Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
HIGH 8.8
CVE-2026-10955
Type Confusion in ANGLE in Google Chrome on Windows prior to 149.0.7827.53 allowed a remote attacker to potentially perform out of bounds memory acce…
Chrome
149.0.7827.53+
HIGH 8.8
CVE-2026-10935
Type Confusion in V8 in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML …
Chrome
149.0.7827.53+
HIGH 8.8
CVE-2026-10936
Type Confusion in V8 in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML …
Chrome
149.0.7827.53+
HIGH 8.8
CVE-2026-10910
Type Confusion in V8 in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML …
Chrome
149.0.7827.53+
MEDIUM 5.5
CVE-2026-45702
OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Cortex-A cores using the TrustZone…
Op Tee
after 4.10.0
HIGH 7.3
CVE-2026-9334
Cpanel::JSON::XS versions before 4.41 for Perl allow type confusion via duplicate object keys when dupkeys_as_arrayref is enabled.
decode_hv() colla…
Cpanel\
4.41+
HIGH 8.8
CVE-2026-9983
Type Confusion in Skia in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HT…
Chrome
148.0.7778.215 / 148.0.7778.216+
HIGH 7.5
CVE-2026-10022
Type Confusion in V8 in Google Chrome prior to 148.0.7778.216 allowed an attacker who convinced a user to install a malicious extension to execute ar…
Chrome
148.0.7778.215 / 148.0.7778.216+
HIGH 7.5
CVE-2026-44325
free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's NRF root SBI endpoint POST /oauth2/token contains a parser…
Free5gc
4.2.2+
HIGH 7.8
CVE-2026-44728
Babel is a compiler for writing next generation JavaScript. From 7.12.0 to before 7.29.4 and 8.0.0-alpha.13, using Babel to compile code that was spe…
Babel
7.29.4+
HIGH 7.5
CVE-2026-9117
Type Confusion in GFX in Google Chrome on Linux, ChromeOS prior to 148.0.7778.179 allowed a remote attacker who had compromised the renderer process …
Chrome
148.0.7778.179+
HIGH 7.5
CVE-2026-5946
Multiple flaws have been identified in `named` related to the handling of DNS messages whose CLASS is not Internet (`IN`) — for example, `CHAOS` or `…
Bind
9.18.49 / 9.20.23+
MEDIUM 6.5
CVE-2026-8570
Type Confusion in V8 in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to obtain potentially sensitive information from process memo…
Chrome
148.0.7778.168+
HIGH 8.8
CVE-2026-8540
Type Confusion in V8 in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML…
Chrome
148.0.7778.168+
HIGH 8.4
CVE-2026-40364
Access of resource using incompatible type ('type confusion') in Microsoft Office Word allows an unauthorized attacker to execute code locally.
365 Apps
Mitigation only
HIGH 7.8
CVE-2026-35417
Use after free in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally.
Windows 10 1809
10.0.17763.8755 / 10.0.19044.7291+
HIGH 7.8
CVE-2026-34344
Access of resource using incompatible type ('type confusion') in Windows Ancillary Function Driver for WinSock allows an authorized attacker to eleva…
Windows 10 1607
10.0.14393.9140 / 10.0.17763.8755+
HIGH 8.8
CVE-2026-8389
JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 150.0.3.
Firefox
150.0.3+
HIGH 7.5
CVE-2026-28983
A type confusion issue was addressed with improved checks. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Sequo…
Ipados
18.7.9 / 26.5+
HIGH 8.8
CVE-2026-7988
Type Confusion in WebRTC in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted H…
Chrome
148.0.7778.96+
HIGH 8.8
CVE-2026-7927
Type Confusion in Runtime in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted …
Chrome
148.0.7778.96+
HIGH 8.3
CVE-2026-7914
Type Confusion in Accessibility in Google Chrome on Windows prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process…
Chrome
148.0.7778.96+
HIGH 8.7
CVE-2026-6210
A type confusion vulnerability in Qt SVG allows an attacker to cause an application crash via a crafted SVG image.
When processing SVG marker refe…
Mitigation only
MEDIUM 6.7
CVE-2026-20451
In slbc, there is a possible out of bounds write due to type confusion. This could lead to local escalation of privilege if a malicious actor has alr…
Mt8115 Firmware
Mitigation only
CRITICAL 9.8
CVE-2026-43037
In the Linux kernel, the following vulnerability has been resolved:
ip6_tunnel: clear skb2->cb[] in ip4ip6_err()
Oskar Kjos reported the following …
Linux Kernel
5.10.253 / 5.15.203+
CRITICAL 9.8
CVE-2026-43038
In the Linux kernel, the following vulnerability has been resolved:
ipv6: icmp: clear skb2->cb[] in ip6_err_gen_icmpv6_unreach()
Sashiko AI-review …
Linux Kernel
5.10.253 / 5.15.203+
HIGH 8.8
CVE-2026-7337
Type Confusion in V8 in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML…
Chrome
147.0.7727.138+
HIGH 7.5
CVE-2026-6732
A flaw was found in libxml2. This vulnerability occurs when the library processes a specially crafted XML Schema Definition (XSD) validated document …
Hardened Images
2.15.3 / 4.1.1.30+
HIGH 7.8
CVE-2026-31502
In the Linux kernel, the following vulnerability has been resolved:
team: fix header_ops type confusion with non-Ethernet ports
Similar to commit 9…
Linux Kernel
6.12.80 / 6.18.21+
HIGH 8.8
CVE-2026-6363
Type Confusion in V8 in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to potentially perform out of bounds memory access via a craf…
Chrome
147.0.7727.101+