Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-7361 |
|
Use after free in iOS in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)
Use after free in iOS in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)
|
| CVE-2026-7345 |
|
Vulnerability in google (CVE-2026-7345)
vulnerability in google (CVE-2026-7345). Successful exploitation can lead to full system takeover.
|
| CVE-2026-7346 |
|
Buffer Overflow in google (CVE-2026-7346)
vulnerability in google (CVE-2026-7346). Confidential information can be exposed externally.
|
| CVE-2026-7347 |
|
Use-After-Free in google (CVE-2026-7347)
vulnerability in google (CVE-2026-7347). Successful exploitation can lead to full system takeover.
|
| CVE-2026-7348 |
|
Use after free in Codecs in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
Use after free in Codecs in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
|
| CVE-2026-7349 |
|
Use-After-Free in google (CVE-2026-7349)
vulnerability in google (CVE-2026-7349). Successful exploitation can lead to full system takeover.
|
| CVE-2026-7350 |
|
Use-After-Free in google (CVE-2026-7350)
vulnerability in google (CVE-2026-7350). Successful exploitation can lead to full system takeover.
|
| CVE-2026-7351 |
|
Vulnerability in google (CVE-2026-7351)
vulnerability in google (CVE-2026-7351). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-7352 |
|
Use-After-Free in google (CVE-2026-7352)
vulnerability in google (CVE-2026-7352). Successful exploitation can lead to full system takeover.
|
| CVE-2026-7353 |
|
Vulnerability in google (CVE-2026-7353)
vulnerability in google (CVE-2026-7353). Successful exploitation can lead to full system takeover.
|
| CVE-2026-7354 |
|
Out of bounds read and write in Angle in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: H...
Out of bounds read and write in Angle in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
|
| CVE-2026-7335 |
|
Use after free in media in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
Use after free in media in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
|
| CVE-2026-7336 |
|
Use after free in WebRTC in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
Use after free in WebRTC in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
|
| CVE-2026-7337 |
|
Vulnerability in google (CVE-2026-7337)
vulnerability in google (CVE-2026-7337). Successful exploitation can lead to full system takeover.
|
| CVE-2026-7338 |
|
Use-After-Free in google (CVE-2026-7338)
vulnerability in google (CVE-2026-7338). Successful exploitation can lead to full system takeover.
|
| CVE-2026-7339 |
|
Vulnerability in google (CVE-2026-7339)
vulnerability in google (CVE-2026-7339). Successful exploitation can lead to full system takeover.
|
| CVE-2026-7340 |
|
Vulnerability in google (CVE-2026-7340)
vulnerability in google (CVE-2026-7340). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-7341 |
|
Use-After-Free in google (CVE-2026-7341)
vulnerability in google (CVE-2026-7341). Successful exploitation can lead to full system takeover.
|
| CVE-2026-7342 |
|
Use-After-Free in google (CVE-2026-7342)
vulnerability in google (CVE-2026-7342). Successful exploitation can lead to full system takeover.
|
| CVE-2026-7343 |
|
Use-After-Free in google (CVE-2026-7343)
vulnerability in google (CVE-2026-7343). Successful exploitation can lead to full system takeover.
|
| CVE-2026-7344 |
|
Use-After-Free in google (CVE-2026-7344)
vulnerability in google (CVE-2026-7344). Successful exploitation can lead to full system takeover.
|
| CVE-2026-7333 |
|
Use-After-Free in google (CVE-2026-7333)
vulnerability in google (CVE-2026-7333). Successful exploitation can lead to full system takeover.
|
| CVE-2026-7334 |
|
Use-After-Free in google (CVE-2026-7334)
vulnerability in google (CVE-2026-7334). Successful exploitation can lead to full system takeover.
|
| CVE-2026-40296 |
|
Cross-Site Scripting (XSS) in phpoffice/phpspreadsheet (CVE-2026-40296)
cross-site scripting in phpoffice/phpspreadsheet (CVE-2026-40296). Risk of unauthorized operations or information disclosure. Exploitable via ``General``. Mitigation: upgrade to `1.30.4` or later.
|
| CVE-2026-7296 |
|
Cross-Site Scripting (XSS) in CVE-2026-7296 (CVE-2026-7296)
cross-site scripting in CVE-2026-7296 (CVE-2026-7296). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-7297 |
|
Cross-Site Scripting (XSS) in CVE-2026-7297 (CVE-2026-7297)
cross-site scripting in CVE-2026-7297 (CVE-2026-7297). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-37750 |
|
Cross-Site Scripting (XSS) in CVE-2026-37750 (CVE-2026-37750)
cross-site scripting in CVE-2026-37750 (CVE-2026-37750). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-7295 |
|
Cross-Site Scripting (XSS) in CVE-2026-7295 (CVE-2026-7295)
cross-site scripting in CVE-2026-7295 (CVE-2026-7295). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-7324 |
|
Buffer Overflow in mozilla (CVE-2026-7324)
vulnerability in mozilla (CVE-2026-7324). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-7320 |
|
Buffer Overflow in mozilla (CVE-2026-7320)
vulnerability in mozilla (CVE-2026-7320). Confidential information can be exposed externally.
|
| CVE-2026-7322 |
|
Buffer Overflow in mozilla (CVE-2026-7322)
vulnerability in mozilla (CVE-2026-7322). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-7323 |
|
Buffer Overflow in mozilla (CVE-2026-7323)
vulnerability in mozilla (CVE-2026-7323). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-27760 |
|
Code Injection in CVE-2026-27760 (CVE-2026-27760)
code injection in CVE-2026-27760 (CVE-2026-27760). Successful exploitation can lead to full system takeover.
|
| CVE-2026-41603 |
|
Vulnerability in apache (CVE-2026-41603)
vulnerability in apache (CVE-2026-41603). Confidential information can be exposed externally.
|
| CVE-2026-41604 |
|
Out-of-Bounds Read in apache (CVE-2026-41604)
vulnerability in apache (CVE-2026-41604). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-41607 |
|
Out-of-Bounds Read in apache (CVE-2026-41607)
vulnerability in apache (CVE-2026-41607). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-41605 |
|
Vulnerability in apache (CVE-2026-41605)
vulnerability in apache (CVE-2026-41605). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-41606 |
|
Vulnerability in apache (CVE-2026-41606)
vulnerability in apache (CVE-2026-41606). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-48431 |
|
Vulnerability in apache (CVE-2025-48431)
vulnerability in apache (CVE-2025-48431). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-41602 |
|
Vulnerability in apache (CVE-2026-41602)
vulnerability in apache (CVE-2026-41602). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-7222 |
|
Cross-Site Scripting (XSS) in CVE-2026-7222 (CVE-2026-7222)
cross-site scripting in CVE-2026-7222 (CVE-2026-7222). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-7200 |
|
Cross-Site Scripting (XSS) in CVE-2026-7200 (CVE-2026-7200)
cross-site scripting in CVE-2026-7200 (CVE-2026-7200). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-7199 |
|
Vulnerability in sqli (CVE-2026-7199)
vulnerability in sqli (CVE-2026-7199). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-32202 KEV |
|
[KEV] Vulnerability in Microsoft windows (CVE-2026-32202)
vulnerability in Microsoft windows (CVE-2026-32202). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2024-1708 KEV |
|
[KEV] Path Traversal in Connectwise screenconnect (CVE-2024-1708)
path traversal in Connectwise screenconnect (CVE-2024-1708). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2026-7194 |
|
Vulnerability in sqli (CVE-2026-7194)
vulnerability in sqli (CVE-2026-7194). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-3087 |
|
Path Traversal in libpython (CVE-2026-3087)
path traversal in libpython (CVE-2026-3087). Data can be tampered with by attackers. Mitigation: upgrade to `3.14.5` or later.
|
| CVE-2026-38934 |
|
Cross-Site Request Forgery (CSRF) in CVE-2026-38934 (CVE-2026-38934)
vulnerability in CVE-2026-38934 (CVE-2026-38934). Successful exploitation can lead to full system takeover.
|
| CVE-2026-38935 |
|
Cross-Site Scripting (XSS) in CVE-2026-38935 (CVE-2026-38935)
cross-site scripting in CVE-2026-38935 (CVE-2026-38935). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-38936 |
|
Cross-Site Scripting (XSS) in CVE-2026-38936 (CVE-2026-38936)
cross-site scripting in CVE-2026-38936 (CVE-2026-38936). Risk of unauthorized operations or information disclosure.
|