Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

50589
Total
4065
Critical
14978
High
14744
Medium
CVE ID Severity Score Description Published
CVE-2026-16092 MEDIUM 6.5 The Improved Save Button plugin for WordPress is vulnerable to second-order SQL Injection via 'meta_key' Custom Field via 'Save and Duplicate' Action in all versions … Jul 30, 2026
CVE-2026-16727 UNKNOWN — Concurrent Execution using Shared Resource with Improper Synchronization (“Race Condition”) in ASUS Armoury Crate allows a local user to execute arbitrary code with elevated privileges … Jul 30, 2026
CVE-2026-15929 UNKNOWN — Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in LG Electronics SmartShare allows SQL Injection. This issue affects SmartShare: through … Jul 30, 2026
CVE-2026-59952 UNKNOWN — Valibot helps validate data using a schema. Versions prior to 1.4.2 can throw a TypeError inside its flatten() helper when validation issues contain attacker-controlled object … Jul 30, 2026
CVE-2026-18019 MEDIUM 4.3 Side-channel information leakage in Media in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium … Jul 30, 2026
CVE-2026-18018 MEDIUM 4.0 Inappropriate implementation in Updater in Google Chrome on Windows prior to 151.0.7922.72 allowed a local attacker to perform UI spoofing via a malicious file. (Chromium … Jul 30, 2026
CVE-2026-18017 HIGH 8.8 Use after free in Dawn in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted … Jul 30, 2026
CVE-2026-18016 MEDIUM 4.3 Insufficient policy enforcement in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker to perform UI spoofing via a … Jul 30, 2026
CVE-2026-18015 CRITICAL 9.6 Inappropriate implementation in Tint in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted … Jul 30, 2026
CVE-2026-18014 MEDIUM 6.5 Insufficient validation of untrusted input in DevTools in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to bypass navigation restrictions via a malicious file. … Jul 30, 2026
CVE-2026-18013 MEDIUM 4.3 Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker to perform UI spoofing via a crafted … Jul 30, 2026
CVE-2026-18012 HIGH 8.8 Use after free in PDFium in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted … Jul 30, 2026
CVE-2026-18011 LOW 2.4 Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a local attacker to obtain potentially sensitive information from process … Jul 30, 2026
CVE-2026-18010 MEDIUM 4.3 Inappropriate implementation in Passwords in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to perform UI spoofing via malicious network traffic. (Chromium security severity: … Jul 30, 2026
CVE-2026-18009 MEDIUM 4.3 Insufficient validation of untrusted input in Passwords in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to perform UI spoofing via malicious network traffic. … Jul 30, 2026
CVE-2026-18008 MEDIUM 4.3 Inappropriate implementation in Settings in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to perform UI spoofing via malicious network traffic. (Chromium security severity: … Jul 30, 2026
CVE-2026-18007 MEDIUM 4.3 Inappropriate implementation in Input in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker to perform UI spoofing via a crafted HTML page. … Jul 30, 2026
CVE-2026-18006 MEDIUM 4.3 Inappropriate implementation in Google Lens in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to perform UI spoofing … Jul 30, 2026
CVE-2026-18005 MEDIUM 6.5 Inappropriate implementation in WebXR in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted … Jul 30, 2026
CVE-2026-18004 MEDIUM 4.3 Insufficient policy enforcement in Speech in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to leak cross-origin data … Jul 30, 2026
CVE-2026-18003 MEDIUM 4.3 Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker to perform UI spoofing via a crafted … Jul 30, 2026
CVE-2026-18002 CRITICAL 9.6 Insufficient validation of untrusted input in Google Lens in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to … Jul 30, 2026
CVE-2026-18001 MEDIUM 6.5 Inappropriate implementation in WebGL in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted … Jul 30, 2026
CVE-2026-18000 LOW 3.1 Insufficient policy enforcement in USB in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to leak … Jul 30, 2026
CVE-2026-17999 MEDIUM 6.5 Race in PictureInPicture in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker to perform domain spoofing via a crafted HTML page. (Chromium … Jul 30, 2026