Vulnerability index

Browse CVEs

827 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Type ConfusionCWE-843 × clear
HIGH 8.8 CVE-2026-10955 Type Confusion in ANGLE in Google Chrome on Windows prior to 149.0.7827.53 allowed a remote attacker to potentially perform out of bounds memory acce… Chrome 149.0.7827.53+ Fix from $1,9502026-06-04 HIGH 8.8 CVE-2026-10935 Type Confusion in V8 in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML … Chrome 149.0.7827.53+ Fix from $1,9502026-06-04 HIGH 8.8 CVE-2026-10936 Type Confusion in V8 in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML … Chrome 149.0.7827.53+ Fix from $1,9502026-06-04 HIGH 8.8 CVE-2026-10910 Type Confusion in V8 in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML … Chrome 149.0.7827.53+ Fix from $1,9502026-06-04 MEDIUM 5.5 CVE-2026-45702 OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Cortex-A cores using the TrustZone… Op Tee after 4.10.0 Fix from $1,6002026-06-03 HIGH 7.3 CVE-2026-9334 Cpanel::JSON::XS versions before 4.41 for Perl allow type confusion via duplicate object keys when dupkeys_as_arrayref is enabled. decode_hv() colla… Cpanel\ 4.41+ Fix from $1,9502026-06-03 HIGH 8.8 CVE-2026-9983 Type Confusion in Skia in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HT… Chrome 148.0.7778.215 / 148.0.7778.216+ Fix from $1,9502026-05-28 HIGH 7.5 CVE-2026-10022 Type Confusion in V8 in Google Chrome prior to 148.0.7778.216 allowed an attacker who convinced a user to install a malicious extension to execute ar… Chrome 148.0.7778.215 / 148.0.7778.216+ Fix from $1,9502026-05-28 HIGH 7.5 CVE-2026-44325 free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's NRF root SBI endpoint POST /oauth2/token contains a parser… Free5gc 4.2.2+ Fix from $1,9502026-05-27 HIGH 7.8 CVE-2026-44728 Babel is a compiler for writing next generation JavaScript. From 7.12.0 to before 7.29.4 and 8.0.0-alpha.13, using Babel to compile code that was spe… Babel 7.29.4+ Fix from $1,9502026-05-26 HIGH 7.5 CVE-2026-9117 Type Confusion in GFX in Google Chrome on Linux, ChromeOS prior to 148.0.7778.179 allowed a remote attacker who had compromised the renderer process … Chrome 148.0.7778.179+ Fix from $1,9502026-05-20 HIGH 7.5 CVE-2026-5946 Multiple flaws have been identified in `named` related to the handling of DNS messages whose CLASS is not Internet (`IN`) — for example, `CHAOS` or `… Bind 9.18.49 / 9.20.23+ Fix from $1,9502026-05-20 MEDIUM 6.5 CVE-2026-8570 Type Confusion in V8 in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to obtain potentially sensitive information from process memo… Chrome 148.0.7778.168+ Fix from $1,6002026-05-14 HIGH 8.8 CVE-2026-8540 Type Confusion in V8 in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML… Chrome 148.0.7778.168+ Fix from $1,9502026-05-14 HIGH 8.4 CVE-2026-40364 Access of resource using incompatible type ('type confusion') in Microsoft Office Word allows an unauthorized attacker to execute code locally. 365 Apps Mitigation only Fix from $1,9502026-05-12 HIGH 7.8 CVE-2026-35417 Use after free in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally. Windows 10 1809 10.0.17763.8755 / 10.0.19044.7291+ Fix from $1,9502026-05-12 HIGH 7.8 CVE-2026-34344 Access of resource using incompatible type ('type confusion') in Windows Ancillary Function Driver for WinSock allows an authorized attacker to eleva… Windows 10 1607 10.0.14393.9140 / 10.0.17763.8755+ Fix from $1,9502026-05-12 HIGH 8.8 CVE-2026-8389 JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 150.0.3. Firefox 150.0.3+ Fix from $1,9502026-05-12 HIGH 7.5 CVE-2026-28983 A type confusion issue was addressed with improved checks. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Sequo… Ipados 18.7.9 / 26.5+ Fix from $1,9502026-05-11 HIGH 8.8 CVE-2026-7988 Type Confusion in WebRTC in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted H… Chrome 148.0.7778.96+ Fix from $1,9502026-05-06 HIGH 8.8 CVE-2026-7927 Type Confusion in Runtime in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted … Chrome 148.0.7778.96+ Fix from $1,9502026-05-06 HIGH 8.3 CVE-2026-7914 Type Confusion in Accessibility in Google Chrome on Windows prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process… Chrome 148.0.7778.96+ Fix from $1,9502026-05-06 HIGH 8.7 CVE-2026-6210 A type confusion vulnerability in Qt SVG allows an attacker to cause an application crash via a crafted SVG image. When processing SVG marker refe… Mitigation only Fix from $1,9502026-05-06 MEDIUM 6.7 CVE-2026-20451 In slbc, there is a possible out of bounds write due to type confusion. This could lead to local escalation of privilege if a malicious actor has alr… Mt8115 Firmware Mitigation only Fix from $1,6002026-05-04 CRITICAL 9.8 CVE-2026-43037 In the Linux kernel, the following vulnerability has been resolved: ip6_tunnel: clear skb2->cb[] in ip4ip6_err() Oskar Kjos reported the following … Linux Kernel 5.10.253 / 5.15.203+ Fix from $2,3002026-05-01 CRITICAL 9.8 CVE-2026-43038 In the Linux kernel, the following vulnerability has been resolved: ipv6: icmp: clear skb2->cb[] in ip6_err_gen_icmpv6_unreach() Sashiko AI-review … Linux Kernel 5.10.253 / 5.15.203+ Fix from $2,3002026-05-01 HIGH 8.8 CVE-2026-7337 Type Confusion in V8 in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML… Chrome 147.0.7727.138+ Fix from $1,9502026-04-28 HIGH 7.5 CVE-2026-6732 A flaw was found in libxml2. This vulnerability occurs when the library processes a specially crafted XML Schema Definition (XSD) validated document … Hardened Images 2.15.3 / 4.1.1.30+ Fix from $1,9502026-04-23 HIGH 7.8 CVE-2026-31502 In the Linux kernel, the following vulnerability has been resolved: team: fix header_ops type confusion with non-Ethernet ports Similar to commit 9… Linux Kernel 6.12.80 / 6.18.21+ Fix from $1,9502026-04-22 HIGH 8.8 CVE-2026-6363 Type Confusion in V8 in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to potentially perform out of bounds memory access via a craf… Chrome 147.0.7727.101+ Fix from $1,9502026-04-15