Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Chrome CRITICAL 9.6
CVE-2026-13878

Use after free in Bluetooth in Google Chrome on Mac prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to pote…

Fix: 150.0.7871.47+
Fix from $2,300 2026-06-30
Chrome CRITICAL 9.1
CVE-2026-13872

Insufficient validation of untrusted input in WebAppInstalls in Google Chrome on Android prior to 150.0.7871.47 allowed a local attacker to potential…

Fix: 150.0.7871.47+
Fix from $2,300 2026-06-30
Chrome CRITICAL 9.6
CVE-2026-13869

Use after free in Device in Google Chrome on Windows prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to pot…

Fix: 150.0.7871.47+
Fix from $2,300 2026-06-30
Chrome CRITICAL 9.6
CVE-2026-13861

Use after free in Core in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perf…

Fix: 150.0.7871.46+
Fix from $2,300 2026-06-30
Chrome CRITICAL 9.6
CVE-2026-13859

Inappropriate implementation in ANGLE in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to potentially perform a sandbox escape via a…

Fix: 150.0.7871.46+
Fix from $2,300 2026-06-30
Chrome CRITICAL 9.6
CVE-2026-13854

Use after free in Ozone in Google Chrome on Linux prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potent…

Fix: 150.0.7871.47+
Fix from $2,300 2026-06-30
Chrome CRITICAL 9.6
CVE-2026-13853

Use after free in Journeys in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially …

Fix: 150.0.7871.46+
Fix from $2,300 2026-06-30
Chrome CRITICAL 9.1
CVE-2026-13852

Insufficient validation of untrusted input in WebAppInstalls in Google Chrome on Android prior to 150.0.7871.47 allowed a local attacker to bypass di…

Fix: 150.0.7871.47+
Fix from $2,300 2026-06-30
Chrome CRITICAL 9.1
CVE-2026-13851

Insufficient validation of untrusted input in WebAppInstalls in Google Chrome on Android prior to 150.0.7871.47 allowed a local attacker to bypass di…

Fix: 150.0.7871.47+
Fix from $2,300 2026-06-30
Chrome CRITICAL 9.6
CVE-2026-13846

Use after free in USB in Google Chrome on Mac prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentiall…

Fix: 150.0.7871.47+
Fix from $2,300 2026-06-30
Chrome CRITICAL 9.6
CVE-2026-13843

Insufficient validation of untrusted input in Chrome for iOS in Google Chrome on iOS prior to 150.0.7871.47 allowed a remote attacker who had comprom…

Fix: 150.0.7871.47+
Fix from $2,300 2026-06-30
Chrome CRITICAL 9.6
CVE-2026-13798

Heap buffer overflow in Chromecast in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to pote…

Fix: 150.0.7871.46+
Fix from $2,300 2026-06-30
Chrome CRITICAL 9.6
CVE-2026-13797

Insufficient validation of untrusted input in Chromecast in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the re…

Fix: 150.0.7871.47+
Fix from $2,300 2026-06-30
Chrome CRITICAL 9.6
CVE-2026-13796

Integer overflow in Chromecast in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentia…

Fix: 150.0.7871.46+
Fix from $2,300 2026-06-30
Chrome CRITICAL 9.6
CVE-2026-13792

Use after free in Touchbar in Google Chrome on Mac prior to 150.0.7871.47 allowed a remote attacker to potentially perform a sandbox escape via a cra…

Fix: 150.0.7871.47+
Fix from $2,300 2026-06-30
Chrome CRITICAL 9.6
CVE-2026-13789

Use after free in GPU in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perfo…

Fix: 150.0.7871.47+
Fix from $2,300 2026-06-30
Chrome CRITICAL 9.6
CVE-2026-13785

Use after free in Bluetooth in Google Chrome on Mac prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI ge…

Fix: 150.0.7871.47+
Fix from $2,300 2026-06-30
Chrome CRITICAL 10.0
CVE-2026-13782

Use after free in Browser in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially p…

Fix: 150.0.7871.46+
Fix from $2,300 2026-06-30
Chrome CRITICAL 9.6
CVE-2026-13781

Insufficient validation of untrusted input in Skia in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer…

Fix: 150.0.7871.46+
Fix from $2,300 2026-06-30
Chrome CRITICAL 9.6
CVE-2026-13780

Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the rendere…

Fix: 150.0.7871.46+
Fix from $2,300 2026-06-30
Chrome CRITICAL 9.8
CVE-2026-13776

Type Confusion in Dawn in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perf…

Fix: 150.0.7871.47+
Fix from $2,300 2026-06-30
Chrome CRITICAL 9.8
CVE-2026-13775

Use after free in GPU in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perfo…

Fix: 150.0.7871.47+
Fix from $2,300 2026-06-30
Unclassified CRITICAL 9.8
CVE-2026-58449

txtai through 9.10.0, fixed in commit 11b32da, exposes an API /reindex endpoint whose function body parameter is resolved through txtai.util.Resolver…

Patch available
Fix from $2,300 2026-06-30
Unclassified CRITICAL 9.8
CVE-2026-50003

A malicious or compromised server can make a DCMTK client using bit-preserving C-GET storage mode write files outside the chosen output directory, us…

Mitigation only
Fix from $2,300 2026-06-30
Unclassified CRITICAL 9.8
CVE-2026-37106

An issue in DokuWiki 2025-05-14b "Librarian" 56.2 allows a remote attacker to create an account via the register function in inc/auth.php. NOTE: this…

Mitigation only
Fix from $2,300 2026-06-30
Websphere Application Server CRITICAL 9.8
CVE-2026-11541

IBM CICS Transaction Gateway for Multiplatforms 9.1, 9.2, 9.3, and 10.1 IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application S…

Fix: 8.5.5.31 / 9.0.5.29+
Fix from $2,300 2026-06-30
Langflow CRITICAL 9.1
CVE-2026-7874

IBM Langflow OSS 1.0.0 through 1.10.0 Langflow could allow disclosure of all stored credentials due to the use of a weak and reversible key derivatio…

Fix: after 1.10.0
Fix from $2,300 2026-06-30
Langflow CRITICAL 9.9
CVE-2026-7873

IBM Langflow OSS 1.0.0 through 1.10.0 allows authenticated attackers to execute arbitrary OS commands and read sensitive files including credentials,…

Fix: after 1.10.0
Fix from $2,300 2026-06-30
Langflow CRITICAL 9.8
CVE-2026-7871

IBM Langflow OSS 1.0.0 through 1.10.0 allows users with Redis access to execute arbitrary code with full application privileges, compromising all sec…

Fix: after 1.10.0
Fix from $2,300 2026-06-30
Langflow CRITICAL 9.8
CVE-2026-7803

IBM Langflow OSS 1.0.0 through 1.10.0 could allow arbitrary code execution due to improper validation of flow nodes with missing or empty component t…

Fix: after 1.10.0
Fix from $2,300 2026-06-30