Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

28561
Total
2193
Critical
8548
High
8866
Medium
CVE ID Severity Score Description Published
CVE-2026-9121 HIGH 8.8 Out of bounds read in GPU in Google Chrome on prior to 148.0.7778.179 allowed a remote attacker to potentially exploit heap corruption via a crafted … May 20, 2026
CVE-2026-9120 HIGH 8.8 Use after free in WebRTC in Google Chrome prior to 148.0.7778.179 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium … May 20, 2026
CVE-2026-9119 HIGH 8.8 Heap buffer overflow in WebRTC in Google Chrome on prior to 148.0.7778.179 allowed a remote attacker to execute arbitrary code inside a sandbox via a … May 20, 2026
CVE-2026-9118 HIGH 8.8 Use after free in XR in Google Chrome on Windows prior to 148.0.7778.179 allowed a remote attacker to execute arbitrary code via a crafted HTML … May 20, 2026
CVE-2026-9117 HIGH 7.5 Type Confusion in GFX in Google Chrome on Linux, ChromeOS prior to 148.0.7778.179 allowed a remote attacker who had compromised the renderer process to potentially … May 20, 2026
CVE-2026-9116 MEDIUM 4.3 Insufficient policy enforcement in ServiceWorker in Google Chrome on prior to 148.0.7778.179 allowed a remote attacker to leak cross-origin data via a crafted HTML page. … May 20, 2026
CVE-2026-9115 MEDIUM 4.3 Insufficient policy enforcement in Service Worker in Google Chrome on prior to 148.0.7778.179 allowed a remote attacker to bypass same origin policy via a crafted … May 20, 2026
CVE-2026-9114 HIGH 8.8 Use after free in QUIC in Google Chrome on prior to 148.0.7778.179 allowed a remote attacker to execute arbitrary code inside a sandbox via malicious … May 20, 2026
CVE-2026-9113 MEDIUM 4.3 Out of bounds read in GPU in Google Chrome on Mac prior to 148.0.7778.179 allowed a remote attacker to perform an out of bounds memory … May 20, 2026
CVE-2026-9112 HIGH 8.8 Use after free in GPU in Google Chrome on Windows prior to 148.0.7778.179 allowed a remote attacker to execute arbitrary code inside a sandbox via … May 20, 2026
CVE-2026-9111 HIGH 8.8 Use after free in WebRTC in Google Chrome on Linux prior to 148.0.7778.179 allowed a remote attacker to execute arbitrary code via a crafted HTML … May 20, 2026
CVE-2026-9110 MEDIUM 4.2 Inappropriate implementation in UI in Google Chrome on Windows prior to 148.0.7778.179 allowed a remote attacker who had compromised the renderer process to perform UI … May 20, 2026
CVE-2026-9102 UNKNOWN A path traversal vulnerability exists in the Altium Enterprise Server ComparisonService due to missing filename sanitization in the Gerber file upload APIs. A regular authenticated … May 20, 2026
CVE-2026-9082 MEDIUM 6.5 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Drupal Drupal core allows SQL Injection. This issue affects Drupal core: … May 20, 2026
CVE-2026-47099 MEDIUM 6.1 TeleJSON prior to 6.0.0 contains a DOM-based cross-site scripting vulnerability in the parse() function that allows attackers to execute arbitrary JavaScript by delivering a crafted … May 20, 2026
CVE-2026-45444 CRITICAL 10.0 Unrestricted Upload of File with Dangerous Type vulnerability in WP Swings Gift Cards For WooCommerce Pro allows Using Malicious Files. This issue affects Gift Cards … May 20, 2026
CVE-2026-39850 HIGH 7.4 Yii 2 is a PHP application framework. Versions 2.0.54 and prior contain flawed logic in the core view rendering method View::renderPhpFile() that leads to Local … May 20, 2026
CVE-2026-39405 UNKNOWN Frappe Learning Management System (LMS) is a learning system that helps users structure their content. In versions 2.50.0 and below, a user with course editing … May 20, 2026
CVE-2026-39352 UNKNOWN Frappe is a full-stack web application framework. Versions prior to 15.105.0 and 16.15.0 contain a possible Arbitrary File Read vulnerability via Path Traversal. The issue … May 20, 2026
CVE-2026-39311 MEDIUM 6.8 Trilium Notes is a cross-platform, hierarchical note taking application focused on building large personal knowledge bases. Versions 0.102.1 and prior contain a critical security flaw … May 20, 2026
CVE-2026-39310 HIGH 8.6 Trilium Notes is a cross-platform, hierarchical note taking application focused on building large personal knowledge bases. In versions 0.102.1 and prior, the Clipper API in … May 20, 2026
CVE-2026-35016 MEDIUM 4.6 Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in search.php that allows authenticated attackers to inject arbitrary JavaScript by passing an unsanitized … May 20, 2026
CVE-2026-35015 MEDIUM 4.6 Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in do_unit_mail.php that allows authenticated attackers to inject arbitrary JavaScript by passing an unsanitized … May 20, 2026
CVE-2026-35014 MEDIUM 4.6 Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in routes_nm.php that allows authenticated attackers to inject arbitrary JavaScript by passing an unsanitized … May 20, 2026
CVE-2026-35013 MEDIUM 4.6 Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in street_view.php that allows authenticated attackers to inject arbitrary JavaScript by passing unsanitized values … May 20, 2026