Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2026-57621 Unauthenticated PHP Object Injection in Booktics <= 1.0.21 versions. Mitigation only Fix from $2,3002026-07-02 CRITICAL 9.1 CVE-2026-27436 Editor Arbitrary Code Execution in Five Star Business Profile and Schema <= 2.3.19 versions. Mitigation only Fix from $2,3002026-07-02 CRITICAL 9.9 CVE-2026-27419 Subscriber Arbitrary File Upload in Zegen <= 1.1.9 versions. No fix yet Fix from $2,3002026-07-02 CRITICAL 9.4 CVE-2026-14439 A path traversal vulnerability exists in the Git Service component shared by Altium Enterprise Server and Altium 365. The service accepts a sequence … Mitigation only Fix from $2,3002026-07-01 CRITICAL 9.6 CVE-2026-14425 Use after free in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML … Chrome 150.0.7871.46+ Fix from $2,3002026-07-01 CRITICAL 9.6 CVE-2026-14424 Use after free in Dawn in Google Chrome on Mac prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted… Chrome 150.0.7871.46+ Fix from $2,3002026-07-01 CRITICAL 9.6 CVE-2026-14423 Type Confusion in Tint in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML p… Chrome 150.0.7871.46+ Fix from $2,3002026-07-01 CRITICAL 9.6 CVE-2026-14420 Out of bounds read and write in Dawn in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a … Chrome 150.0.7871.46+ Fix from $2,3002026-07-01 CRITICAL 9.6 CVE-2026-14419 Use after free in Skia in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML p… Chrome 150.0.7871.46+ Fix from $2,3002026-07-01 CRITICAL 9.6 CVE-2026-14417 Use after free in Dawn in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML p… Chrome 150.0.7871.46+ Fix from $2,3002026-07-01 CRITICAL 9.6 CVE-2026-14416 Out of bounds read in Dawn in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HT… Chrome 150.0.7871.46+ Fix from $2,3002026-07-01 CRITICAL 9.6 CVE-2026-14411 Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbo… Chrome 150.0.7871.46+ Fix from $2,3002026-07-01 CRITICAL 9.6 CVE-2026-14405 Uninitialized Use in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HT… Chrome 150.0.7871.46+ Fix from $2,3002026-07-01 CRITICAL 9.6 CVE-2026-14398 Use after free in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML … Chrome 150.0.7871.46+ Fix from $2,3002026-07-01 CRITICAL 9.6 CVE-2026-14397 Out of bounds write in ANGLE in Google Chrome on Mac prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a c… Chrome 150.0.7871.46+ Fix from $2,3002026-07-01 CRITICAL 9.6 CVE-2026-14392 Out of bounds write in Tint in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted H… Chrome 150.0.7871.46+ Fix from $2,3002026-07-01 CRITICAL 9.6 CVE-2026-14390 Use after free in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML … Chrome 150.0.7871.46+ Fix from $2,3002026-07-01 CRITICAL 9.6 CVE-2026-14387 Integer overflow in Skia in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML… Chrome 150.0.7871.46+ Fix from $2,3002026-07-01 CRITICAL 9.6 CVE-2026-14382 Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbo… Chrome 150.0.7871.46+ Fix from $2,3002026-07-01 CRITICAL 9.8 CVE-2026-52186 SQL Injection vulnerability in UTT nv518G nv518GV3v3.2.7-210919-161313 allows a remote attacker to execute arbitrary code via the gohead/sub_463bbc c… Mitigation only Fix from $2,3002026-07-01 CRITICAL 9.8 CVE-2026-58457 Shenzhen Aitemi M300 Wi-Fi Repeater (hardware model MT02) contains an unauthenticated OS command injection vulnerability that allows network-adjacent… Mitigation only Fix from $2,3002026-07-01 CRITICAL 9.8 CVE-2026-14363 Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in The Wikimedia Foundation Mediawiki - Cargo Exte… Cargo 3.9.1+ Fix from $2,3002026-07-01 CRITICAL 9.6 CVE-2026-53492 containerd is an open-source container runtime. In Versions prior to 2.3.2, 2.2.5 and 2.1.9, the CRI implementation improperly trusts Container Devic… Containerd 2.1.9 / 2.2.5+ Fix from $2,3002026-07-01 CRITICAL 9.8 CVE-2026-51947 An issue in Pivotal CRM 6.6.4.08 and systems using patch-ghi-15381-cwe-502-20251225.zip (fixed in Pivotal CRM 6.6.5.10 and Patch_CWE502_20260316.zip)… Mitigation only Fix from $2,3002026-07-01 CRITICAL 9.9 CVE-2026-50195 containerd is an open-source container runtime. Versions prior to 2.3.2, 2.2.5 and 2.1.9 contain a vulnerability in the CRI checkpoint import process… Containerd 2.1.9 / 2.2.5+ Fix from $2,3002026-07-01 CRITICAL 10.0 CVE-2026-50160 Hoppscotch is an API development ecosystem. In self-hosted deployments of hoppscotch-backend from version 2026.4.1 and earlier, the unauthenticated P… Hoppscotch 2026.5.0+ Fix from $2,3002026-07-01 CRITICAL 9.8 CVE-2026-58521 Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in The Wikimedia Foundation Mediawiki - Cargo Exte… Cargo 3.9.1+ Fix from $2,3002026-07-01 CRITICAL 9.8 CVE-2026-58453 JAIOTlink C492A-W6 Wi-Fi IP cameras running firmware 4.8.30.57701411 contain a hard-coded credentials vulnerability that allows network-adjacent atta… Mitigation only Fix from $2,3002026-07-01 CRITICAL 9.8 CVE-2026-34117 Guardian language-system passes the id GET parameter directly into a PHP exec() call in text_to_subtitles.php (line 19) without sanitization: exec(\"… Mitigation only Fix from $2,3002026-07-01 CRITICAL 9.8 CVE-2026-34116 Guardian language-system passes the id GET parameter directly into a PHP exec() call in transcribe.php (line 15) without sanitization: exec(\"php job… Mitigation only Fix from $2,3002026-07-01