Vulnerability index

Browse CVEs

827 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Type ConfusionCWE-843 × clear
HIGH 7.5 CVE-2026-52829 ZEBRA is a Zcash node written entirely in Rust. Prior to 4.5.0, an unauthenticated IPv4 peer can deterministically terminate a synced Zebra node usin… Fix unknown Fix from $4,9002026-08-18 CRITICAL 9.8 CVE-2026-59940 Seroval facilitates JS value stringification, including complex structures beyond JSON.stringify capabilities. Prior to 1.5.3, seroval.fromJSON() all… Fix unknown Fix from $5,7502026-08-18 CRITICAL 9.1 CVE-2026-74956 Same-origin policy bypass in the DOM: Service Workers component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and… Fix unknown Fix from $5,7502026-08-18 HIGH 8.8 CVE-2026-16238 Type confusion in PostgreSQL pg_restore_attribute_stats() allows an object creator to execute arbitrary code as the operating system user running the… No fix yet Fix from $4,9002026-08-13 HIGH 8.8 CVE-2026-16239 Type confusion in PostgreSQL "portal"/cursor lifecycle allows a user to execute arbitrary code as the operating system user running the database, via… No fix yet Fix from $4,9002026-08-13 HIGH 8.8 CVE-2026-14680 Type confusion with PostgreSQL "internal" data type arguments allows any user to execute arbitrary code as the operating system user running the data… PostgreSQL No fix yet Fix from $4,9002026-08-13 HIGH 8.1 CVE-2026-14668 Type confusion regarding input of PostgreSQL ctid data type selectivity estimator allows an object creator to view a calculation derived from the val… No fix yet Fix from $4,9002026-08-13 HIGH 8.8 CVE-2026-14671 Type confusion in PostgreSQL module "refint" allows an object creator to execute arbitrary code as the operating system user running the database. T… No fix yet Fix from $4,9002026-08-13 MEDIUM 5.4 CVE-2026-70339 Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over… Edge Chromium No fix yet Fix from $4,0002026-08-11 MEDIUM 6.5 CVE-2026-18701 An issue in MongoDB Server's query subsystem could allow an authenticated user with read privileges to cause the server process to terminate unexpect… No fix yet Fix from $4,0002026-08-11 HIGH 7.8 CVE-2026-68811 Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to execute code locally. 365 Apps No fix yet Fix from $4,9002026-08-11 HIGH 7.8 CVE-2026-68803 Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to execute code locally. 365 Apps No fix yet Fix from $4,9002026-08-11 HIGH 8.8 CVE-2026-65807 Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to execute code over a networ… 365 Apps No fix yet Fix from $4,9002026-08-11 HIGH 7.8 CVE-2026-64904 Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally. 365 Apps No fix yet Fix from $4,9002026-08-11 HIGH 7.8 CVE-2026-61932 Access of resource using incompatible type ('type confusion') in Windows DWM Core Library allows an authorized attacker to elevate privileges locally. Windows 10 1607 10.0.14393.9418 / 10.0.17763.9115+ Fix from $4,9002026-08-11 HIGH 8.2 CVE-2026-72766 n8n before 1.123.67, 2.x before 2.31.5, and 2.32.x before 2.32.1 contain a type confusion vulnerability in the Send Email node, which does not enforc… No fix yet Fix from $4,9002026-08-11 HIGH 8.6 CVE-2026-14644 Nexus Repository 3 contained a privilege escalation vulnerability in the REST privileges API. An authenticated user with permission to manage privile… No fix yet Fix from $1,9502026-08-07 CRITICAL 9.8 CVE-2026-71558 Heap type confusion vulnerability in Apache Fory C++ deserialization. This issue affects Apache Fory C++ versions from 0.14.0 before 1.5.0. A crafte… Fory 1.5.0+ Fix from $2,3002026-08-07 HIGH 8.8 CVE-2026-15572 A flaw was found in Keycloak's Dynamic Client Registration (DCR) security policy management. The "Allowed Protocol Mapper Types" policy, which restri… Build Of Keycloak 26.4.14 / 26.6.5+ Fix from $1,9502026-08-05 CRITICAL 9.6 CVE-2026-66321 Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over… Edge Chromium 151.0.4129.59+ Fix from $2,3002026-08-04 HIGH 8.8 CVE-2026-17989 Type Confusion in V8 in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML … Chrome 151.0.7922.72+ Fix from $1,9502026-07-30 HIGH 7.5 CVE-2026-17948 Type Confusion in V8 in Google Chrome prior to 151.0.7922.72 allowed an attacker who convinced a user to install a malicious extension to execute arb… Chrome 151.0.7922.72+ Fix from $1,9502026-07-30 MEDIUM 5.8 CVE-2026-17866 Type Confusion in Tab in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potent… Chrome 151.0.7922.72+ Fix from $1,6002026-07-30 HIGH 8.8 CVE-2026-17725 Type Confusion in V8 in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML … Chrome 151.0.7922.72+ Fix from $1,9502026-07-30 CRITICAL 9.6 CVE-2026-17697 Type Confusion in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML … Chrome 151.0.7922.72+ Fix from $2,3002026-07-30 CRITICAL 9.6 CVE-2026-17687 Type Confusion in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially per… Chrome 151.0.7922.72+ Fix from $2,3002026-07-30 CRITICAL 9.8 CVE-2026-64727 A type confusion issue was addressed with improved memory handling. This issue is fixed in macOS Tahoe 26.6, tvOS 26.6. An app may be able to cause u… macOS 26.6+ Fix from $2,3002026-07-27 CRITICAL 9.8 CVE-2026-64704 A type confusion issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.… macOS 14.8.8 / 15.7.8+ Fix from $2,3002026-07-27 MEDIUM 5.5 CVE-2026-64693 A type confusion issue was addressed with improved checks. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6, macOS Seq… Ipados 14.8.8 / 15.7.8+ Fix from $1,6002026-07-27 MEDIUM 6.5 CVE-2026-13066 Improper handling of DBPointer objects during BSON serialization in MongoDB's server-side JavaScript engine can result in internal process memory con… MongoDB 7.0.39 / 8.0.28+ Fix from $1,6002026-07-22