Vulnerability index

Browse CVEs

827 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Type ConfusionCWE-843 × clear
Chrome HIGH 8.8
CVE-2026-10955

Type Confusion in ANGLE in Google Chrome on Windows prior to 149.0.7827.53 allowed a remote attacker to potentially perform out of bounds memory acce…

Fix: 149.0.7827.53+
Fix from $1,950 2026-06-04
Chrome HIGH 8.8
CVE-2026-10935

Type Confusion in V8 in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML …

Fix: 149.0.7827.53+
Fix from $1,950 2026-06-04
Chrome HIGH 8.8
CVE-2026-10936

Type Confusion in V8 in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML …

Fix: 149.0.7827.53+
Fix from $1,950 2026-06-04
Chrome HIGH 8.8
CVE-2026-10910

Type Confusion in V8 in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML …

Fix: 149.0.7827.53+
Fix from $1,950 2026-06-04
Op Tee MEDIUM 5.5
CVE-2026-45702

OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Cortex-A cores using the TrustZone…

Fix: after 4.10.0
Fix from $1,600 2026-06-03
Cpanel\ HIGH 7.3
CVE-2026-9334

Cpanel::JSON::XS versions before 4.41 for Perl allow type confusion via duplicate object keys when dupkeys_as_arrayref is enabled. decode_hv() colla…

Fix: 4.41+
Fix from $1,950 2026-06-03
Chrome HIGH 8.8
CVE-2026-9983

Type Confusion in Skia in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HT…

Fix: 148.0.7778.215 / 148.0.7778.216+
Fix from $1,950 2026-05-28
Chrome HIGH 7.5
CVE-2026-10022

Type Confusion in V8 in Google Chrome prior to 148.0.7778.216 allowed an attacker who convinced a user to install a malicious extension to execute ar…

Fix: 148.0.7778.215 / 148.0.7778.216+
Fix from $1,950 2026-05-28
Free5gc HIGH 7.5
CVE-2026-44325

free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's NRF root SBI endpoint POST /oauth2/token contains a parser…

Fix: 4.2.2+
Fix from $1,950 2026-05-27
Babel HIGH 7.8
CVE-2026-44728

Babel is a compiler for writing next generation JavaScript. From 7.12.0 to before 7.29.4 and 8.0.0-alpha.13, using Babel to compile code that was spe…

Fix: 7.29.4+
Fix from $1,950 2026-05-26
Chrome HIGH 7.5
CVE-2026-9117

Type Confusion in GFX in Google Chrome on Linux, ChromeOS prior to 148.0.7778.179 allowed a remote attacker who had compromised the renderer process …

Fix: 148.0.7778.179+
Fix from $1,950 2026-05-20
Bind HIGH 7.5
CVE-2026-5946

Multiple flaws have been identified in `named` related to the handling of DNS messages whose CLASS is not Internet (`IN`) — for example, `CHAOS` or `…

Fix: 9.18.49 / 9.20.23+
Fix from $1,950 2026-05-20
Chrome MEDIUM 6.5
CVE-2026-8570

Type Confusion in V8 in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to obtain potentially sensitive information from process memo…

Fix: 148.0.7778.168+
Fix from $1,600 2026-05-14
Chrome HIGH 8.8
CVE-2026-8540

Type Confusion in V8 in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML…

Fix: 148.0.7778.168+
Fix from $1,950 2026-05-14
365 Apps HIGH 8.4
CVE-2026-40364

Access of resource using incompatible type ('type confusion') in Microsoft Office Word allows an unauthorized attacker to execute code locally.

Mitigation only
Fix from $1,950 2026-05-12
Windows 10 1809 HIGH 7.8
CVE-2026-35417

Use after free in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally.

Fix: 10.0.17763.8755 / 10.0.19044.7291+
Fix from $1,950 2026-05-12
Windows 10 1607 HIGH 7.8
CVE-2026-34344

Access of resource using incompatible type ('type confusion') in Windows Ancillary Function Driver for WinSock allows an authorized attacker to eleva…

Fix: 10.0.14393.9140 / 10.0.17763.8755+
Fix from $1,950 2026-05-12
Firefox HIGH 8.8
CVE-2026-8389

JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 150.0.3.

Fix: 150.0.3+
Fix from $1,950 2026-05-12
Ipados HIGH 7.5
CVE-2026-28983

A type confusion issue was addressed with improved checks. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Sequo…

Fix: 18.7.9 / 26.5+
Fix from $1,950 2026-05-11
Chrome HIGH 8.8
CVE-2026-7988

Type Confusion in WebRTC in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted H…

Fix: 148.0.7778.96+
Fix from $1,950 2026-05-06
Chrome HIGH 8.8
CVE-2026-7927

Type Confusion in Runtime in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted …

Fix: 148.0.7778.96+
Fix from $1,950 2026-05-06
Chrome HIGH 8.3
CVE-2026-7914

Type Confusion in Accessibility in Google Chrome on Windows prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process…

Fix: 148.0.7778.96+
Fix from $1,950 2026-05-06
Unclassified HIGH 8.7
CVE-2026-6210

A type confusion vulnerability in Qt SVG allows an attacker to cause an application crash via a crafted SVG image. When processing SVG marker refe…

Mitigation only
Fix from $1,950 2026-05-06
Mt8115 Firmware MEDIUM 6.7
CVE-2026-20451

In slbc, there is a possible out of bounds write due to type confusion. This could lead to local escalation of privilege if a malicious actor has alr…

Mitigation only
Fix from $1,600 2026-05-04
Linux Kernel CRITICAL 9.8
CVE-2026-43037

In the Linux kernel, the following vulnerability has been resolved: ip6_tunnel: clear skb2->cb[] in ip4ip6_err() Oskar Kjos reported the following …

Fix: 5.10.253 / 5.15.203+
Fix from $2,300 2026-05-01
Linux Kernel CRITICAL 9.8
CVE-2026-43038

In the Linux kernel, the following vulnerability has been resolved: ipv6: icmp: clear skb2->cb[] in ip6_err_gen_icmpv6_unreach() Sashiko AI-review …

Fix: 5.10.253 / 5.15.203+
Fix from $2,300 2026-05-01
Chrome HIGH 8.8
CVE-2026-7337

Type Confusion in V8 in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML…

Fix: 147.0.7727.138+
Fix from $1,950 2026-04-28
Hardened Images HIGH 7.5
CVE-2026-6732

A flaw was found in libxml2. This vulnerability occurs when the library processes a specially crafted XML Schema Definition (XSD) validated document …

Fix: 2.15.3 / 4.1.1.30+
Fix from $1,950 2026-04-23
Linux Kernel HIGH 7.8
CVE-2026-31502

In the Linux kernel, the following vulnerability has been resolved: team: fix header_ops type confusion with non-Ethernet ports Similar to commit 9…

Fix: 6.12.80 / 6.18.21+
Fix from $1,950 2026-04-22
Chrome HIGH 8.8
CVE-2026-6363

Type Confusion in V8 in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to potentially perform out of bounds memory access via a craf…

Fix: 147.0.7727.101+
Fix from $1,950 2026-04-15