heap corruption via a … Jun 24, 2026
CVE-2026-13025 HIGH 8.3 Race in DevTools in Google Chrome prior to 149.0.7827.197 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape … Jun 24, 2026
CVE-2026-13024 MEDIUM 4.2 Insufficient validation of untrusted input in Navigation in Google Chrome prior to 149.0.7827.197 allowed a remote attacker who had compromised the renderer process to bypass … Jun 24, 2026
CVE-2026-13023 MEDIUM 5.3 Uninitialized Use in GPU in Google Chrome prior to 149.0.7827.197 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information … Jun 24, 2026
CVE-2026-13022 UNKNOWN Inappropriate implementation in Autofill in Google Chrome prior to 149.0.7827.197 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via … Jun 24, 2026
CVE-2026-13021 MEDIUM 4.3 Inappropriate implementation in DeviceBoundSessionCredentials in Google Chrome prior to 149.0.7827.197 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium … Jun 24, 2026
CVE-2026-12760 UNKNOWN A denial-of-service (DoS) vulnerability has been identified in Tapo C200 v3 in the network packet handling logic due to improper handling of IPv4 fragmented packets. … Jun 24, 2026
CVE-2025-60471 MEDIUM 5.5 A use-after-free in the gf_filter_pid_reconfigure_task_discard function (/filter_core/filter_pid.c) of GPAC Project/MP4Box before 26.02.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted … Jun 24, 2026
CVE-2026-55611 NONE AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. From 1.11.1 until 1.14.1, userId/workspaceId … Jun 24, 2026
CVE-2026-54699 HIGH 7.7 Warp is an agentic development environment. From 0.2024.03.12.08.02.stable_01 until 0.2026.05.06.15.42.stable_01, Warp contains an OS command injection vulnerability in the WSL URL-opening fallback. When Warp is … Jun 24, 2026
CVE-2026-54686 MEDIUM 4.3 Warp is an agentic development environment. From 0.2021.04.25.23.05.stable_00 until 0.2026.05.06.15.42.stable_01, Warp accepted certain state-mutating terminal lifecycle hooks from the PTY stream without verifying that the … Jun 24, 2026
CVE-2026-49851 UNKNOWN Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.3.0, Mistune is vulnerable to a CPU exhaustion DoS due to superlinear (approximately … Jun 24, 2026