boxscore/security
Thursday, June 4, 2026 · all times UTC← 2026-06-03 · archive · 2026-06-05 →

624 CVEs published June 4, 2026: 74 critical, 263 high, 262 medium, 25 low; 0 in KEV; 8 with a public exploit reference; 0 awaiting enrichment. Elevated volume. 25 rendered as box scores below; the remaining 599 in the results table.

Standings

League
MTDYTD2025 same span2025 full
CVEs published1378575010422563
KEV catalog size1670

249 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. C/H/M/L = YTD disclosures by severity band. KEV = catalog entries all-time / YTD. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100. Med CVSS / Med EPSS = medians over the vendor's YTD disclosures. Δ = this month-to-date minus the same day-span of last month.

Operating Systems & Platforms
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
linux3410008163028612730.37.8.0013-27
google48866258331255157450.87.8.0023+488
microsoft7497443331030378275.47.8.0046+7
red hat872832284400.07.2.0035+6
apple04701227193714.96.2.00340
canonical0140455000.05.5.00090
freebsd070520000.07.8.00200
suse020200000.08.2.00200
Network & Infrastructure
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
cisco215314096853.37.0.0694+2
ivanti16020033466.78.8.5751+1
checkpoint060330300.06.5.03380
fortinet06130028350.07.9.43300
zyxel2300301100.06.5.0017+2
f50320007133.39.2.09960
ubiquiti031200400.08.8.00680
broadcom02000042100.0.19900
Open Source Ecosystems
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
apache32648262724011.67.2.0053+31
mozilla41033401300.07.4.0035+4
gitlab0901604222.24.3.00320
drupal0511305120.05.1.00260
docker140400100.08.8.0022+1
github021100000.08.1.03470
jenkins000000600
joomla000000100
Enterprise Applications
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
ibm5541326150700.07.5.0031+5
oracle128815404013.68.1.0027+1
progress591710900.07.5.0036+5
solarwinds14110011375.08.7.7758+1
adobe04010075375.08.6.27760
veeam031200400.08.6.00400
zohocorp020110000.07.1.01040
atlassian0000001300
Industrial & Embedded
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
synology52325133000.05.6.0025+5
d-link25031026120.07.4.0059+2
abb440400000.07.3.0024+4
siemens120110100.07.3.0026+1
hitachi energy020020000.05.7.00140
hikvision01000021100.01.00000
dahua000000200
qnap000000800
Other
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
edimax051032019100.07.4.00590
concrete cms1451101321000.06.0.0015+1
open ises044221210000.07.1.00210
sourcecodester2042001428000.02.1.0025+20
helmholz04203930000.07.1.00260
mb connect line04203930000.07.1.00260
acer2636111960000.08.7.0024+26
nvidia23582070000.07.8.0029+2

Leaders (trailing 30 days unless noted)

Highest EPSS
CVEEPSS%ileCVSS
CVE-2008-4250.987599.9
CVE-2026-0257.939199.8
CVE-2026-43284.932499.88.8
CVE-2026-43500.928599.87.8
CVE-2010-0249.918899.8
CVE-2026-20182.915299.8
CVE-2026-42208.894299.8
CVE-2026-9082.883299.89.8
CVE-2009-3459.865899.7
CVE-2025-34291.838499.7
Highest CVSS
CVECVSSEPSSNote
CVE-2026-4817210.0.1891KEV
CVE-2026-805410.0.0158
CVE-2026-4508710.0.0147
CVE-2026-4919910.0.0134
CVE-2026-4399710.0.0098
CVE-2026-4282610.0.0084
CVE-2026-2022310.0.0083
CVE-2026-4400510.0.0083
CVE-2026-4400610.0.0081
CVE-2026-4684010.0.0073
Most disclosures (vendor)
VendorCVEs
google656
linux607
microsoft177
ibm54
edimax51
apache49
red hat47
concrete cms45
open ises44
helmholz42
Most KEV additions (YTD)
VendorKEV
microsoft27
cisco8
apple7
google5
ivanti4
synacor4
adobe3
fortinet3
linux3
smartertools3
Most-affected ecosystems
EcosystemAdvisories
Maven24
PyPI10
Packagist7
crates.io2
npm2
Fastest to KEV
CVEVendorDays
CVE-2008-4250Microsoft0
CVE-2009-1537Microsoft0
CVE-2009-3459Adobe0
CVE-2010-0249Microsoft0
CVE-2010-0806Microsoft0
CVE-2022-0492Linux0
CVE-2024-21182Oracle0
CVE-2025-34291Langflow0
CVE-2025-48595Google0
CVE-2026-0257Palo Alto Networks0
Longest unpatched (KEV due date passed)
CVEVendorDueDays over
CVE-2021-27104Accellion2021-11-171660
CVE-2021-27102Accellion2021-11-171660
CVE-2021-27101Accellion2021-11-171660
CVE-2021-27103Accellion2021-11-171660
CVE-2021-21017Adobe2021-11-171660
CVE-2021-28550Adobe2021-11-171660
CVE-2021-42013Apache2021-11-171660
CVE-2021-41773Apache2021-11-171660
CVE-2021-30858Apple2021-11-171660
CVE-2021-30860Apple2021-11-171660

Transactions

EXPLOIT PUBLISHEDCVE-2026-10796 (nvm-sh nvm). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-11216 (Google Chrome). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-45287 (open-telemetry go.opentelemetry.io/otel/schema/v1.1). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-47706 (strawberry-graphql strawberry). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-47707 (strawberry-graphql strawberry). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-5066 (zephyrproject-rtos Zephyr). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-5589 (zephyrproject-rtos Zephyr). Public exploit reference added.

DUE DATE PASSEDCVE-2008-4250 (Microsoft Windows). CISA remediation deadline was June 3, 2026; still in catalog.

DUE DATE PASSEDCVE-2009-1537 (Microsoft DirectX). CISA remediation deadline was June 3, 2026; still in catalog.

DUE DATE PASSEDCVE-2009-3459 (Adobe Acrobat and Reader). CISA remediation deadline was June 3, 2026; still in catalog.

DUE DATE PASSEDCVE-2010-0249 (Microsoft Internet Explorer). CISA remediation deadline was June 3, 2026; still in catalog.

DUE DATE PASSEDCVE-2010-0806 (Microsoft Internet Explorer). CISA remediation deadline was June 3, 2026; still in catalog.

DUE DATE PASSEDCVE-2026-41091 (Microsoft Malware Protection Engine). CISA remediation deadline was June 3, 2026; still in catalog.

DUE DATE PASSEDCVE-2026-45498 (Microsoft Defender Antimalware Platform). CISA remediation deadline was June 3, 2026; still in catalog.

Yesterday's Results

624 CVEs published. 25 box scores and 375 table rows below; the remaining 224 continue on page 2 — every CVE is listed, nothing truncated.

Microsoft Microsoft 365 Copilot — M365 Copilot Information Disclosure Vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  N  N    7.5   .0764   94.1     —
AFFECTED
  Product                Versions  Fixed
  Microsoft 365 Copilot  - –       —
TIMELINE
  Apr 30  Reserved by CNA
  Jun 4   Published (CNA: microsoft)
CWE-77 · CNA: microsoft · 1 reference · NVD status: Modified
Arista Networks EOS — On affected platforms running Arista EOS with OpenConfig configured, a gNMI Set request can be run when it should have been rejected (No SSL Profiles Enabled).
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   N   H   H    7.2   .0443   90.6     —
AFFECTED
  Product  Versions  Fixed
  EOS      4.29.0 –  —
TIMELINE
  Feb 26  Reserved by CNA
  Jun 4   Published (CNA: Arista)
CWE-306 · CNA: Arista · 1 reference · NVD status: Awaiting Analysis
Shibby Tomato Web UI rstats rstats_path os command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   H   N   H   H   H    7.3   .0270   84.6     —
AFFECTED
  Product  Versions     Fixed
  Tomato   1.28.0000 –  —
TIMELINE
  Jun 4   Reserved by CNA
  Jun 4   Published (CNA: VulDB)
CWE-77, CWE-78 · CNA: VulDB · 7 references · NVD status: Deferred
Shibby Tomato Web UI rc start_vpnserver os command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   H   N   H   H   H    7.3   .0263   84.3     —
AFFECTED
  Product  Versions     Fixed
  Tomato   1.28.0000 –  —
TIMELINE
  Jun 4   Reserved by CNA
  Jun 4   Published (CNA: VulDB)
CWE-77, CWE-78 · CNA: VulDB · 6 references · NVD status: Deferred
Shibby Tomato Web UI rc start_dhcpc os command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   H   N   H   H   H    7.3   .0220   81.0     —
AFFECTED
  Product  Versions     Fixed
  Tomato   1.28.0000 –  —
TIMELINE
  Jun 4   Reserved by CNA
  Jun 4   Published (CNA: VulDB)
CWE-77, CWE-78 · CNA: VulDB · 6 references · NVD status: Deferred
Shibby Tomato Web UI rc start_6rd_tunnel os command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   H   N   H   H   H    7.3   .0220   81.0     —
AFFECTED
  Product  Versions     Fixed
  Tomato   1.28.0000 –  —
TIMELINE
  Jun 4   Reserved by CNA
  Jun 4   Published (CNA: VulDB)
CWE-77, CWE-78 · CNA: VulDB · 6 references · NVD status: Deferred
Microsoft Azure HorizonDB — Azure HorizonDB Elevation of Privilege Vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0103   61.0     —
AFFECTED
  Product          Versions  Fixed
  Azure HorizonDB  - –       —
TIMELINE
  May 21  Reserved by CNA
  Jun 4   Published (CNA: microsoft)
CWE-290 · CNA: microsoft · 1 reference · NVD status: Analyzed
n/a n/a — The network diagnosis (ping) module in Neterbit NW-431F Router 20241014-IR03 and before is vulnerable to OS…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0103   60.7     —
AFFECTED
  Product  Versions  Fixed
  n/a      n/a –     —
TIMELINE
  Dec 8   Reserved by CNA
  Jun 4   Published (CNA: mitre)
CWE-78 · CNA: mitre · 2 references · NVD status: Deferred
Microsoft Exchange Online Information Disclosure Vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  N  N    7.5   .0101   60.4     —
AFFECTED
  Product                    Versions  Fixed
  Microsoft Exchange Online  - –       —
TIMELINE
  May 21  Reserved by CNA
  Jun 4   Published (CNA: microsoft)
CWE-285 · CNA: microsoft · 1 reference · NVD status: Analyzed
Google Chrome — Uninitialized Use in Dawn in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-o…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   R  C  H  N  N    7.4   .0098   59.5     —
AFFECTED
  Product  Versions         Fixed
  Chrome   149.0.7827.53 –  —
TIMELINE
  Jun 4   Reserved by CNA
  Jun 4   Published (CNA: Chrome)
CWE-457 · CNA: Chrome · 2 references · NVD status: Modified
Web-Dorado Contact Form Maker — Contact Form by WD 1.13.1 CSRF to Local File Inclusion
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   L   L   N   N   N   N   L   N    5.1   .0089   56.3     —
AFFECTED
  Product             Versions  Fixed
  Contact Form Maker  1.13.1 –  —
TIMELINE
  Jun 4   Reserved by CNA
  Jun 4   Published (CNA: VulnCheck)
CWE-22 · CNA: VulnCheck · 4 references · NVD status: Deferred
Microsoft Graph Information Disclosure Vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  N  N    6.5   .0076   52.1     —
AFFECTED
  Product          Versions  Fixed
  Microsoft Graph  - –       —
TIMELINE
  May 19  Reserved by CNA
  Jun 4   Published (CNA: microsoft)
CWE-200 · CNA: microsoft · 1 reference · NVD status: Analyzed
OpenStack Mistral through 22.0.0 allows Arbitrary Remote Code Execution when the API is exposed. There are …
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  C  H  H  H    9.9   .0073   51.4     —
AFFECTED
  Product  Versions  Fixed
  Mistral  20.0.0 –  —
TIMELINE
  Apr 20  Reserved by CNA
  Jun 4   Published (CNA: mitre)
CWE-863, CWE-749 · CNA: mitre · 7 references · NVD status: Awaiting Analysis
Microsoft Copilot Chat (Microsoft Edge) — Copilot Chat (Microsoft Edge) Information Disclosure Vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  N  N    7.5   .0073   51.3     —
AFFECTED
  Product                        Versions  Fixed
  Copilot Chat (Microsoft Edge)  - –       —
TIMELINE
  May 19  Reserved by CNA
  Jun 4   Published (CNA: microsoft)
CWE-74 · CNA: microsoft · 1 reference · NVD status: Analyzed
Seagull Software BarTender Unauthenticated RCE via .NET Remoting Service
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0073   51.2     —
AFFECTED
  Product         Versions     Fixed
  BarTender 2010  unspecified  —
  BarTender 2016  unspecified  —
  BarTender 2019  unspecified  —
TIMELINE
  Feb 2   Reserved by CNA
  Jun 4   Published (CNA: VulnCheck)
CWE-306, CWE-502 · CNA: VulnCheck · 2 references · NVD status: Awaiting Analysis
Acer Connect M6E 5G Portable WiFi Router — VPN Command Injection Vulnerability
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   A   L   N   H   N   H   H   H    8.5   .0072   50.9     —
AFFECTED
  Product                              Versions     Fixed
  Connect M6E 5G Portable WiFi Router  unspecified  —
TIMELINE
  Jun 4   Reserved by CNA
  Jun 4   Published (CNA: Acer)
CWE-78 · CNA: Acer · 1 reference · NVD status: Analyzed
Mobatek MobaXterm 12.1 Buffer Overflow via Sessions File
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0064   47.6     —
AFFECTED
  Product            Versions  Fixed
  Mobatek MobaXterm  12.1 –    —
TIMELINE
  Jun 4   Reserved by CNA
  Jun 4   Published (CNA: VulnCheck)
CWE-120 · CNA: VulnCheck · 3 references · NVD status: Deferred
OpenStack Ironic through before 35.0.2 allows file overwrite via directory traversal during deployment with…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  H  N    8.1   .0060   45.9     —
AFFECTED
  Product  Versions  Fixed
  Ironic   17.0.0 –  —
TIMELINE
  May 22  Reserved by CNA
  Jun 4   Published (CNA: mitre)
CWE-23 · CNA: mitre · 3 references · NVD status: Analyzed
Python Software Foundation CPython — tarfile.data_filter path traversal bypass allows writing outside the extraction directory
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   A   N   H   N    6.9   .0060   45.8     —
AFFECTED
  Product  Versions     Fixed
  CPython  unspecified  —
TIMELINE
  May 4   Reserved by CNA
  Jun 4   Published (CNA: PSF)
CWE-22 · CNA: PSF · 11 references · NVD status: Awaiting Analysis
n/a n/a — Incorrect access control in the web management interface of T3 Technology CPE models T625Pro v1.0.07, T6825…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0055   43.3     —
AFFECTED
  Product  Versions  Fixed
  n/a      n/a –     —
TIMELINE
  Apr 6   Reserved by CNA
  Jun 4   Published (CNA: mitre)
CWE-284 · CNA: mitre · 4 references · NVD status: Deferred
Apache Fory: Java ReplaceResolverSerializer deserialization checks bypass
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  N    9.1   .0052   41.8     —
AFFECTED
  Product      Versions     Fixed
  Apache Fory  unspecified  —
TIMELINE
  Jun 3   Reserved by CNA
  Jun 4   Published (CNA: apache)
CWE-502 · CNA: apache · 2 references · NVD status: Analyzed
Google Chrome — Use after free in WebRTC in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbit…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   R  U  H  H  H    8.8   .0049   40.1     —
AFFECTED
  Product  Versions         Fixed
  Chrome   149.0.7827.53 –  —
TIMELINE
  Jun 4   Reserved by CNA
  Jun 4   Published (CNA: Chrome)
CWE-416 · CNA: Chrome · 2 references · NVD status: Analyzed
Google Chrome — Use after free in WebRTC in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbit…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   R  U  H  H  H    8.8   .0049   40.1     —
AFFECTED
  Product  Versions         Fixed
  Chrome   149.0.7827.53 –  —
TIMELINE
  Jun 4   Reserved by CNA
  Jun 4   Published (CNA: Chrome)
CWE-416 · CNA: Chrome · 2 references · NVD status: Analyzed
Google Chrome — Use after free in WebRTC in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbit…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   R  U  H  H  H    8.8   .0049   40.1     —
AFFECTED
  Product  Versions         Fixed
  Chrome   149.0.7827.53 –  —
TIMELINE
  Jun 4   Reserved by CNA
  Jun 4   Published (CNA: Chrome)
CWE-416 · CNA: Chrome · 2 references · NVD status: Analyzed
Google Chrome — Use after free in WebRTC in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbit…
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   R  U  H  H  H    8.8   .0049   40.1     —
AFFECTED
  Product  Versions         Fixed
  Chrome   149.0.7827.53 –  —
TIMELINE
  Jun 4   Reserved by CNA
  Jun 4   Published (CNA: Chrome)
CWE-416 · CNA: Chrome · 2 references · NVD status: Analyzed
Remainder (ranked, continued)
CVECVSSEPSS %ileVendorProductCWETitle
CVE-2026-108828.838.5GoogleChromeCWE-416Use after free in Network in Google Chrome prior to 149.0.7827.53 allowed a r…
CVE-2026-359069.638.4n/an/aCWE-78An undocumented debug CGI endpoint in T3 Technology CPE models T625Pro v1.0.0…
CVE-2025-697558.238.3n/an/aCWE-78An issue in Neterbit NW-431F Router vNW-431F-20241014-IR03 allows a remote at…
CVE-2026-107967.538.3nvm-shnvmCWE-78nvm executes commands from a malicious Node.js mirror's version strings
CVE-2019-257279.338.1ad-manager-wdAd Manager WDCWE-22WordPress Plugin ad manager wd 1.0.11 Arbitrary File Download
CVE-2026-109398.837.8GoogleChromeCWE-416Use after free in WebRTC in Google Chrome prior to 149.0.7827.53 allowed a re…
CVE-2026-109758.837.8GoogleChromeCWE-416Use after free in WebRTC in Google Chrome prior to 149.0.7827.53 allowed a re…
CVE-2026-109828.837.8GoogleChromeCWE-416Use after free in WebXR in Google Chrome prior to 149.0.7827.53 allowed a rem…
CVE-2026-110038.837.8GoogleChromeCWE-416Use after free in WebRTC in Google Chrome prior to 149.0.7827.53 allowed a re…
CVE-2025-674469.837.7n/an/aCWE-384Improper Authentication (Authentication Bypass) exists in Neterbit NW-431F Ro…
CVE-2026-454978.837.5MicrosoftMicrosoft 365 CopilotCWE-77Microsoft M365 Copilot Remote Code Execution Vulnerability
CVE-2026-107377.537.4smartypantsSP Project & Document ManagerCWE-862SP Project & Document Manager <= 4.71 - Missing Authorization to Unauthentica…
CVE-2026-108809.836.3OsnexusQuantaStorCWE-89Unauthenticated SQL Injection in Osnexus Quantastor
CVE-2026-410658.936.1TautulliTautulliCWE-1336Tautulli Vulnerable to Unauthenticated/Authenticated Remote Code Execution vi…
CVE-2026-412498.236.1coreshopCoreShopCWE-94CoreShop Vulnerable to Remote Code Execution (RCE) via Insecure `pull_request…
CVE-2026-505897.536.1OpenStackIronicCWE-770In OpenStack Ironic 32 before 37.0.0, an unauthenticated malicious user could…
CVE-2026-491909.435.5AcerConnect M6E 5G Portable WiFi RouterCWE-78Missing Per-Instruction Authorization Checks
CVE-2026-109108.835.5GoogleChromeCWE-843Type Confusion in V8 in Google Chrome prior to 149.0.7827.53 allowed a remote…
CVE-2026-359059.835.1n/an/aCWE-259T3 Technology CPE models T625Pro v1.0.07, T6825G v1.0.03, and T7281 v1.0.03 w…
CVE-2026-109418.834.9GoogleChromeCWE-125Out of bounds memory access in Skia in Google Chrome prior to 149.0.7827.53 a…
CVE-2026-477075.334.8strawberry-graphqlstrawberryCWE-400Strawberry GraphQL's Bypass of MaxAliasesLimiter via Fragment Spreads leading…
CVE-2026-109048.834.2GoogleChromeCWE-20Inappropriate implementation in V8 in Google Chrome prior to 149.0.7827.53 al…
CVE-2026-109288.834.2GoogleChromeCWE-94Script injection in Headless in Google Chrome prior to 149.0.7827.53 allowed …
CVE-2026-88297.534.0OALDERSHTML::EntitiesCWE-416HTML::Entities versions before 3.84 for Perl read freed heap memory in _decod…
CVE-2026-108878.133.6GoogleChromeCWE-416Use after free in Chromoting in Google Chrome on Mac prior to 149.0.7827.53 a…
CVE-2026-109358.832.5GoogleChromeCWE-843Type Confusion in V8 in Google Chrome prior to 149.0.7827.53 allowed a remote…
CVE-2026-109368.832.5GoogleChromeCWE-843Type Confusion in V8 in Google Chrome prior to 149.0.7827.53 allowed a remote…
CVE-2026-109628.832.5GoogleChromeCWE-843Type Confusion in Media in Google Chrome prior to 149.0.7827.53 allowed a rem…
CVE-2026-108819.632.2GoogleChromeCWE-125Out of bounds read and write in ANGLE in Google Chrome prior to 149.0.7827.53…
CVE-2026-108838.832.2GoogleChromeCWE-787Type Confusion in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a rem…
CVE-2026-108958.832.1GoogleChromeCWE-416Use after free in Ozone in Google Chrome prior to 149.0.7827.53 allowed a rem…
CVE-2026-109028.832.1GoogleChromeCWE-416Use after free in Ozone in Google Chrome prior to 149.0.7827.53 allowed a rem…
CVE-2026-109138.832.1GoogleChromeCWE-416Use after free in ANGLE in Google Chrome on Windows prior to 149.0.7827.53 al…
CVE-2026-109148.832.1GoogleChromeCWE-416Use after free in ANGLE in Google Chrome on Windows prior to 149.0.7827.53 al…
CVE-2026-109548.832.1GoogleChromeCWE-416Use after free in Actor in Google Chrome prior to 149.0.7827.53 allowed a rem…
CVE-2026-109568.832.1GoogleChromeCWE-416Use after free in MimeHandlerView in Google Chrome prior to 149.0.7827.53 all…
CVE-2026-454318.732.0GX INDIAGX Earth 2022CWE-78Command Injection Vulnerability in GX Earth ONT Models
CVE-2026-4918510.031.8AcerConnect M6E 5G Portable WiFi RouterCWE-78Instruction Injection via FieldX MDM
CVE-2026-111188.831.8GoogleChromeCWE-416Use after free in WebRTC in Google Chrome prior to 149.0.7827.53 allowed a re…
CVE-2026-111028.831.8GoogleChromeCWE-474Inappropriate implementation in Isolated Web Apps in Google Chrome prior to 1…
CVE-2025-88738.731.7Arista NetworksEOSCWE-1286Arista EOS Dataplane Denial of Service via Malformed IPsec Packet
CVE-2025-713169.231.6SQLitesqldiffCWE-176SQLite sqldiff remote code execution via argument injection
CVE-2026-109558.831.2GoogleChromeCWE-843Type Confusion in ANGLE in Google Chrome on Windows prior to 149.0.7827.53 al…
CVE-2026-108858.830.5GoogleChromeCWE-416Use after free in Chrome for iOS in Google Chrome on iOS prior to 149.0.7827.…
CVE-2026-108968.830.5GoogleChromeCWE-416Use after free in Chrome for iOS in Google Chrome on iOS prior to 149.0.7827.…
CVE-2026-109467.530.6GoogleChromeCWE-122Heap buffer overflow in Media in Google Chrome prior to 149.0.7827.53 allowed…
CVE-2026-38207.230.1SMCIAS-2115HS-TNRCWE-78Supermicro BMC's SMTP service contains a command injection vulnerability
CVE-2026-408987.529.8quic-goquic-goCWE-770quic-go: HTTP/3 QPACK Trailer Expansion Memory Exhaustion
CVE-2026-412368.829.7froxlorfroxlorCWE-59Froxlor has privilege escalation in SSH key synchronization via symlinked `au…
CVE-2026-109578.829.2GoogleChromeCWE-416Use after free in Glic in Google Chrome prior to 149.0.7827.53 allowed a remo…
CVE-2026-109588.829.2GoogleChromeCWE-416Use after free in Chrome for iOS in Google Chrome on iOS prior to 149.0.7827.…
CVE-2026-109598.829.2GoogleChromeCWE-416Use after free in Input in Google Chrome on Android prior to 149.0.7827.53 al…
CVE-2026-109638.829.2GoogleChromeCWE-472Integer overflow in V8 in Google Chrome prior to 149.0.7827.53 allowed a remo…
CVE-2026-109648.829.2GoogleChromeCWE-472Integer overflow in V8 in Google Chrome prior to 149.0.7827.53 allowed a remo…
CVE-2026-109658.829.2GoogleChromeCWE-472Integer overflow in DevTools in Google Chrome prior to 149.0.7827.53 allowed …
CVE-2026-109878.829.2GoogleChromeCWE-472Integer overflow in V8 in Google Chrome prior to 149.0.7827.53 allowed a remo…
CVE-2026-109918.829.2GoogleChromeCWE-416Use after free in V8 in Google Chrome prior to 149.0.7827.53 allowed a remote…
CVE-2026-110008.829.2GoogleChromeCWE-416Use after free in Fonts in Google Chrome on Linux prior to 149.0.7827.53 allo…
CVE-2026-110288.829.2GoogleChromeCWE-416Use after free in Media in Google Chrome on Linux and ChromeOS prior to 149.0…
CVE-2026-110468.829.2GoogleChromeCWE-20Insufficient validation of untrusted input in Media in Google Chrome prior to…
CVE-2026-108938.829.0GoogleChromeCWE-416Use after free in Chromoting in Google Chrome prior to 149.0.7827.53 allowed …
CVE-2026-109458.829.0GoogleChromeCWE-416Use after free in PDF in Google Chrome prior to 149.0.7827.53 allowed a remot…
CVE-2026-110548.828.6GoogleChromeCWE-416Use after free in WebRTC in Google Chrome prior to 149.0.7827.53 allowed a re…
CVE-2026-110688.828.6GoogleChromeCWE-416Use after free in WebSockets in Google Chrome prior to 149.0.7827.53 allowed …
CVE-2026-110748.828.6GoogleChromeCWE-416Use after free in WebRTC in Google Chrome on Linux prior to 149.0.7827.53 all…
CVE-2026-111478.828.5GoogleChromeCWE-416Use after free in WebML in Google Chrome on Windows prior to 149.0.7827.53 al…
CVE-2026-109958.828.2GoogleChromeCWE-122Heap buffer overflow in TabStrip in Google Chrome prior to 149.0.7827.53 allo…
CVE-2026-110248.828.2GoogleChromeCWE-121Stack buffer overflow in Skia in Google Chrome prior to 149.0.7827.53 allowed…
CVE-2026-109238.828.1GoogleChromeCWE-416Use after free in WebAppInstalls in Google Chrome on Android prior to 149.0.7…
CVE-2026-109386.528.1GoogleChromeCWE-20Inappropriate implementation in Input in Google Chrome prior to 149.0.7827.53…
CVE-2019-257389.327.8framework-yHybrid ComposerCWE-306WordPress Hybrid Composer 1.4.6 Unauthenticated Settings Change
CVE-2026-108869.627.6GoogleChromeCWE-416Use after free in FileSystem in Google Chrome prior to 149.0.7827.53 allowed …
CVE-2026-454338.727.5GX INDIAGX Earth 2022CWE-321Hardcoded Cryptographic Key Vulnerability in GX Earth ONT Models
CVE-2026-109017.527.1GoogleChromeCWE-416Use after free in Passwords in Google Chrome on Mac prior to 149.0.7827.53 al…
CVE-2026-109767.426.5GoogleChromeCWE-457Uninitialized Use in Dawn in Google Chrome prior to 149.0.7827.53 allowed a r…
CVE-2026-109776.526.5GoogleChromeCWE-457Uninitialized Use in Skia in Google Chrome prior to 149.0.7827.53 allowed a r…
CVE-2026-109946.526.5GoogleChromeCWE-457Uninitialized Use in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a …
CVE-2026-109788.826.2GoogleChromeCWE-416Use after free in Chromoting in Google Chrome on Windows prior to 149.0.7827.…
CVE-2026-109868.826.2GoogleChromeCWE-472Integer overflow in Media in Google Chrome prior to 149.0.7827.53 allowed a r…
CVE-2026-109936.526.2GoogleChromeCWE-122Heap buffer overflow in Skia in Google Chrome prior to 149.0.7827.53 allowed …
CVE-2026-108988.326.1GoogleChromeCWE-121Stack buffer overflow in GPU in Google Chrome prior to 149.0.7827.53 allowed …
CVE-2026-499417.525.8RRWONet::CIDR::SetCWE-674Net::CIDR::Set versions through 0.20 for Perl did not validate IP addresses
CVE-2026-108437.225.7Red HatRed Hat OpenShift Container Platform 4CWE-250Cloud-credential-operator: cco mint-mode credentialsrequest manifests grant a…
CVE-2026-109806.525.6GoogleChromeCWE-20Insufficient validation of untrusted input in DevTools in Google Chrome prior…
CVE-2026-364996.525.6n/an/aCWE-770A missing upper-bound check in the udpif_set_threads() function of Open vSwit…
CVE-2026-108775.525.7SourceCodesterShip Ferry Ticket Reservation SystemCWE-74SourceCodester Ship Ferry Ticket Reservation System Admin Login login.php sql…
CVE-2025-466387.525.6DellBSAFE SSL-JCWE-770Dell BSAFE SSL-J contains an allocation of resources without limits or thrott…
CVE-2019-257407.125.6JoomskyJS JobsCWE-22Joomla com_jsjobs 1.2.6 Arbitrary File Deletion
CVE-2026-109067.525.4GoogleChromeCWE-416Use after free in WebAuthentication in Google Chrome prior to 149.0.7827.53 a…
CVE-2026-108929.625.4GoogleChromeCWE-787Out of bounds write in GPU in Google Chrome on Android prior to 149.0.7827.53…
CVE-2026-109319.625.4GoogleChromeCWE-416Use after free in FileSystem in Google Chrome prior to 149.0.7827.53 allowed …
CVE-2026-109729.625.4GoogleChromeCWE-416Use after free in Ozone in Google Chrome on Linux prior to 149.0.7827.53 allo…
CVE-2026-109749.625.4GoogleChromeCWE-20Insufficient validation of untrusted input in ANGLE in Google Chrome prior to…
CVE-2026-109839.625.4GoogleChromeCWE-20Insufficient validation of untrusted input in Dawn in Google Chrome prior to …
CVE-2026-110099.625.4GoogleChromeCWE-416Use after free in USB in Google Chrome on Windows prior to 149.0.7827.53 allo…
CVE-2026-110219.625.4GoogleChromeCWE-20Insufficient validation of untrusted input in GPU in Google Chrome on Windows…
CVE-2026-110659.625.4GoogleChromeCWE-416Use after free in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a rem…
CVE-2026-108918.825.4GoogleChromeCWE-416Use after free in GFX in Google Chrome on Linux prior to 149.0.7827.53 allowe…
CVE-2026-108978.825.4GoogleChromeCWE-787Inappropriate implementation in GPU in Google Chrome prior to 149.0.7827.53 a…
CVE-2026-109078.825.4GoogleChromeCWE-787Out of bounds write in ANGLE in Google Chrome prior to 149.0.7827.53 allowed …
CVE-2026-109888.825.4GoogleChromeCWE-416Use after free in Views in Google Chrome prior to 149.0.7827.53 allowed a rem…
CVE-2026-109898.825.4GoogleChromeCWE-122Inappropriate implementation in V8 in Google Chrome prior to 149.0.7827.53 al…
CVE-2026-109719.625.2GoogleChromeCWE-20Insufficient validation of untrusted input in Printing in Google Chrome on Wi…
CVE-2026-113227.125.1nesquenaHermes WebUICWE-59Hermes WebUI before 0.51.221 Path Traversal via Symlink Workspace Bypass
CVE-2026-50668.824.8zephyrproject-rtosZephyrCWE-787net: sockets: tls: Potential out-of-bounds write/read in socket_op_vtable::co…
CVE-2026-491868.624.7AcerConnect M6E 5G Portable WiFi RouterCWE-287Lack of MQTT Broker Topic Access Control Lists
CVE-2026-491888.724.5AcerConnect M6E 5G Portable WiFi RouterCWE-489Elevated Root Command Execution via ai_cmd Sockets
CVE-2023-55028.224.5Arista NetworksEOSCWE-287On affected platforms running Arista EOS with 802.1x authentication configure…
CVE-2026-110889.624.3GoogleChromeCWE-472Integer overflow in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a r…
CVE-2026-109308.124.4GoogleChromeCWE-125Out of bounds read in ANGLE in Google Chrome on Mac prior to 149.0.7827.53 al…
CVE-2026-110158.124.4GoogleChromeCWE-125Out of bounds read in WebGPU in Google Chrome prior to 149.0.7827.53 allowed …
CVE-2026-502929.824.0freedesktoplibinputCWE-93In libinput before 1.30.4 and 1.31.x before 1.31.3, libinput-device-group une…
CVE-2026-109518.824.0GoogleChromeCWE-416Use after free in Autofill in Google Chrome on iOS prior to 149.0.7827.53 all…
CVE-2026-109528.824.0GoogleChromeCWE-416Use after free in Chrome for iOS in Google Chrome on iOS prior to 149.0.7827.…
CVE-2026-110768.823.9GoogleChromeCWE-843Type Confusion in CSS in Google Chrome prior to 149.0.7827.53 allowed a remot…
CVE-2026-499427.323.9RRWONet::CIDR::SetCWE-1289Net::CIDR::Set versions through 0.20 for Perl did not validate network masks
CVE-2026-109298.323.6GoogleChromeCWE-122Heap buffer overflow in ANGLE in Google Chrome on Android prior to 149.0.7827…
CVE-2026-109498.323.6GoogleChromeCWE-122Heap buffer overflow in Video in Google Chrome prior to 149.0.7827.53 allowed…
CVE-2026-110118.123.7GoogleChromeCWE-602Insufficient policy enforcement in Password Manager in Google Chrome prior to…
CVE-2026-108022.123.6keystonejskeystoneCWE-400keystonejs keystone GraphQL API Endpoint output-field.ts resource consumption
CVE-2026-497717.623.410WebPhoto Gallery by 10WebCWE-89WordPress Photo Gallery by 10Web plugin <= 1.8.41 - SQL Injection vulnerability
CVE-2026-109687.423.4GoogleChromeCWE-20Insufficient validation of untrusted input in Dawn in Google Chrome on Window…
CVE-2026-109796.523.4GoogleChromeCWE-125Out of bounds read in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a…
CVE-2026-109856.523.4GoogleChromeCWE-125Out of bounds read in Skia in Google Chrome prior to 149.0.7827.53 allowed a …
CVE-2026-109926.523.4GoogleChromeCWE-20Insufficient data validation in Animation in Google Chrome prior to 149.0.782…
CVE-2026-110066.523.4GoogleChromeCWE-125Out of bounds read in Dawn in Google Chrome prior to 149.0.7827.53 allowed a …
CVE-2026-110076.523.4GoogleChromeCWE-20Insufficient validation of untrusted input in WebView in Google Chrome on And…
CVE-2026-110086.523.4GoogleChromeCWE-20Insufficient validation of untrusted input in WebAppInstalls in Google Chrome…
CVE-2026-110136.523.4GoogleChromeCWE-20Insufficient validation of untrusted input in Network in Google Chrome prior …
CVE-2026-111178.823.2GoogleChromeCWE-416Use after free in Views in Google Chrome on Windows prior to 149.0.7827.53 al…
CVE-2026-109118.323.2GoogleChromeCWE-20Insufficient validation of untrusted input in Media in Google Chrome prior to…
CVE-2026-109178.323.2GoogleChromeCWE-20Insufficient validation of untrusted input in Media in Google Chrome prior to…
CVE-2026-109208.323.2GoogleChromeCWE-20Insufficient validation of untrusted input in WebShare in Google Chrome on Ma…
CVE-2026-109909.623.0GoogleChromeCWE-416Use after free in Glic in Google Chrome prior to 149.0.7827.53 allowed a remo…
CVE-2026-110029.623.0GoogleChromeCWE-416Use after free in Autofill in Google Chrome prior to 149.0.7827.53 allowed a …
CVE-2026-109228.822.9GoogleChromeCWE-20Insufficient validation of untrusted input in DevTools in Google Chrome prior…
CVE-2026-406055.722.9TautulliTautulliCWE-22Tautulli Vulnerable to Authenticated Path Traversal in Cache Deletion API
CVE-2026-108742.122.9projectworldsOnline Art Gallery Shop ProjectCWE-74projectworlds Online Art Gallery Shop Project adminHome.php sql injection
CVE-2026-108752.122.9projectworldsOnline Art Gallery Shop ProjectCWE-74projectworlds Online Art Gallery Shop Project adminHome.ph sql injection
CVE-2026-41049.822.7Akmer Informatics Automation Industry and Trade Ltd. Co.TeknoPassCWE-89SQLi in Akmer Informatics' TeknoPass
CVE-2024-278927.222.8Arista NetworksEOSCWE-306On affected platforms running Arista EOS with OpenConfig configured, a gNMI S…
CVE-2026-110439.622.7GoogleChromeCWE-787Out of bounds write in ANGLE in Google Chrome on Mac prior to 149.0.7827.53 a…
CVE-2026-110479.622.7GoogleChromeCWE-20Inappropriate implementation in Base in Google Chrome on Windows prior to 149…
CVE-2026-109328.822.7GoogleChromeCWE-416Use after free in UI in Google Chrome on Android prior to 149.0.7827.53 allow…
CVE-2026-110428.822.7GoogleChromeCWE-416Use after free in Views in Google Chrome prior to 149.0.7827.53 allowed a rem…
CVE-2026-109669.622.6GoogleChromeCWE-20Inappropriate implementation in Codecs in Google Chrome prior to 149.0.7827.5…
CVE-2026-109446.522.1GoogleChromeCWE-693Insufficient policy enforcement in Autofill in Google Chrome on iOS prior to …
CVE-2026-109506.522.1GoogleChromeCWE-693Insufficient policy enforcement in Autofill in Google Chrome on iOS prior to …
CVE-2026-477065.322.1strawberry-graphqlstrawberryCWE-400Strawberry GraphQL has a Circular Fragment Reference DOS
CVE-2026-491919.321.7AcerConnect M6E 5G Portable WiFi RouterCWE-287Exposed Hard-coded M3WebServer Backend API Key
CVE-2026-112798.821.5GoogleChromeCWE-125Out of bounds read in DevTools in Google Chrome prior to 149.0.7827.53 allowe…
CVE-2026-109608.321.6GoogleChromeCWE-457Uninitialized Use in Codecs in Google Chrome prior to 149.0.7827.53 allowed a…
CVE-2026-502118.821.5AcerConnect M6E 5G Portable WiFi RouterCWE-134Exposed Factory Testing App Boundaries
CVE-2026-502195.921.3libexpat projectlibexpatCWE-416libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_GetB…
CVE-2026-109996.521.2GoogleChromeCWE-190Integer overflow in ANGLE in Google Chrome on Windows prior to 149.0.7827.53 …
CVE-2026-108848.321.1GoogleChromeCWE-416Use after free in Chromecast in Google Chrome prior to 149.0.7827.53 allowed …
CVE-2026-108898.321.1GoogleChromeCWE-125Out of bounds read in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a…
CVE-2026-108948.321.1GoogleChromeCWE-416Use after free in Printing in Google Chrome on Linux prior to 149.0.7827.53 a…
CVE-2026-109058.321.1GoogleChromeCWE-416Use after free in Network in Google Chrome prior to 149.0.7827.53 allowed a r…
CVE-2026-109088.321.1GoogleChromeCWE-416Use after free in FullScreen in Google Chrome on Windows prior to 149.0.7827.…
CVE-2026-109098.321.1GoogleChromeCWE-416Use after free in Dawn in Google Chrome prior to 149.0.7827.53 allowed a remo…
CVE-2026-109188.321.1GoogleChromeCWE-416Use after free in Viz in Google Chrome prior to 149.0.7827.53 allowed a remot…
CVE-2026-109198.321.1GoogleChromeCWE-416Use after free in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a rem…
CVE-2026-109218.321.1GoogleChromeCWE-190Integer overflow in Dawn in Google Chrome prior to 149.0.7827.53 allowed a re…
CVE-2026-109248.321.1GoogleChromeCWE-190Integer overflow in Chromecast in Google Chrome prior to 149.0.7827.53 allowe…
CVE-2026-109258.321.1GoogleChromeCWE-787Out of bounds write in Skia in Google Chrome on Mac prior to 149.0.7827.53 al…
CVE-2026-109278.321.1GoogleChromeCWE-125Out of bounds read in Dawn in Google Chrome prior to 149.0.7827.53 allowed a …
CVE-2026-109538.321.1GoogleChromeCWE-416Use after free in Core in Google Chrome on Android prior to 149.0.7827.53 all…
CVE-2026-110108.321.1GoogleChromeCWE-416Use after free in WebShare in Google Chrome on Android prior to 149.0.7827.53…
CVE-2026-110128.321.1GoogleChromeCWE-416Use after free in Serial in Google Chrome on Android prior to 149.0.7827.53 a…
CVE-2026-108997.521.1GoogleChromeCWE-416Use after free in Ozone in Google Chrome on Linux prior to 149.0.7827.53 allo…
CVE-2026-109007.521.1GoogleChromeCWE-416Use after free in Passwords in Google Chrome on Mac prior to 149.0.7827.53 al…
CVE-2026-109708.321.0GoogleChromeCWE-20Insufficient validation of untrusted input in InterestGroups in Google Chrome…
CVE-2026-109697.521.0GoogleChromeCWE-20Insufficient validation of untrusted input in Extensions in Google Chrome pri…
CVE-2026-110276.521.0GoogleChromeCWE-20Insufficient validation of untrusted input in Glic in Google Chrome prior to …
CVE-2026-110446.521.0GoogleChromeCWE-472Integer overflow in ANGLE in Google Chrome on Mac prior to 149.0.7827.53 allo…
CVE-2026-110456.521.0GoogleChromeCWE-20Insufficient validation of untrusted input in GPU in Google Chrome prior to 1…
CVE-2026-109816.520.9GoogleChromeCWE-20Insufficient validation of untrusted input in Codecs in Google Chrome prior t…
CVE-2026-449174.920.8OpenStackIronicCWE-669OpenStack Ironic before 35.0.2 allows a malicious authenticated project admin…
CVE-2026-111168.820.7GoogleChromeCWE-416Use after free in Chromoting in Google Chrome prior to 149.0.7827.53 allowed …
CVE-2024-278916.920.6Arista NetworksEOSCWE-284On affected platforms running Arista EOS with MACsec and egress ACLs configur…
CVE-2026-110498.820.5GoogleChromeCWE-416Use after free in Password Manager in Google Chrome prior to 149.0.7827.53 al…
CVE-2026-110508.820.5GoogleChromeCWE-416Use after free in V8 in Google Chrome prior to 149.0.7827.53 allowed a remote…
CVE-2026-110558.820.5GoogleChromeCWE-416Use after free in ANGLE in Google Chrome on Windows prior to 149.0.7827.53 al…
CVE-2026-110598.820.5GoogleChromeCWE-416Use after free in Blink in Google Chrome prior to 149.0.7827.53 allowed a rem…
CVE-2026-110608.820.5GoogleChromeCWE-416Use after free in Media in Google Chrome on Windows prior to 149.0.7827.53 al…
CVE-2026-110778.820.5GoogleChromeCWE-125Bad cast in Dawn in Google Chrome prior to 149.0.7827.53 allowed a remote att…
CVE-2026-110868.820.5GoogleChromeCWE-20Inappropriate implementation in Dawn in Google Chrome prior to 149.0.7827.53 …
CVE-2026-111258.820.5GoogleChromeCWE-416Use after free in Compositing in Google Chrome prior to 149.0.7827.53 allowed…
CVE-2026-111308.820.5GoogleChromeCWE-416Use after free in Media in Google Chrome prior to 149.0.7827.53 allowed a rem…
CVE-2026-111368.820.5GoogleChromeCWE-416Use after free in Canvas in Google Chrome prior to 149.0.7827.53 allowed a re…
CVE-2026-111648.820.5GoogleChromeCWE-416Use after free in Blink in Google Chrome prior to 149.0.7827.53 allowed a rem…
CVE-2026-111718.820.5GoogleChromeCWE-472Integer overflow in Blink in Google Chrome prior to 149.0.7827.53 allowed a r…
CVE-2026-111738.820.5GoogleChromeCWE-787Out of bounds write in V8 in Google Chrome prior to 149.0.7827.53 allowed a r…
CVE-2026-112118.820.5GoogleChromeCWE-472Integer overflow in V8 in Google Chrome prior to 149.0.7827.53 allowed a remo…
CVE-2026-112628.820.5GoogleChromeCWE-416Use after free in TabStrip in Google Chrome prior to 149.0.7827.53 allowed a …
CVE-2026-109126.520.5GoogleChromeCWE-20Insufficient validation of untrusted input in Extensions in Google Chrome pri…
CVE-2026-110166.520.5GoogleChromeCWE-20Insufficient validation of untrusted input in Network in Google Chrome prior …
CVE-2026-110186.520.5GoogleChromeCWE-602Insufficient policy enforcement in Actor in Google Chrome prior to 149.0.7827…
CVE-2026-110226.520.5GoogleChromeCWE-20Insufficient validation of untrusted input in DevTools in Google Chrome prior…
CVE-2026-110256.520.5GoogleChromeCWE-602Insufficient policy enforcement in Navigation in Google Chrome on Android pri…
CVE-2026-110379.620.3GoogleChromeCWE-787Out of bounds write in Codecs in Google Chrome prior to 149.0.7827.53 allowed…
CVE-2026-110308.820.3GoogleChromeCWE-416Use after free in Network in Google Chrome prior to 149.0.7827.53 allowed a r…
CVE-2026-385707.520.3n/an/aCWE-125bacnet_stack 1.3.1 contains an Out-of-bounds Read in bacnet_tag_number_decode…
CVE-2026-110959.620.0GoogleChromeCWE-20Insufficient validation of untrusted input in Codecs in Google Chrome prior t…
CVE-2026-111139.620.0GoogleChromeCWE-20Insufficient validation of untrusted input in ANGLE in Google Chrome prior to…
CVE-2026-111209.620.0GoogleChromeCWE-20Insufficient validation of untrusted input in Enterprise Reporting in Google …
CVE-2026-109158.319.9GoogleChromeCWE-416Use after free in Core in Google Chrome on iOS prior to 149.0.7827.53 allowed…
CVE-2026-110045.319.8GoogleChromeCWE-125Out of bounds read in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a…
CVE-2026-110055.319.8GoogleChromeCWE-125Out of bounds read in ANGLE in Google Chrome on Windows prior to 149.0.7827.5…
CVE-2026-109376.519.7GoogleChromeCWE-346Inappropriate implementation in Passwords in Google Chrome prior to 149.0.782…
CVE-2026-108102.119.7itsourcecodeFees Management SystemCWE-79itsourcecode Fees Management System navbar.php cross site scripting
CVE-2026-111918.819.5GoogleChromeCWE-125Out of bounds memory access in ANGLE in Google Chrome prior to 149.0.7827.53 …
CVE-2019-257268.819.3NicheofficeAll in One Video DownloaderCWE-89All in One Video Downloader 1.2 SQL Injection via admin page-edit
CVE-2019-257308.819.3ThemerigListing Hub CMSCWE-89Listing Hub CMS 1.0 SQL Injection via pages.php id
CVE-2026-412347.619.2froxlorfroxlorCWE-74Froxlor: BIND Zone File Injection via TXT Record Content
CVE-2026-110176.519.2GoogleChromeCWE-284Inappropriate implementation in Link Preview in Google Chrome prior to 149.0.…
CVE-2026-108762.119.2SourceCodesterShip Ferry Ticket Reservation SystemCWE-266SourceCodester Ship Ferry Ticket Reservation System admin improper authorization
CVE-2026-412378.619.1froxlorfroxlorCWE-74Froxlor has an incomplete fix for CVE-2026-30932
CVE-2025-598748.119.0HCLHiveCWE-1027HCL Hive Telco Observability is affected by a Required directives missing fro…
CVE-2026-109338.318.9GoogleChromeCWE-416Use after free in Audio in Google Chrome on Windows prior to 149.0.7827.53 al…
CVE-2026-109348.318.9GoogleChromeCWE-416Use after free in Autofill in Google Chrome on Android prior to 149.0.7827.53…
CVE-2026-109618.318.9GoogleChromeCWE-416Use after free in Chrome for iOS in Google Chrome on iOS prior to 149.0.7827.…
CVE-2026-109678.318.9GoogleChromeCWE-416Use after free in SurfaceCapture in Google Chrome on Android prior to 149.0.7…
CVE-2026-111539.118.4GoogleChromeCWE-1300Side-channel information leakage in Forms in Google Chrome prior to 149.0.782…
CVE-2026-112427.518.4GoogleChromeCWE-20Insufficient validation of untrusted input in Plugins in Google Chrome prior …
CVE-2026-112557.518.4GoogleChromeCWE-20Insufficient validation of untrusted input in Storage Access API in Google Ch…
CVE-2026-105867.218.4wpdevteamGutenberg Essential Blocks – Page Builder for Gutenberg Blocks & PatternsCWE-918Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns <= …
CVE-2026-439869.918.1TautulliTautulliCWE-918Tautulli vulnerable to unauthenticated SSRF in /image/<hash> via attacker-see…
CVE-2019-257288.818.1care2xCare2xCWE-89Care2x 2.7 Hospital Information System SQL Injection via ck_config
CVE-2019-257328.818.0eitubeEI-TubeCWE-89PHP EI-Tube Script 3 SQL Injection via search parameter
CVE-2019-257458.818.0jgwhite33Google Review SliderCWE-89WordPress Plugin Google Review Slider 6.1 SQL Injection via tid
CVE-2026-467417.518.1SANBEGEtsy::StatsDCWE-93Etsy::StatsD versions through 1.002002 for Perl allow metric injections
CVE-2026-109966.518.1GoogleChromeCWE-346Inappropriate implementation in Workers in Google Chrome prior to 149.0.7827.…
CVE-2026-110196.518.1GoogleChromeCWE-290Inappropriate implementation in Payments in Google Chrome on Android prior to…
CVE-2026-502662.218.1OpenStackNeutronCWE-863In OpenStack Neutron before 28.0.1, a project manager can create or update a …
CVE-2026-111448.817.7GoogleChromeCWE-416Use after free in Media in Google Chrome prior to 149.0.7827.53 allowed a rem…
CVE-2019-257299.317.7simcy_creativePDF SignerCWE-352PDF Signer 3.0 Server-Side Template Injection RCE via CSRF Cookie
CVE-2026-467395.317.7COSIMONet::StatsdCWE-93Net::Statsd versions before 0.13 for Perl allow metric injections
CVE-2026-492028.817.5AcerConnect M6E 5G Portable WiFi RouterCWE-287Unverified Meeting Recording Endpoints & Permissive CORS
CVE-2026-112636.517.4GoogleChromeCWE-693Insufficient policy enforcement in WebAuthentication in Google Chrome on Andr…
CVE-2026-110529.617.3GoogleChromeCWE-843Type Confusion in GPU in Google Chrome on Windows prior to 149.0.7827.53 allo…
CVE-2026-111009.617.3GoogleChromeCWE-416Use after free in File Input in Google Chrome on Mac prior to 149.0.7827.53 a…
CVE-2026-55896.317.2zephyrproject-rtosZephyrCWE-787Out-of-bounds write caused by an integer underflow in the Bluetooth Mesh subs…
CVE-2026-110619.617.0GoogleChromeCWE-125Type Confusion in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a rem…
CVE-2026-110669.617.0GoogleChromeCWE-20Insufficient validation of untrusted input in ANGLE in Google Chrome prior to…
CVE-2026-110336.516.6GoogleChromeCWE-457Uninitialized Use in WebML in Google Chrome on Mac prior to 149.0.7827.53 all…
CVE-2026-110396.516.6GoogleChromeCWE-457Uninitialized Use in Skia in Google Chrome prior to 149.0.7827.53 allowed a r…
CVE-2026-110576.516.6GoogleChromeCWE-457Uninitialized Use in Skia in Google Chrome prior to 149.0.7827.53 allowed a r…
CVE-2026-110646.516.6GoogleChromeCWE-457Race in GPU in Google Chrome on Android prior to 149.0.7827.53 allowed a remo…
CVE-2026-110676.516.6GoogleChromeCWE-457Uninitialized Use in Dawn in Google Chrome prior to 149.0.7827.53 allowed a r…
CVE-2026-110876.516.6GoogleChromeCWE-457Uninitialized Use in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a …
CVE-2026-110896.516.6GoogleChromeCWE-457Uninitialized Use in Media in Google Chrome prior to 149.0.7827.53 allowed a …
CVE-2026-110906.516.6GoogleChromeCWE-457Uninitialized Use in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a …
CVE-2026-111016.516.6GoogleChromeCWE-457Uninitialized Use in Dawn in Google Chrome on Windows prior to 149.0.7827.53 …
CVE-2026-111046.516.6GoogleChromeCWE-457Uninitialized Use in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a …
CVE-2026-111096.516.6GoogleChromeCWE-457Uninitialized Use in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a …
CVE-2026-111106.516.6GoogleChromeCWE-457Uninitialized Use in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a …
CVE-2026-111236.516.6GoogleChromeCWE-457Uninitialized Use in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a …
CVE-2026-111376.516.6GoogleChromeCWE-457Uninitialized Use in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a …
CVE-2026-111386.516.6GoogleChromeCWE-457Uninitialized Use in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a …
CVE-2026-111416.516.6GoogleChromeCWE-457Uninitialized Use in Audio in Google Chrome prior to 149.0.7827.53 allowed a …
CVE-2026-112686.516.6GoogleChromeCWE-457Uninitialized Use in ANGLE in Google Chrome on Windows prior to 149.0.7827.53…
CVE-2026-110858.816.2GoogleChromeCWE-472Integer overflow in GPU in Google Chrome on Android prior to 149.0.7827.53 al…
CVE-2026-110918.816.2GoogleChromeCWE-125Inappropriate implementation in Dawn in Google Chrome prior to 149.0.7827.53 …
CVE-2026-111826.516.3GoogleChromeCWE-200Inappropriate implementation in SVG in Google Chrome prior to 149.0.7827.53 a…
CVE-2026-415227.116.1dfir-irisiris-webCWE-285Iris has an Improper Authorization issue
CVE-2026-52288.816.0Kurt Software StudioWriteUp Mobile AppCWE-284Improper Access Control in Kurt Software Studio's WriteUp Mobile App
CVE-2026-491878.716.0AcerConnect M6E 5G Portable WiFi RouterCWE-200Hard-coded APK Resource Credentials & Scepters
CVE-2026-491938.716.0AcerConnect M6E 5G Portable WiFi RouterCWE-200Publicly Readable AWS S3 Telemetry Buckets
CVE-2026-418587.516.0Cloud Foundry Foundationwindows-utilities-releaseCWE-338Weak Randomness / Insecure Cryptographic Primitive (CWE-338) in Get-RandomPas…
CVE-2026-502106.916.0AcerConnect M6E 5G Portable WiFi RouterCWE-200Weak Static Cryptographic Initialization Vectors
CVE-2026-454328.715.8GX INDIAGX Earth 2022CWE-319Cleartext Transmission of Credentials Vulnerability in GX Earth ONT Models
CVE-2026-112248.115.8GoogleChromeCWE-416Use after free in Chromoting in Google Chrome on Linux prior to 149.0.7827.53…
CVE-2026-105976.915.9ITPisonOMICARD EDMCWE-639ITPison|OMICARD EDM - Insecure Direct Object Reference
CVE-2026-112829.615.7GoogleChromeCWE-693Insufficient policy enforcement in Sandbox in Google Chrome on Linux prior to…
CVE-2026-502258.815.7AcerConnect M6E 5G Portable WiFi RouterCWE-306Account Creation Exhaustion
CVE-2026-110966.515.7GoogleChromeCWE-125Out of bounds read in WebRTC in Google Chrome prior to 149.0.7827.53 allowed …
CVE-2026-111056.515.8GoogleChromeCWE-20Insufficient validation of untrusted input in WebUI in Google Chrome prior to…
CVE-2026-112308.815.6GoogleChromeCWE-416Use after free in Extensions in Google Chrome prior to 149.0.7827.53 allowed …
CVE-2026-112358.815.6GoogleChromeCWE-20Insufficient policy enforcement in Compositing in Google Chrome prior to 149.…
CVE-2026-112488.815.5GoogleChromeCWE-693Inappropriate implementation in Google Lens in Google Chrome prior to 149.0.7…
CVE-2026-109976.515.4GoogleChromeCWE-732Insufficient policy enforcement in Extensions in Google Chrome prior to 149.0…
CVE-2026-112509.615.2GoogleChromeCWE-416Inappropriate implementation in DevTools in Google Chrome prior to 149.0.7827…
CVE-2026-108689.015.3mispmispCWE-269MISP user edit endpoint mass assignment vulnerability allows unauthorized use…
CVE-2026-502058.815.0AcerConnect M6E 5G Portable WiFi RouterCWE-532Plaintext Log Credential Leakage
CVE-2026-111708.115.1GoogleChromeCWE-693Inappropriate implementation in Chromoting in Google Chrome on Linux prior to…
CVE-2026-112846.515.0GoogleChromeCWE-1300Side-channel information leakage in PerformanceAPIs in Google Chrome prior to…
CVE-2026-411785.314.9open-telemetrygo.opentelemetry.io/otel/baggageCWE-789OpenTelemetry-Go's baggage parsing no longer caps raw header length
CVE-2026-113038.814.9GoogleChromeCWE-416Use after free in PDFium in Google Chrome prior to 149.0.7827.53 allowed a re…
CVE-2026-110569.614.6GoogleChromeCWE-20Insufficient validation of untrusted input in SiteIsolation in Google Chrome …
CVE-2026-110639.614.6GoogleChromeCWE-20Insufficient validation of untrusted input in WebNN in Google Chrome on Windo…
CVE-2026-110829.614.6GoogleChromeCWE-416Race in GPU in Google Chrome on Android prior to 149.0.7827.53 allowed a remo…
CVE-2026-110949.614.5GoogleChromeCWE-416Use after free in Codecs in Google Chrome on Windows prior to 149.0.7827.53 a…
CVE-2026-111149.614.5GoogleChromeCWE-416Use after free in Device Trust in Google Chrome on Mac prior to 149.0.7827.53…
CVE-2026-111199.614.5GoogleChromeCWE-20Inappropriate implementation in GPU in Google Chrome on Android prior to 149.…
CVE-2026-111319.614.5GoogleChromeCWE-416Use after free in Autofill in Google Chrome on Android prior to 149.0.7827.53…
CVE-2026-111469.614.6GoogleChromeCWE-20Insufficient validation of untrusted input in Chromoting in Google Chrome pri…
CVE-2026-111529.614.6GoogleChromeCWE-416Object lifecycle issue in Dawn in Google Chrome prior to 149.0.7827.53 allowe…
CVE-2026-111639.614.6GoogleChromeCWE-416Use after free in Messages in Google Chrome on Android prior to 149.0.7827.53…
CVE-2026-111659.614.6GoogleChromeCWE-416Use after free in WebMIDI in Google Chrome on iOS prior to 149.0.7827.53 allo…
CVE-2026-111679.614.6GoogleChromeCWE-250Inappropriate implementation in WebView in Google Chrome on Android prior to …
CVE-2026-110418.814.6GoogleChromeCWE-20Insufficient validation of untrusted input in Media in Google Chrome on Windo…
CVE-2026-110718.814.6GoogleChromeCWE-416Use after free in Base in Google Chrome on Linux prior to 149.0.7827.53 allow…
CVE-2026-110808.814.6GoogleChromeCWE-416Use after free in WebView in Google Chrome on Android prior to 149.0.7827.53 …
CVE-2026-111248.814.5GoogleChromeCWE-122Integer overflow in Skia in Google Chrome prior to 149.0.7827.53 allowed a re…
CVE-2026-111728.814.6GoogleChromeCWE-451Incorrect security UI in Contact Picker in Google Chrome on Android prior to …
CVE-2026-111758.814.5GoogleChromeCWE-451Incorrect security UI in Messages in Google Chrome on Android prior to 149.0.…
CVE-2026-111778.814.6GoogleChromeCWE-416Use after free in Omnibox in Google Chrome prior to 149.0.7827.53 allowed a r…
CVE-2026-111888.814.5GoogleChromeCWE-416Use after free in USB in Google Chrome on Android prior to 149.0.7827.53 allo…
CVE-2026-112028.814.5GoogleChromeCWE-20Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior …
CVE-2026-112728.814.6GoogleChromeCWE-20Insufficient validation of untrusted input in Reading List in Google Chrome o…
CVE-2026-502246.914.6AcerConnect M6E 5G Portable WiFi RouterCWE-200Unauthenticated IPv6 WAN Management Exposure
CVE-2026-110299.614.4GoogleChromeCWE-20Insufficient validation of untrusted input in Drag and Drop in Google Chrome …
CVE-2026-112876.514.4GoogleChromeCWE-20Insufficient policy enforcement in Navigation in Google Chrome on Android pri…
CVE-2026-109845.414.4GoogleChromeCWE-451Inappropriate implementation in Accessibility in Google Chrome on Android pri…
CVE-2026-110985.314.4GoogleChromeCWE-20Insufficient validation of untrusted input in GPU in Google Chrome prior to 1…
CVE-2026-491949.414.3AcerConnect M6E 5G Portable WiFi RouterCWE-287SCREEN_CLICK Authentication Bypass
CVE-2026-502138.714.3AcerConnect M6E 5G Portable WiFi RouterCWE-798Bulk User Private Data Harvesting
CVE-2026-425396.514.3dfir-irisiris-webCWE-201IRIS has an Excessive Data Exposure issue
CVE-2026-110516.513.9GoogleChromeCWE-125Out of bounds read in ANGLE in Google Chrome on Linux prior to 149.0.7827.53 …
CVE-2026-110736.513.9GoogleChromeCWE-416Use after free in WebGL in Google Chrome prior to 149.0.7827.53 allowed a rem…
CVE-2026-110756.513.9GoogleChromeCWE-125Out of bounds read in V8 in Google Chrome prior to 149.0.7827.53 allowed a re…
CVE-2026-110936.513.9GoogleChromeCWE-20Inappropriate implementation in Printing in Google Chrome prior to 149.0.7827…
CVE-2026-110976.513.9GoogleChromeCWE-474Inappropriate implementation in WebView in Google Chrome on Android prior to …
CVE-2026-111216.513.9GoogleChromeCWE-20Insufficient validation of untrusted input in Skia in Google Chrome prior to …
CVE-2026-111286.513.9GoogleChromeCWE-20Inappropriate implementation in Web Share in Google Chrome prior to 149.0.782…
CVE-2026-111406.513.9GoogleChromeCWE-20Out of bounds read in Chromecast in Google Chrome prior to 149.0.7827.53 allo…
CVE-2026-111606.513.9GoogleChromeCWE-125Out of bounds read in Input in Google Chrome on Linux prior to 149.0.7827.53 …
CVE-2026-111686.513.9GoogleChromeCWE-200Inappropriate implementation in Extensions in Google Chrome prior to 149.0.78…
CVE-2026-111806.513.9GoogleChromeCWE-200Inappropriate implementation in SVG in Google Chrome prior to 149.0.7827.53 a…
CVE-2026-112036.513.9GoogleChromeCWE-200Inappropriate implementation in GPU in Google Chrome on Mac prior to 149.0.78…
CVE-2026-112066.513.9GoogleChromeCWE-693Insufficient policy enforcement in ServiceWorker in Google Chrome prior to 14…
CVE-2026-112086.513.9GoogleChromeCWE-416Use after free in Codecs in Google Chrome prior to 149.0.7827.53 allowed a re…
CVE-2026-112096.513.9GoogleChromeCWE-200Inappropriate implementation in Passwords in Google Chrome prior to 149.0.782…
CVE-2026-112716.513.9GoogleChromeCWE-200Inappropriate implementation in Passwords in Google Chrome prior to 149.0.782…
CVE-2026-113058.813.8GoogleChromeCWE-416Use after free in PDFium in Google Chrome prior to 149.0.7827.53 allowed a re…
CVE-2026-113078.813.8GoogleChromeCWE-416Use after free in PDFium in Google Chrome prior to 149.0.7827.53 allowed a re…
CVE-2026-109408.313.9GoogleChromeCWE-362Race in Codecs in Google Chrome on Windows prior to 149.0.7827.53 allowed a r…
CVE-2026-111118.113.8GoogleChromeCWE-125Out of bounds read in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a…
CVE-2026-111966.513.9GoogleChromeCWE-843Type Confusion in XML in Google Chrome prior to 149.0.7827.53 allowed a remot…
CVE-2026-111798.813.7GoogleChromeCWE-284Inappropriate implementation in ORB in Google Chrome prior to 149.0.7827.53 a…
CVE-2026-412358.613.7froxlorfroxlorCWE-863Froxlor has an authorization bypass in FTP shell assignment via missing serve…
CVE-2026-111074.313.6GoogleChromeCWE-451Inappropriate implementation in Downloads in Google Chrome prior to 149.0.782…
CVE-2026-111088.813.5GoogleChromeCWE-269Inappropriate implementation in NFC in Google Chrome on Android prior to 149.…
CVE-2026-110236.513.5GoogleChromeCWE-20Inappropriate implementation in WebAppInstalls in Google Chrome prior to 149.…
CVE-2026-108636.413.3mispmispCWE-20MISP User-controlled order parameter in correlations over-correlation endpoint
CVE-2026-113068.813.2GoogleChromeCWE-416Use after free in PDFium in Google Chrome prior to 149.0.7827.53 allowed a re…
CVE-2026-108615.113.1mispmispCWE-601MISP post-login open redirect via pre_login_requested_url
CVE-2026-110408.313.1GoogleChromeCWE-416Use after free in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a rem…
CVE-2026-111497.512.9GoogleChromeCWE-20Insufficient validation of untrusted input in Extensions in Google Chrome pri…
CVE-2026-111517.512.9GoogleChromeCWE-20Insufficient validation of untrusted input in Password Manager in Google Chro…
CVE-2026-112397.512.9GoogleChromeCWE-20Inappropriate implementation in Extensions in Google Chrome prior to 149.0.78…
CVE-2026-110206.512.9GoogleChromeCWE-346Inappropriate implementation in Extensions in Google Chrome prior to 149.0.78…
CVE-2026-112318.112.5GoogleChromeCWE-94Inappropriate implementation in Safe Browsing in Google Chrome on Mac prior t…
CVE-2026-457394.312.5strawberry-graphqlstrawberryCWE-200Strawberry GraphQL: Default GraphiQL may expose HTTP headers in URLs
CVE-2026-86536.512.4StylemixThemesMasterStudy LMS ProCWE-89MasterStudy LMS Pro Plus <= 4.8.20 - Authenticated (Instructor+) SQL Injectio…
CVE-2026-110016.512.4GoogleChromeCWE-290Inappropriate implementation in Payments in Google Chrome prior to 149.0.7827…
CVE-2026-439266.312.4FOSSBillingFOSSBillingCWE-204FOSSBilling's password reset confirmation endpoint lacks rate limiting
CVE-2026-110709.612.3GoogleChromeCWE-20Insufficient validation of untrusted input in Chromoting in Google Chrome on …
CVE-2026-111129.612.3GoogleChromeCWE-20Insufficient validation of untrusted input in Chromoting in Google Chrome on …
CVE-2026-111989.612.3GoogleChromeCWE-20Insufficient validation of untrusted input in Codecs in Google Chrome prior t…
CVE-2026-112079.612.3GoogleChromeCWE-20Insufficient validation of untrusted input in Autofill in Google Chrome prior…
CVE-2026-110798.812.3GoogleChromeCWE-20Insufficient validation of untrusted input in Codecs in Google Chrome prior t…
CVE-2026-111936.512.2GoogleChromeCWE-284Insufficient policy enforcement in Password Manager in Google Chrome prior to…
CVE-2025-656406.312.3n/an/aCWE-79Cross Site Scripting (XSS) vulnerability in the "Task in Progress / Recent" p…
CVE-2026-110146.512.0GoogleChromeCWE-602Insufficient policy enforcement in Extensions in Google Chrome prior to 149.0…
CVE-2026-109166.111.9GoogleChromeCWE-20Insufficient validation of untrusted input in DevTools in Google Chrome prior…
CVE-2026-112774.311.8GoogleChromeCWE-284Insufficient policy enforcement in Chrome for iOS in Google Chrome on iOS pri…
CVE-2026-112568.311.7GoogleChromeCWE-125Integer overflow in GPU in Google Chrome prior to 149.0.7827.53 allowed a rem…
CVE-2026-111698.111.7GoogleChromeCWE-91Inappropriate implementation in XML in Google Chrome prior to 149.0.7827.53 a…
CVE-2026-108407.111.6Red HatRed Hat OpenShift Builds 1.7.4CWE-732Openshift-pipelines-operator-rh: openshift-pipelines-operator: tekton-schedul…
CVE-2019-257315.311.6ZuzZuz MusicCWE-79Zuz Music 2.1 Persistent Cross-site Scripting via zuzconsole Contact
CVE-2019-257375.311.6ScreetsLive Chat UnlimitedCWE-79Live Chat Unlimited 2.8.3 Stored Cross-Site Scripting
CVE-2026-48816.011.5Octopus DeployOctopus ServerCWE-862In affected versions of Octopus Server, permissions were not checked correctl…

Results continue: ranks 401–624.

Methodology

Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.

Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.

Day boundary. A day is a UTC calendar day. This page covers 2026-06-04 00:00:00–23:59:59 UTC. All times shown are UTC.

Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.

Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.