Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
26401
Total
1955
Critical
7975
High
8228
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-45171 | UNKNOWN | — | Incomplete input validation and improperly configured folder permissions within Idira Privileged Session Manager (PSM) versions prior to 15.0.3, 14.6.3, 14.2.5, and 14.0.5, an authenticated, low-privileged … | Jun 11, 2026 |
| CVE-2026-44890 | HIGH | 7.5 | Netty is a network application framework for development of protocol servers and clients. In netty-codec-redis prior to versions 4.1.135.Final and 4.2.15.Final, an attacker can cause … | Jun 11, 2026 |
| CVE-2026-44250 | HIGH | 7.5 | Netty is a network application framework for development of protocol servers and clients. In netty-codec-redis prior to versions 4.1.135.Final and 4.2.15.Final, an attacker can cause … | Jun 11, 2026 |
| CVE-2026-44249 | HIGH | 8.1 | Netty is a network application framework for development of protocol servers and clients. In netty-handler prior to versions 4.1.135.Final and 4.2.15.Final, an attacker can bypass … | Jun 11, 2026 |
| CVE-2026-42653 | HIGH | 7.1 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in iova.Mihai SliceWP allows Stored XSS. This issue affects SliceWP: from n/a through 1.2.6. | Jun 11, 2026 |
| CVE-2026-42647 | CRITICAL | 9.3 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Beardev JoomSport allows Blind SQL Injection. This issue affects JoomSport: from … | Jun 11, 2026 |
| CVE-2026-39494 | CRITICAL | 9.3 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WBW Plugins Product Filter by WBW allows Blind SQL Injection. This … | Jun 11, 2026 |
| CVE-2026-12035 | HIGH | 8.8 | Use after free in Views in Google Chrome on Windows prior to 149.0.7827.115 allowed a remote attacker to potentially exploit heap corruption via a crafted … | Jun 11, 2026 |
| CVE-2026-12034 | HIGH | 8.3 | Insufficient validation of untrusted input in Linux Toolkit Theming in Google Chrome on Linux prior to 149.0.7827.115 allowed a remote attacker who had compromised the … | Jun 11, 2026 |
| CVE-2026-12033 | MEDIUM | 5.3 | Out of bounds read in VideoCapture in Google Chrome prior to 149.0.7827.115 allowed a remote attacker who had compromised the GPU process to obtain potentially … | Jun 11, 2026 |
| CVE-2026-12032 | LOW | 3.1 | Inappropriate implementation in Passwords in Google Chrome on Android prior to 149.0.7827.115 allowed a remote attacker who had compromised the renderer process to bypass site … | Jun 11, 2026 |
| CVE-2026-12031 | HIGH | 8.3 | Inappropriate implementation in Views in Google Chrome on Windows prior to 149.0.7827.115 allowed a remote attacker who had compromised the renderer process to potentially perform … | Jun 11, 2026 |
| CVE-2026-12030 | HIGH | 8.3 | Out of bounds write in GPU in Google Chrome on Android prior to 149.0.7827.115 allowed a remote attacker who had compromised the renderer process to … | Jun 11, 2026 |
| CVE-2026-12029 | HIGH | 8.3 | Use after free in Video in Google Chrome on Windows prior to 149.0.7827.115 allowed a remote attacker who had compromised the renderer process to potentially … | Jun 11, 2026 |
| CVE-2026-12028 | HIGH | 8.3 | Use after free in GPU in Google Chrome on Android prior to 149.0.7827.115 allowed a remote attacker who had compromised the renderer process to potentially … | Jun 11, 2026 |
| CVE-2026-12027 | CRITICAL | 9.6 | Inappropriate implementation in Headless in Google Chrome prior to 149.0.7827.115 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox … | Jun 11, 2026 |
| CVE-2026-12026 | UNKNOWN | — | Out of bounds read in Video in Google Chrome on ChromeOS prior to 149.0.7827.115 allowed a remote attacker who had compromised the renderer process to … | Jun 11, 2026 |
| CVE-2026-12025 | MEDIUM | 5.3 | Insufficient validation of untrusted input in Network in Google Chrome prior to 149.0.7827.115 allowed a remote attacker who had compromised the renderer process to leak … | Jun 11, 2026 |
| CVE-2026-12024 | MEDIUM | 6.5 | Insufficient policy enforcement in DevTools in Google Chrome prior to 149.0.7827.115 allowed a remote attacker to bypass same origin policy via a crafted HTML page. … | Jun 11, 2026 |
| CVE-2026-12023 | HIGH | 8.3 | Use after free in GPU in Google Chrome on Mac prior to 149.0.7827.115 allowed a remote attacker who had compromised the renderer process to potentially … | Jun 11, 2026 |
| CVE-2026-12022 | HIGH | 8.3 | Race in Safe Browsing in Google Chrome on Mac prior to 149.0.7827.115 allowed a remote attacker who had compromised the renderer process to potentially perform … | Jun 11, 2026 |
| CVE-2026-12020 | HIGH | 8.8 | Use after free in Autofill in Google Chrome on Mac prior to 149.0.7827.115 allowed a remote attacker to potentially exploit heap corruption via a crafted … | Jun 11, 2026 |
| CVE-2026-12019 | HIGH | 8.3 | Heap buffer overflow in Codecs in Google Chrome on Linux and ChromeOS prior to 149.0.7827.115 allowed a remote attacker who had compromised the renderer process … | Jun 11, 2026 |
| CVE-2026-12018 | HIGH | 8.8 | Inappropriate implementation in Mojo in Google Chrome on Windows prior to 149.0.7827.115 allowed a local attacker to perform OS-level privilege escalation via a malicious file. … | Jun 11, 2026 |
| CVE-2026-12017 | LOW | 3.1 | Inappropriate implementation in Extensions in Google Chrome prior to 149.0.7827.115 allowed a remote attacker who had compromised the renderer process to bypass site isolation via … | Jun 11, 2026 |