Vulnerability index

Browse CVEs

827 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Type ConfusionCWE-843 × clear
Unclassified HIGH 7.5
CVE-2026-52829

ZEBRA is a Zcash node written entirely in Rust. Prior to 4.5.0, an unauthenticated IPv4 peer can deterministically terminate a synced Zebra node usin…

Fix unknown
Fix from $4,900 2026-08-18
Unclassified CRITICAL 9.8
CVE-2026-59940

Seroval facilitates JS value stringification, including complex structures beyond JSON.stringify capabilities. Prior to 1.5.3, seroval.fromJSON() all…

Fix unknown
Fix from $5,750 2026-08-18
Unclassified CRITICAL 9.1
CVE-2026-74956

Same-origin policy bypass in the DOM: Service Workers component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and…

Fix unknown
Fix from $5,750 2026-08-18
Unclassified HIGH 8.8
CVE-2026-16238

Type confusion in PostgreSQL pg_restore_attribute_stats() allows an object creator to execute arbitrary code as the operating system user running the…

No fix yet
Fix from $4,900 2026-08-13
Unclassified HIGH 8.8
CVE-2026-16239

Type confusion in PostgreSQL "portal"/cursor lifecycle allows a user to execute arbitrary code as the operating system user running the database, via…

No fix yet
Fix from $4,900 2026-08-13
PostgreSQL HIGH 8.8
CVE-2026-14680

Type confusion with PostgreSQL "internal" data type arguments allows any user to execute arbitrary code as the operating system user running the data…

No fix yet
Fix from $4,900 2026-08-13
Unclassified HIGH 8.1
CVE-2026-14668

Type confusion regarding input of PostgreSQL ctid data type selectivity estimator allows an object creator to view a calculation derived from the val…

No fix yet
Fix from $4,900 2026-08-13
Unclassified HIGH 8.8
CVE-2026-14671

Type confusion in PostgreSQL module "refint" allows an object creator to execute arbitrary code as the operating system user running the database. T…

No fix yet
Fix from $4,900 2026-08-13
Edge Chromium MEDIUM 5.4
CVE-2026-70339

Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over…

No fix yet
Fix from $4,000 2026-08-11
Unclassified MEDIUM 6.5
CVE-2026-18701

An issue in MongoDB Server's query subsystem could allow an authenticated user with read privileges to cause the server process to terminate unexpect…

No fix yet
Fix from $4,000 2026-08-11
365 Apps HIGH 7.8
CVE-2026-68811

Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

No fix yet
Fix from $4,900 2026-08-11
365 Apps HIGH 7.8
CVE-2026-68803

Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

No fix yet
Fix from $4,900 2026-08-11
365 Apps HIGH 8.8
CVE-2026-65807

Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to execute code over a networ…

No fix yet
Fix from $4,900 2026-08-11
365 Apps HIGH 7.8
CVE-2026-64904

Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally.

No fix yet
Fix from $4,900 2026-08-11
Windows 10 1607 HIGH 7.8
CVE-2026-61932

Access of resource using incompatible type ('type confusion') in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.

Fix: 10.0.14393.9418 / 10.0.17763.9115+
Fix from $4,900 2026-08-11
Unclassified HIGH 8.2
CVE-2026-72766

n8n before 1.123.67, 2.x before 2.31.5, and 2.32.x before 2.32.1 contain a type confusion vulnerability in the Send Email node, which does not enforc…

No fix yet
Fix from $4,900 2026-08-11
Unclassified HIGH 8.6
CVE-2026-14644

Nexus Repository 3 contained a privilege escalation vulnerability in the REST privileges API. An authenticated user with permission to manage privile…

No fix yet
Fix from $1,950 2026-08-07
Fory CRITICAL 9.8
CVE-2026-71558

Heap type confusion vulnerability in Apache Fory C++ deserialization. This issue affects Apache Fory C++ versions from 0.14.0 before 1.5.0. A crafte…

Fix: 1.5.0+
Fix from $2,300 2026-08-07
Build Of Keycloak HIGH 8.8
CVE-2026-15572

A flaw was found in Keycloak's Dynamic Client Registration (DCR) security policy management. The "Allowed Protocol Mapper Types" policy, which restri…

Fix: 26.4.14 / 26.6.5+
Fix from $1,950 2026-08-05
Edge Chromium CRITICAL 9.6
CVE-2026-66321

Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over…

Fix: 151.0.4129.59+
Fix from $2,300 2026-08-04
Chrome HIGH 8.8
CVE-2026-17989

Type Confusion in V8 in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML …

Fix: 151.0.7922.72+
Fix from $1,950 2026-07-30
Chrome HIGH 7.5
CVE-2026-17948

Type Confusion in V8 in Google Chrome prior to 151.0.7922.72 allowed an attacker who convinced a user to install a malicious extension to execute arb…

Fix: 151.0.7922.72+
Fix from $1,950 2026-07-30
Chrome MEDIUM 5.8
CVE-2026-17866

Type Confusion in Tab in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potent…

Fix: 151.0.7922.72+
Fix from $1,600 2026-07-30
Chrome HIGH 8.8
CVE-2026-17725

Type Confusion in V8 in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML …

Fix: 151.0.7922.72+
Fix from $1,950 2026-07-30
Chrome CRITICAL 9.6
CVE-2026-17697

Type Confusion in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML …

Fix: 151.0.7922.72+
Fix from $2,300 2026-07-30
Chrome CRITICAL 9.6
CVE-2026-17687

Type Confusion in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially per…

Fix: 151.0.7922.72+
Fix from $2,300 2026-07-30
macOS CRITICAL 9.8
CVE-2026-64727

A type confusion issue was addressed with improved memory handling. This issue is fixed in macOS Tahoe 26.6, tvOS 26.6. An app may be able to cause u…

Fix: 26.6+
Fix from $2,300 2026-07-27
macOS CRITICAL 9.8
CVE-2026-64704

A type confusion issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.…

Fix: 14.8.8 / 15.7.8+
Fix from $2,300 2026-07-27
Ipados MEDIUM 5.5
CVE-2026-64693

A type confusion issue was addressed with improved checks. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6, macOS Seq…

Fix: 14.8.8 / 15.7.8+
Fix from $1,600 2026-07-27
MongoDB MEDIUM 6.5
CVE-2026-13066

Improper handling of DBPointer objects during BSON serialization in MongoDB's server-side JavaScript engine can result in internal process memory con…

Fix: 7.0.39 / 8.0.28+
Fix from $1,600 2026-07-22