Vulnerability index

Browse CVEs

827 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Type ConfusionCWE-843 × clear
Chrome HIGH 8.8
CVE-2026-6301

Type Confusion in Turbofan in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafte…

Fix: 147.0.7727.101+
Fix from $1,950 2026-04-15
Chrome HIGH 8.8
CVE-2026-6307

Type Confusion in Turbofan in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafte…

Fix: 147.0.7727.101+
Fix from $1,950 2026-04-15
Framemaker HIGH 7.8
CVE-2026-27298

Adobe Framemaker versions 2022.8 and earlier are affected by an Access of Resource Using Incompatible Type ('Type Confusion') vulnerability that coul…

Fix: 2022.9+
Fix from $1,950 2026-04-14
Unclassified HIGH 7.7
CVE-2026-40683

In OpenStack Keystone before 28.0.1, the LDAP identity backend does not convert the user enabled attribute to a boolean when the user_enabled_invert …

Mitigation only
Fix from $1,950 2026-04-14
Windows 10 1607 HIGH 7.8
CVE-2026-26162

Access of resource using incompatible type ('type confusion') in Windows OLE allows an authorized attacker to elevate privileges locally.

Fix: 10.0.14393.9060 / 10.0.17763.8644+
Fix from $1,950 2026-04-14
Windows 10 1809 MEDIUM 5.5
CVE-2026-20806

Access of resource using incompatible type ('type confusion') in Windows COM allows an authorized attacker to disclose information locally.

Fix: 10.0.17763.8644 / 10.0.19044.7184+
Fix from $1,600 2026-04-14
Unclassified CRITICAL 9.8
CVE-2025-70023

An issue pertaining to CWE-843: Access of Resource Using Incompatible Type was discovered in transloadit uppy v0.25.6.

Mitigation only
Fix from $2,300 2026-04-14
Jq MEDIUM 6.1
CVE-2026-39956

jq is a command-line JSON processor. In commits after 69785bf77f86e2ea1b4a20ca86775916889e91c9, the _strindices builtin in jq's src/builtin.c passes …

Fix: 2026-04-08+
Fix from $1,600 2026-04-13
Escargot CRITICAL 9.8
CVE-2026-40446

Access of resource using incompatible type ('type confusion') vulnerability in Samsung Open Source Escargot allows Pointer Manipulation.This issue af…

Patch available
Fix from $2,300 2026-04-13
Escargot HIGH 7.5
CVE-2026-25204

Deserialization of untrusted data vulnerability in Samsung Open Source Escargot Java Script allows denial of service condition via process abort. Th…

Fix: 2026-03-28+
Fix from $1,950 2026-04-13
Proteus HIGH 7.8
CVE-2026-5496

Labcenter Electronics Proteus PDSPRJ File Parsing Type Confusion Remote Code Execution Vulnerability. This vulnerability allows remote attackers to e…

Mitigation only
Fix from $1,950 2026-04-11
Chrome HIGH 8.8
CVE-2026-5914

Type Confusion in CSS in Google Chrome prior to 147.0.7727.55 allowed an attacker who convinced a user to install a malicious extension to potentiall…

Fix: 147.0.7727.55+
Fix from $1,950 2026-04-08
Chrome HIGH 8.8
CVE-2026-5865

Type Confusion in V8 in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML …

Fix: 147.0.7727.55+
Fix from $1,950 2026-04-08
Chrome HIGH 8.8
CVE-2026-5871

Type Confusion in V8 in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML …

Fix: 147.0.7727.55+
Fix from $1,950 2026-04-08
Go HIGH 7.1
CVE-2026-27144

The compiler is meant to unwrap pointers which are the operands of a memory move; a no-op interface conversion prevented the compiler from making the…

Fix: 1.25.9 / 1.26.2+
Fix from $1,950 2026-04-08
Openexr HIGH 7.1
CVE-2026-34379

OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From…

Fix: 3.2.7 / 3.3.9+
Fix from $1,950 2026-04-06
Unclassified HIGH 7.5
CVE-2026-21710EPSS 26%

A flaw in Node.js HTTP request handling causes an uncaught `TypeError` when a request is received with a header named `__proto__` and the application…

Mitigation only
Fix from $1,950 2026-03-30
Handlebars HIGH 8.1
CVE-2026-33940

Handlebars provides the power necessary to let users build semantic templates. In versions 4.0.0 through 4.7.8, a crafted object placed in the templa…

Fix: 4.7.9+
Fix from $1,950 2026-03-27
Handlebars CRITICAL 9.8
CVE-2026-33937

Handlebars provides the power necessary to let users build semantic templates. In versions 4.0.0 through 4.7.8, `Handlebars.compile()` accepts a pre-…

Fix: 4.7.9+
Fix from $2,300 2026-03-27
Handlebars HIGH 8.1
CVE-2026-33938

Handlebars provides the power necessary to let users build semantic templates. In versions 4.0.0 through 4.7.8, the `@partial-block` special variable…

Fix: 4.7.9+
Fix from $1,950 2026-03-27
Ipados MEDIUM 6.2
CVE-2026-28822

A type confusion issue was addressed with improved memory handling. This issue is fixed in iOS 26.4 and iPadOS 26.4, macOS Sequoia 15.7.5, macOS Sono…

Fix: 14.8.5 / 15.7.5+
Fix from $1,600 2026-03-25
Firefox CRITICAL 9.8
CVE-2026-4702

JIT miscompilation in the JavaScript Engine component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunderbi…

Fix: 140.9.0 / 149.0+
Fix from $2,300 2026-03-24
Firefox CRITICAL 9.8
CVE-2026-4698

JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 149, Firefox ESR 115.34, Firefox ESR 140.9, Thund…

Fix: 115.34.0 / 140.9.0+
Fix from $2,300 2026-03-24
Qwik HIGH 7.5
CVE-2026-32701

Qwik is a performance-focused JavaScript framework. Versions prior to 1.19.2 improperly inferred arrays from dotted form field names during FormData …

Fix: 1.19.2+
Fix from $1,950 2026-03-20
Tar Rs HIGH 8.1
CVE-2026-33055

tar-rs is a tar archive reading/writing library for Rust. Versions 0.4.44 and below have conditional logic that skips the PAX size header in cases wh…

Fix: 0.4.45+
Fix from $1,950 2026-03-20
Chrome HIGH 8.8
CVE-2026-4457

Type Confusion in V8 in Google Chrome prior to 146.0.7680.153 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML pag…

Fix: 146.0.7680.153+
Fix from $1,950 2026-03-20
Htslib HIGH 8.1
CVE-2026-31968

HTSlib is a library for reading and writing bioinformatics file formats. CRAM is a compressed format which stores DNA sequence alignment data using a…

Fix: 1.21.1 / 1.22.2+
Fix from $1,950 2026-03-18
Affinity HIGH 7.8
CVE-2025-66342

A type confusion vulnerability exists in the EMF functionality of Canva Affinity. A specially crafted EMF file can trigger this vulnerability, which …

Fix: 3.1.0+
Fix from $1,950 2026-03-17
Openharmony HIGH 7.0
CVE-2025-25277

in OpenHarmony v5.1.0 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through using incompatible type. This …

Mitigation only
Fix from $1,950 2026-03-16
Lexbor HIGH 7.5
CVE-2026-29079

Lexbor is a web browser engine library. Prior to 2.7.0, a type‑confusion vulnerability exists in Lexbor’s HTML fragment parser. When ns = UNDEF, a co…

Fix: 2.7.0+
Fix from $1,950 2026-03-13