Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
CRITICAL 9.6
CVE-2026-14423
Type Confusion in Tint in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML p…
Chrome
150.0.7871.46+
HIGH 8.3
CVE-2026-58592
Ladybird contains a dangling-reference memory-safety flaw in its WebAssembly ESM-integration module loader. When a JavaScript function is imported in…
Mitigation only
MEDIUM 6.5
CVE-2026-54164
API Platform Core is a system to create hypermedia-driven REST and GraphQL APIs. In versions prior to 4.1.30, 4.2.26 and 4.3.12, the serializer's Abs…
Mitigation only
CRITICAL 9.8
CVE-2025-15646
HTML::Gumbo versions before 0.19 for Perl disclose heap memory via type confusion.
Support for the <template> element was added to libgumbo 0.10.0 i…
Patch available
MEDIUM 6.5
CVE-2026-14148
Type Confusion in CSS in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to obtain potentially sensitive information from process memo…
Chrome
150.0.7871.46+
MEDIUM 6.5
CVE-2026-14119
Type Confusion in Bluetooth in Google Chrome on Windows prior to 150.0.7871.47 allowed an attacker on the local network segment to obtain potentially…
Chrome
150.0.7871.47+
HIGH 8.8
CVE-2026-13967
Heap buffer overflow in V8 in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted…
Chrome
150.0.7871.47+
CRITICAL 9.6
CVE-2026-13883
Type Confusion in ANGLE in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML …
Chrome
150.0.7871.46+
HIGH 8.3
CVE-2026-13803
Type Confusion in Chrome Tabs in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potential…
Chrome
150.0.7871.47+
CRITICAL 9.8
CVE-2026-13776
Type Confusion in Dawn in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perf…
Chrome
150.0.7871.47+
HIGH 7.5
CVE-2026-44628
An unauthenticated attacker can crash the worklist server with a single crafted query when the server has a valid Called AE Title / storage directory…
Mitigation only
HIGH 8.8
CVE-2026-43705
A type confusion issue was addressed with improved checks. This issue is fixed in Safari 26.5.2, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.5.2 and iPadO…
Safari
26.5.2+
HIGH 7.8
CVE-2026-12390
In AzeoTech DAQFactory versions 21.1 and prior, a Type Confusion vulnerability can be exploited by an attacker using specially crafted .ctl files whi…
Daqfactory
after 21.1
HIGH 8.8
CVE-2026-0162
In ParsePayloads of AudioSdpParser.cpp, there is a possible memory corruption due to type confusion. This could lead to remote code execution with no…
Android
Mitigation only
MEDIUM 5.4
CVE-2026-12298
Memory safety bug fixed in Firefox 152. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12.
Firefox
140.12.0 / 152.0+
MEDIUM 5.4
CVE-2026-12299
JIT miscompilation in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37, Thunderbir…
Firefox
115.37.0 / 140.12.0+
MEDIUM 5.4
CVE-2026-6047
LibreOffice can import documents in the OOXML format (DOCX). A heap buffer overflow existed when replaying deferred parser events for a text box elem…
Mitigation only
MEDIUM 5.4
CVE-2026-8358
LibreOffice Calc can import tracked changes from a spreadsheet document. A heap buffer overflow existed when a document reused the same change identi…
No fix yet
HIGH 7.8
CVE-2026-45641
Access of resource using incompatible type ('type confusion') in Windows Hyper-V allows an unauthorized attacker to execute code locally.
Windows 10 21h2
10.0.19044.7417 / 10.0.19045.7417+
HIGH 8.1
CVE-2026-45635
Access of resource using incompatible type ('type confusion') in Universal Plug and Play (upnp.dll) allows an unauthorized attacker to execute code o…
Windows 10 1607
10.0.14393.9234 / 10.0.17763.8880+
HIGH 7.8
CVE-2026-45600
Access of resource using incompatible type ('type confusion') in Windows Kernel-Mode Drivers allows an authorized attacker to elevate privileges loca…
Windows 11 24h2
10.0.26100.8655 / 10.0.26100.32995+
HIGH 8.4
CVE-2026-45456
Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally.
365 Apps
16.0.19725.20384+
HIGH 7.8
CVE-2026-44817
Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
365 Apps
Mitigation only
MEDIUM 5.3
CVE-2026-8499
The Helpfulcrowd Product Reviews plugin for WordPress is vulnerable to Authorization Bypass via PHP Type Juggling in versions up to, and including, 1…
Mitigation only
HIGH 8.8
CVE-2026-11662
Type Confusion in Bindings in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafte…
Chrome
149.0.7827.103+
HIGH 7.3
CVE-2026-11463
A vulnerability was determined in USCiLab Cereal up to 1.3.2. Affected is an unknown function of the component Shared Pointer Handler. Executing a ma…
Mitigation only
MEDIUM 6.5
CVE-2026-11196
Type Confusion in XML in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to obtain potentially sensitive information from process memo…
Chrome
149.0.7827.53+
HIGH 8.8
CVE-2026-11076
Type Confusion in CSS in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML…
Chrome
149.0.7827.53+
CRITICAL 9.6
CVE-2026-11052
Type Confusion in GPU in Google Chrome on Windows prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potent…
Chrome
149.0.7827.53+
HIGH 8.8
CVE-2026-10962
Type Confusion in Media in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HT…
Chrome
149.0.7827.53+