Vulnerability index

Browse CVEs

827 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Type ConfusionCWE-843 × clear
Chrome CRITICAL 9.6
CVE-2026-14423

Type Confusion in Tint in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML p…

Fix: 150.0.7871.46+
Fix from $2,300 2026-07-01
Unclassified HIGH 8.3
CVE-2026-58592

Ladybird contains a dangling-reference memory-safety flaw in its WebAssembly ESM-integration module loader. When a JavaScript function is imported in…

Mitigation only
Fix from $1,950 2026-07-01
Unclassified MEDIUM 6.5
CVE-2026-54164

API Platform Core is a system to create hypermedia-driven REST and GraphQL APIs. In versions prior to 4.1.30, 4.2.26 and 4.3.12, the serializer's Abs…

Mitigation only
Fix from $1,600 2026-07-01
Unclassified CRITICAL 9.8
CVE-2025-15646

HTML::Gumbo versions before 0.19 for Perl disclose heap memory via type confusion. Support for the <template> element was added to libgumbo 0.10.0 i…

Patch available
Fix from $2,300 2026-07-01
Chrome MEDIUM 6.5
CVE-2026-14148

Type Confusion in CSS in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to obtain potentially sensitive information from process memo…

Fix: 150.0.7871.46+
Fix from $1,600 2026-06-30
Chrome MEDIUM 6.5
CVE-2026-14119

Type Confusion in Bluetooth in Google Chrome on Windows prior to 150.0.7871.47 allowed an attacker on the local network segment to obtain potentially…

Fix: 150.0.7871.47+
Fix from $1,600 2026-06-30
Chrome HIGH 8.8
CVE-2026-13967

Heap buffer overflow in V8 in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted…

Fix: 150.0.7871.47+
Fix from $1,950 2026-06-30
Chrome CRITICAL 9.6
CVE-2026-13883

Type Confusion in ANGLE in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML …

Fix: 150.0.7871.46+
Fix from $2,300 2026-06-30
Chrome HIGH 8.3
CVE-2026-13803

Type Confusion in Chrome Tabs in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potential…

Fix: 150.0.7871.47+
Fix from $1,950 2026-06-30
Chrome CRITICAL 9.8
CVE-2026-13776

Type Confusion in Dawn in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perf…

Fix: 150.0.7871.47+
Fix from $2,300 2026-06-30
Unclassified HIGH 7.5
CVE-2026-44628

An unauthenticated attacker can crash the worklist server with a single crafted query when the server has a valid Called AE Title / storage directory…

Mitigation only
Fix from $1,950 2026-06-30
Safari HIGH 8.8
CVE-2026-43705

A type confusion issue was addressed with improved checks. This issue is fixed in Safari 26.5.2, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.5.2 and iPadO…

Fix: 26.5.2+
Fix from $1,950 2026-06-29
Daqfactory HIGH 7.8
CVE-2026-12390

In AzeoTech DAQFactory versions 21.1 and prior, a Type Confusion vulnerability can be exploited by an attacker using specially crafted .ctl files whi…

Fix: after 21.1
Fix from $1,950 2026-06-18
Android HIGH 8.8
CVE-2026-0162

In ParsePayloads of AudioSdpParser.cpp, there is a possible memory corruption due to type confusion. This could lead to remote code execution with no…

Mitigation only
Fix from $1,950 2026-06-16
Firefox MEDIUM 5.4
CVE-2026-12298

Memory safety bug fixed in Firefox 152. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12.

Fix: 140.12.0 / 152.0+
Fix from $1,600 2026-06-16
Firefox MEDIUM 5.4
CVE-2026-12299

JIT miscompilation in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37, Thunderbir…

Fix: 115.37.0 / 140.12.0+
Fix from $1,600 2026-06-16
Unclassified MEDIUM 5.4
CVE-2026-6047

LibreOffice can import documents in the OOXML format (DOCX). A heap buffer overflow existed when replaying deferred parser events for a text box elem…

Mitigation only
Fix from $1,600 2026-06-15
Unclassified MEDIUM 5.4
CVE-2026-8358

LibreOffice Calc can import tracked changes from a spreadsheet document. A heap buffer overflow existed when a document reused the same change identi…

No fix yet
Fix from $1,600 2026-06-15
Windows 10 21h2 HIGH 7.8
CVE-2026-45641

Access of resource using incompatible type ('type confusion') in Windows Hyper-V allows an unauthorized attacker to execute code locally.

Fix: 10.0.19044.7417 / 10.0.19045.7417+
Fix from $1,950 2026-06-09
Windows 10 1607 HIGH 8.1
CVE-2026-45635

Access of resource using incompatible type ('type confusion') in Universal Plug and Play (upnp.dll) allows an unauthorized attacker to execute code o…

Fix: 10.0.14393.9234 / 10.0.17763.8880+
Fix from $1,950 2026-06-09
Windows 11 24h2 HIGH 7.8
CVE-2026-45600

Access of resource using incompatible type ('type confusion') in Windows Kernel-Mode Drivers allows an authorized attacker to elevate privileges loca…

Fix: 10.0.26100.8655 / 10.0.26100.32995+
Fix from $1,950 2026-06-09
365 Apps HIGH 8.4
CVE-2026-45456

Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally.

Fix: 16.0.19725.20384+
Fix from $1,950 2026-06-09
365 Apps HIGH 7.8
CVE-2026-44817

Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Mitigation only
Fix from $1,950 2026-06-09
Unclassified MEDIUM 5.3
CVE-2026-8499

The Helpfulcrowd Product Reviews plugin for WordPress is vulnerable to Authorization Bypass via PHP Type Juggling in versions up to, and including, 1…

Mitigation only
Fix from $1,600 2026-06-09
Chrome HIGH 8.8
CVE-2026-11662

Type Confusion in Bindings in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafte…

Fix: 149.0.7827.103+
Fix from $1,950 2026-06-09
Unclassified HIGH 7.3
CVE-2026-11463

A vulnerability was determined in USCiLab Cereal up to 1.3.2. Affected is an unknown function of the component Shared Pointer Handler. Executing a ma…

Mitigation only
Fix from $1,950 2026-06-07
Chrome MEDIUM 6.5
CVE-2026-11196

Type Confusion in XML in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to obtain potentially sensitive information from process memo…

Fix: 149.0.7827.53+
Fix from $1,600 2026-06-04
Chrome HIGH 8.8
CVE-2026-11076

Type Confusion in CSS in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML…

Fix: 149.0.7827.53+
Fix from $1,950 2026-06-04
Chrome CRITICAL 9.6
CVE-2026-11052

Type Confusion in GPU in Google Chrome on Windows prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potent…

Fix: 149.0.7827.53+
Fix from $2,300 2026-06-04
Chrome HIGH 8.8
CVE-2026-10962

Type Confusion in Media in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HT…

Fix: 149.0.7827.53+
Fix from $1,950 2026-06-04