AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H N N 7.5 .0764 94.1 —
AFFECTED Product Versions Fixed Microsoft 365 Copilot - – —
TIMELINE Apr 30 Reserved by CNA Jun 4 Published (CNA: microsoft)
624 CVEs published June 4, 2026: 74 critical, 263 high, 262 medium, 25 low; 0 in KEV; 8 with a public exploit reference; 0 awaiting enrichment. Elevated volume. 25 rendered as box scores below; the remaining 599 in the results table.
| MTD | YTD | 2025 same span | 2025 full | |
|---|---|---|---|---|
| CVEs published | 1378 | 5750 | 1042 | 2563 |
| KEV catalog size | 1670 | |||
249 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. C/H/M/L = YTD disclosures by severity band. KEV = catalog entries all-time / YTD. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100. Med CVSS / Med EPSS = medians over the vendor's YTD disclosures. Δ = this month-to-date minus the same day-span of last month.
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| linux | 34 | 1000 | 81 | 630 | 286 | 1 | 27 | 3 | 0.3 | 7.8 | .0013 | -27 |
| 488 | 662 | 58 | 331 | 255 | 15 | 74 | 5 | 0.8 | 7.8 | .0023 | +488 | |
| microsoft | 7 | 497 | 44 | 333 | 103 | 0 | 378 | 27 | 5.4 | 7.8 | .0046 | +7 |
| red hat | 8 | 72 | 8 | 32 | 28 | 4 | 4 | 0 | 0.0 | 7.2 | .0035 | +6 |
| apple | 0 | 47 | 0 | 12 | 27 | 1 | 93 | 7 | 14.9 | 6.2 | .0034 | 0 |
| canonical | 0 | 14 | 0 | 4 | 5 | 5 | 0 | 0 | 0.0 | 5.5 | .0009 | 0 |
| freebsd | 0 | 7 | 0 | 5 | 2 | 0 | 0 | 0 | 0.0 | 7.8 | .0020 | 0 |
| suse | 0 | 2 | 0 | 2 | 0 | 0 | 0 | 0 | 0.0 | 8.2 | .0020 | 0 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| cisco | 2 | 15 | 3 | 1 | 4 | 0 | 96 | 8 | 53.3 | 7.0 | .0694 | +2 |
| ivanti | 1 | 6 | 0 | 2 | 0 | 0 | 33 | 4 | 66.7 | 8.8 | .5751 | +1 |
| checkpoint | 0 | 6 | 0 | 3 | 3 | 0 | 3 | 0 | 0.0 | 6.5 | .0338 | 0 |
| fortinet | 0 | 6 | 1 | 3 | 0 | 0 | 28 | 3 | 50.0 | 7.9 | .4330 | 0 |
| zyxel | 2 | 3 | 0 | 0 | 3 | 0 | 11 | 0 | 0.0 | 6.5 | .0017 | +2 |
| f5 | 0 | 3 | 2 | 0 | 0 | 0 | 7 | 1 | 33.3 | 9.2 | .0996 | 0 |
| ubiquiti | 0 | 3 | 1 | 2 | 0 | 0 | 4 | 0 | 0.0 | 8.8 | .0068 | 0 |
| broadcom | 0 | 2 | 0 | 0 | 0 | 0 | 4 | 2 | 100.0 | — | .1990 | 0 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| apache | 32 | 64 | 8 | 26 | 27 | 2 | 40 | 1 | 1.6 | 7.2 | .0053 | +31 |
| mozilla | 4 | 10 | 3 | 3 | 4 | 0 | 13 | 0 | 0.0 | 7.4 | .0035 | +4 |
| gitlab | 0 | 9 | 0 | 1 | 6 | 0 | 4 | 2 | 22.2 | 4.3 | .0032 | 0 |
| drupal | 0 | 5 | 1 | 1 | 3 | 0 | 5 | 1 | 20.0 | 5.1 | .0026 | 0 |
| docker | 1 | 4 | 0 | 4 | 0 | 0 | 1 | 0 | 0.0 | 8.8 | .0022 | +1 |
| github | 0 | 2 | 1 | 1 | 0 | 0 | 0 | 0 | 0.0 | 8.1 | .0347 | 0 |
| jenkins | 0 | 0 | 0 | 0 | 0 | 0 | 6 | 0 | — | — | — | 0 |
| joomla | 0 | 0 | 0 | 0 | 0 | 0 | 1 | 0 | — | — | — | 0 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| ibm | 5 | 54 | 13 | 26 | 15 | 0 | 7 | 0 | 0.0 | 7.5 | .0031 | +5 |
| oracle | 1 | 28 | 8 | 15 | 4 | 0 | 40 | 1 | 3.6 | 8.1 | .0027 | +1 |
| progress | 5 | 9 | 1 | 7 | 1 | 0 | 9 | 0 | 0.0 | 7.5 | .0036 | +5 |
| solarwinds | 1 | 4 | 1 | 1 | 0 | 0 | 11 | 3 | 75.0 | 8.7 | .7758 | +1 |
| adobe | 0 | 4 | 0 | 1 | 0 | 0 | 75 | 3 | 75.0 | 8.6 | .2776 | 0 |
| veeam | 0 | 3 | 1 | 2 | 0 | 0 | 4 | 0 | 0.0 | 8.6 | .0040 | 0 |
| zohocorp | 0 | 2 | 0 | 1 | 1 | 0 | 0 | 0 | 0.0 | 7.1 | .0104 | 0 |
| atlassian | 0 | 0 | 0 | 0 | 0 | 0 | 13 | 0 | — | — | — | 0 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| synology | 5 | 23 | 2 | 5 | 13 | 3 | 0 | 0 | 0.0 | 5.6 | .0025 | +5 |
| d-link | 2 | 5 | 0 | 3 | 1 | 0 | 26 | 1 | 20.0 | 7.4 | .0059 | +2 |
| abb | 4 | 4 | 0 | 4 | 0 | 0 | 0 | 0 | 0.0 | 7.3 | .0024 | +4 |
| siemens | 1 | 2 | 0 | 1 | 1 | 0 | 1 | 0 | 0.0 | 7.3 | .0026 | +1 |
| hitachi energy | 0 | 2 | 0 | 0 | 2 | 0 | 0 | 0 | 0.0 | 5.7 | .0014 | 0 |
| hikvision | 0 | 1 | 0 | 0 | 0 | 0 | 2 | 1 | 100.0 | — | 1.0000 | 0 |
| dahua | 0 | 0 | 0 | 0 | 0 | 0 | 2 | 0 | — | — | — | 0 |
| qnap | 0 | 0 | 0 | 0 | 0 | 0 | 8 | 0 | — | — | — | 0 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| edimax | 0 | 51 | 0 | 32 | 0 | 19 | 1 | 0 | 0.0 | 7.4 | .0059 | 0 |
| concrete cms | 1 | 45 | 1 | 10 | 13 | 21 | 0 | 0 | 0.0 | 6.0 | .0015 | +1 |
| open ises | 0 | 44 | 2 | 21 | 21 | 0 | 0 | 0 | 0.0 | 7.1 | .0021 | 0 |
| sourcecodester | 20 | 42 | 0 | 0 | 14 | 28 | 0 | 0 | 0.0 | 2.1 | .0025 | +20 |
| helmholz | 0 | 42 | 0 | 39 | 3 | 0 | 0 | 0 | 0.0 | 7.1 | .0026 | 0 |
| mb connect line | 0 | 42 | 0 | 39 | 3 | 0 | 0 | 0 | 0.0 | 7.1 | .0026 | 0 |
| acer | 26 | 36 | 11 | 19 | 6 | 0 | 0 | 0 | 0.0 | 8.7 | .0024 | +26 |
| nvidia | 2 | 35 | 8 | 20 | 7 | 0 | 0 | 0 | 0.0 | 7.8 | .0029 | +2 |
| CVE | EPSS | %ile | CVSS |
|---|---|---|---|
| CVE-2008-4250 | .9875 | 99.9 | — |
| CVE-2026-0257 | .9391 | 99.8 | — |
| CVE-2026-43284 | .9324 | 99.8 | 8.8 |
| CVE-2026-43500 | .9285 | 99.8 | 7.8 |
| CVE-2010-0249 | .9188 | 99.8 | — |
| CVE-2026-20182 | .9152 | 99.8 | — |
| CVE-2026-42208 | .8942 | 99.8 | — |
| CVE-2026-9082 | .8832 | 99.8 | 9.8 |
| CVE-2009-3459 | .8658 | 99.7 | — |
| CVE-2025-34291 | .8384 | 99.7 | — |
| CVE | CVSS | EPSS | Note |
|---|---|---|---|
| CVE-2026-48172 | 10.0 | .1891 | KEV |
| CVE-2026-8054 | 10.0 | .0158 | |
| CVE-2026-45087 | 10.0 | .0147 | |
| CVE-2026-49199 | 10.0 | .0134 | |
| CVE-2026-43997 | 10.0 | .0098 | |
| CVE-2026-42826 | 10.0 | .0084 | |
| CVE-2026-20223 | 10.0 | .0083 | |
| CVE-2026-44005 | 10.0 | .0083 | |
| CVE-2026-44006 | 10.0 | .0081 | |
| CVE-2026-46840 | 10.0 | .0073 |
| Vendor | CVEs |
|---|---|
| 656 | |
| linux | 607 |
| microsoft | 177 |
| ibm | 54 |
| edimax | 51 |
| apache | 49 |
| red hat | 47 |
| concrete cms | 45 |
| open ises | 44 |
| helmholz | 42 |
| Vendor | KEV |
|---|---|
| microsoft | 27 |
| cisco | 8 |
| apple | 7 |
| 5 | |
| ivanti | 4 |
| synacor | 4 |
| adobe | 3 |
| fortinet | 3 |
| linux | 3 |
| smartertools | 3 |
| Ecosystem | Advisories |
|---|---|
| Maven | 24 |
| PyPI | 10 |
| Packagist | 7 |
| crates.io | 2 |
| npm | 2 |
| CVE | Vendor | Days |
|---|---|---|
| CVE-2008-4250 | Microsoft | 0 |
| CVE-2009-1537 | Microsoft | 0 |
| CVE-2009-3459 | Adobe | 0 |
| CVE-2010-0249 | Microsoft | 0 |
| CVE-2010-0806 | Microsoft | 0 |
| CVE-2022-0492 | Linux | 0 |
| CVE-2024-21182 | Oracle | 0 |
| CVE-2025-34291 | Langflow | 0 |
| CVE-2025-48595 | 0 | |
| CVE-2026-0257 | Palo Alto Networks | 0 |
| CVE | Vendor | Due | Days over |
|---|---|---|---|
| CVE-2021-27104 | Accellion | 2021-11-17 | 1660 |
| CVE-2021-27102 | Accellion | 2021-11-17 | 1660 |
| CVE-2021-27101 | Accellion | 2021-11-17 | 1660 |
| CVE-2021-27103 | Accellion | 2021-11-17 | 1660 |
| CVE-2021-21017 | Adobe | 2021-11-17 | 1660 |
| CVE-2021-28550 | Adobe | 2021-11-17 | 1660 |
| CVE-2021-42013 | Apache | 2021-11-17 | 1660 |
| CVE-2021-41773 | Apache | 2021-11-17 | 1660 |
| CVE-2021-30858 | Apple | 2021-11-17 | 1660 |
| CVE-2021-30860 | Apple | 2021-11-17 | 1660 |
EXPLOIT PUBLISHED — CVE-2026-10796 (nvm-sh nvm). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-11216 (Google Chrome). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-45287 (open-telemetry go.opentelemetry.io/otel/schema/v1.1). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-47706 (strawberry-graphql strawberry). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-47707 (strawberry-graphql strawberry). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-5066 (zephyrproject-rtos Zephyr). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-5589 (zephyrproject-rtos Zephyr). Public exploit reference added.
DUE DATE PASSED — CVE-2008-4250 (Microsoft Windows). CISA remediation deadline was June 3, 2026; still in catalog.
DUE DATE PASSED — CVE-2009-1537 (Microsoft DirectX). CISA remediation deadline was June 3, 2026; still in catalog.
DUE DATE PASSED — CVE-2009-3459 (Adobe Acrobat and Reader). CISA remediation deadline was June 3, 2026; still in catalog.
DUE DATE PASSED — CVE-2010-0249 (Microsoft Internet Explorer). CISA remediation deadline was June 3, 2026; still in catalog.
DUE DATE PASSED — CVE-2010-0806 (Microsoft Internet Explorer). CISA remediation deadline was June 3, 2026; still in catalog.
DUE DATE PASSED — CVE-2026-41091 (Microsoft Malware Protection Engine). CISA remediation deadline was June 3, 2026; still in catalog.
DUE DATE PASSED — CVE-2026-45498 (Microsoft Defender Antimalware Platform). CISA remediation deadline was June 3, 2026; still in catalog.
624 CVEs published. 25 box scores and 375 table rows below; the remaining 224 continue on page 2 — every CVE is listed, nothing truncated.
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H N N 7.5 .0764 94.1 —
AFFECTED Product Versions Fixed Microsoft 365 Copilot - – —
TIMELINE Apr 30 Reserved by CNA Jun 4 Published (CNA: microsoft)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N L N N H H 7.2 .0443 90.6 —
AFFECTED Product Versions Fixed EOS 4.29.0 – —
TIMELINE Feb 26 Reserved by CNA Jun 4 Published (CNA: Arista)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N H N H H H 7.3 .0270 84.6 —
AFFECTED Product Versions Fixed Tomato 1.28.0000 – —
TIMELINE Jun 4 Reserved by CNA Jun 4 Published (CNA: VulDB)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N H N H H H 7.3 .0263 84.3 —
AFFECTED Product Versions Fixed Tomato 1.28.0000 – —
TIMELINE Jun 4 Reserved by CNA Jun 4 Published (CNA: VulDB)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N H N H H H 7.3 .0220 81.0 —
AFFECTED Product Versions Fixed Tomato 1.28.0000 – —
TIMELINE Jun 4 Reserved by CNA Jun 4 Published (CNA: VulDB)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N H N H H H 7.3 .0220 81.0 —
AFFECTED Product Versions Fixed Tomato 1.28.0000 – —
TIMELINE Jun 4 Reserved by CNA Jun 4 Published (CNA: VulDB)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0103 61.0 —
AFFECTED Product Versions Fixed Azure HorizonDB - – —
TIMELINE May 21 Reserved by CNA Jun 4 Published (CNA: microsoft)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0103 60.7 —
AFFECTED Product Versions Fixed n/a n/a – —
TIMELINE Dec 8 Reserved by CNA Jun 4 Published (CNA: mitre)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H N N 7.5 .0101 60.4 —
AFFECTED Product Versions Fixed Microsoft Exchange Online - – —
TIMELINE May 21 Reserved by CNA Jun 4 Published (CNA: microsoft)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N R C H N N 7.4 .0098 59.5 —
AFFECTED Product Versions Fixed Chrome 149.0.7827.53 – —
TIMELINE Jun 4 Reserved by CNA Jun 4 Published (CNA: Chrome)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV L L N N N N L N 5.1 .0089 56.3 —
AFFECTED Product Versions Fixed Contact Form Maker 1.13.1 – —
TIMELINE Jun 4 Reserved by CNA Jun 4 Published (CNA: VulnCheck)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N U H N N 6.5 .0076 52.1 —
AFFECTED Product Versions Fixed Microsoft Graph - – —
TIMELINE May 19 Reserved by CNA Jun 4 Published (CNA: microsoft)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N C H H H 9.9 .0073 51.4 —
AFFECTED Product Versions Fixed Mistral 20.0.0 – —
TIMELINE Apr 20 Reserved by CNA Jun 4 Published (CNA: mitre)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H N N 7.5 .0073 51.3 —
AFFECTED Product Versions Fixed Copilot Chat (Microsoft Edge) - – —
TIMELINE May 19 Reserved by CNA Jun 4 Published (CNA: microsoft)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H H H 9.3 .0073 51.2 —
AFFECTED Product Versions Fixed BarTender 2010 unspecified — BarTender 2016 unspecified — BarTender 2019 unspecified —
TIMELINE Feb 2 Reserved by CNA Jun 4 Published (CNA: VulnCheck)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV A L N H N H H H 8.5 .0072 50.9 —
AFFECTED Product Versions Fixed Connect M6E 5G Portable WiFi Router unspecified —
TIMELINE Jun 4 Reserved by CNA Jun 4 Published (CNA: Acer)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H H H 9.3 .0064 47.6 —
AFFECTED Product Versions Fixed Mobatek MobaXterm 12.1 – —
TIMELINE Jun 4 Reserved by CNA Jun 4 Published (CNA: VulnCheck)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N U H H N 8.1 .0060 45.9 —
AFFECTED Product Versions Fixed Ironic 17.0.0 – —
TIMELINE May 22 Reserved by CNA Jun 4 Published (CNA: mitre)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N A N H N 6.9 .0060 45.8 —
AFFECTED Product Versions Fixed CPython unspecified —
TIMELINE May 4 Reserved by CNA Jun 4 Published (CNA: PSF)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0055 43.3 —
AFFECTED Product Versions Fixed n/a n/a – —
TIMELINE Apr 6 Reserved by CNA Jun 4 Published (CNA: mitre)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H N 9.1 .0052 41.8 —
AFFECTED Product Versions Fixed Apache Fory unspecified —
TIMELINE Jun 3 Reserved by CNA Jun 4 Published (CNA: apache)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N R U H H H 8.8 .0049 40.1 —
AFFECTED Product Versions Fixed Chrome 149.0.7827.53 – —
TIMELINE Jun 4 Reserved by CNA Jun 4 Published (CNA: Chrome)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N R U H H H 8.8 .0049 40.1 —
AFFECTED Product Versions Fixed Chrome 149.0.7827.53 – —
TIMELINE Jun 4 Reserved by CNA Jun 4 Published (CNA: Chrome)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N R U H H H 8.8 .0049 40.1 —
AFFECTED Product Versions Fixed Chrome 149.0.7827.53 – —
TIMELINE Jun 4 Reserved by CNA Jun 4 Published (CNA: Chrome)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N R U H H H 8.8 .0049 40.1 —
AFFECTED Product Versions Fixed Chrome 149.0.7827.53 – —
TIMELINE Jun 4 Reserved by CNA Jun 4 Published (CNA: Chrome)
| CVE | CVSS | EPSS %ile | Vendor | Product | CWE | Title |
|---|---|---|---|---|---|---|
| CVE-2026-10882 | 8.8 | 38.5 | Chrome | CWE-416 | Use after free in Network in Google Chrome prior to 149.0.7827.53 allowed a r… | |
| CVE-2026-35906 | 9.6 | 38.4 | n/a | n/a | CWE-78 | An undocumented debug CGI endpoint in T3 Technology CPE models T625Pro v1.0.0… |
| CVE-2025-69755 | 8.2 | 38.3 | n/a | n/a | CWE-78 | An issue in Neterbit NW-431F Router vNW-431F-20241014-IR03 allows a remote at… |
| CVE-2026-10796 | 7.5 | 38.3 | nvm-sh | nvm | CWE-78 | nvm executes commands from a malicious Node.js mirror's version strings |
| CVE-2019-25727 | 9.3 | 38.1 | ad-manager-wd | Ad Manager WD | CWE-22 | WordPress Plugin ad manager wd 1.0.11 Arbitrary File Download |
| CVE-2026-10939 | 8.8 | 37.8 | Chrome | CWE-416 | Use after free in WebRTC in Google Chrome prior to 149.0.7827.53 allowed a re… | |
| CVE-2026-10975 | 8.8 | 37.8 | Chrome | CWE-416 | Use after free in WebRTC in Google Chrome prior to 149.0.7827.53 allowed a re… | |
| CVE-2026-10982 | 8.8 | 37.8 | Chrome | CWE-416 | Use after free in WebXR in Google Chrome prior to 149.0.7827.53 allowed a rem… | |
| CVE-2026-11003 | 8.8 | 37.8 | Chrome | CWE-416 | Use after free in WebRTC in Google Chrome prior to 149.0.7827.53 allowed a re… | |
| CVE-2025-67446 | 9.8 | 37.7 | n/a | n/a | CWE-384 | Improper Authentication (Authentication Bypass) exists in Neterbit NW-431F Ro… |
| CVE-2026-45497 | 8.8 | 37.5 | Microsoft | Microsoft 365 Copilot | CWE-77 | Microsoft M365 Copilot Remote Code Execution Vulnerability |
| CVE-2026-10737 | 7.5 | 37.4 | smartypants | SP Project & Document Manager | CWE-862 | SP Project & Document Manager <= 4.71 - Missing Authorization to Unauthentica… |
| CVE-2026-10880 | 9.8 | 36.3 | Osnexus | QuantaStor | CWE-89 | Unauthenticated SQL Injection in Osnexus Quantastor |
| CVE-2026-41065 | 8.9 | 36.1 | Tautulli | Tautulli | CWE-1336 | Tautulli Vulnerable to Unauthenticated/Authenticated Remote Code Execution vi… |
| CVE-2026-41249 | 8.2 | 36.1 | coreshop | CoreShop | CWE-94 | CoreShop Vulnerable to Remote Code Execution (RCE) via Insecure `pull_request… |
| CVE-2026-50589 | 7.5 | 36.1 | OpenStack | Ironic | CWE-770 | In OpenStack Ironic 32 before 37.0.0, an unauthenticated malicious user could… |
| CVE-2026-49190 | 9.4 | 35.5 | Acer | Connect M6E 5G Portable WiFi Router | CWE-78 | Missing Per-Instruction Authorization Checks |
| CVE-2026-10910 | 8.8 | 35.5 | Chrome | CWE-843 | Type Confusion in V8 in Google Chrome prior to 149.0.7827.53 allowed a remote… | |
| CVE-2026-35905 | 9.8 | 35.1 | n/a | n/a | CWE-259 | T3 Technology CPE models T625Pro v1.0.07, T6825G v1.0.03, and T7281 v1.0.03 w… |
| CVE-2026-10941 | 8.8 | 34.9 | Chrome | CWE-125 | Out of bounds memory access in Skia in Google Chrome prior to 149.0.7827.53 a… | |
| CVE-2026-47707 | 5.3 | 34.8 | strawberry-graphql | strawberry | CWE-400 | Strawberry GraphQL's Bypass of MaxAliasesLimiter via Fragment Spreads leading… |
| CVE-2026-10904 | 8.8 | 34.2 | Chrome | CWE-20 | Inappropriate implementation in V8 in Google Chrome prior to 149.0.7827.53 al… | |
| CVE-2026-10928 | 8.8 | 34.2 | Chrome | CWE-94 | Script injection in Headless in Google Chrome prior to 149.0.7827.53 allowed … | |
| CVE-2026-8829 | 7.5 | 34.0 | OALDERS | HTML::Entities | CWE-416 | HTML::Entities versions before 3.84 for Perl read freed heap memory in _decod… |
| CVE-2026-10887 | 8.1 | 33.6 | Chrome | CWE-416 | Use after free in Chromoting in Google Chrome on Mac prior to 149.0.7827.53 a… | |
| CVE-2026-10935 | 8.8 | 32.5 | Chrome | CWE-843 | Type Confusion in V8 in Google Chrome prior to 149.0.7827.53 allowed a remote… | |
| CVE-2026-10936 | 8.8 | 32.5 | Chrome | CWE-843 | Type Confusion in V8 in Google Chrome prior to 149.0.7827.53 allowed a remote… | |
| CVE-2026-10962 | 8.8 | 32.5 | Chrome | CWE-843 | Type Confusion in Media in Google Chrome prior to 149.0.7827.53 allowed a rem… | |
| CVE-2026-10881 | 9.6 | 32.2 | Chrome | CWE-125 | Out of bounds read and write in ANGLE in Google Chrome prior to 149.0.7827.53… | |
| CVE-2026-10883 | 8.8 | 32.2 | Chrome | CWE-787 | Type Confusion in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a rem… | |
| CVE-2026-10895 | 8.8 | 32.1 | Chrome | CWE-416 | Use after free in Ozone in Google Chrome prior to 149.0.7827.53 allowed a rem… | |
| CVE-2026-10902 | 8.8 | 32.1 | Chrome | CWE-416 | Use after free in Ozone in Google Chrome prior to 149.0.7827.53 allowed a rem… | |
| CVE-2026-10913 | 8.8 | 32.1 | Chrome | CWE-416 | Use after free in ANGLE in Google Chrome on Windows prior to 149.0.7827.53 al… | |
| CVE-2026-10914 | 8.8 | 32.1 | Chrome | CWE-416 | Use after free in ANGLE in Google Chrome on Windows prior to 149.0.7827.53 al… | |
| CVE-2026-10954 | 8.8 | 32.1 | Chrome | CWE-416 | Use after free in Actor in Google Chrome prior to 149.0.7827.53 allowed a rem… | |
| CVE-2026-10956 | 8.8 | 32.1 | Chrome | CWE-416 | Use after free in MimeHandlerView in Google Chrome prior to 149.0.7827.53 all… | |
| CVE-2026-45431 | 8.7 | 32.0 | GX INDIA | GX Earth 2022 | CWE-78 | Command Injection Vulnerability in GX Earth ONT Models |
| CVE-2026-49185 | 10.0 | 31.8 | Acer | Connect M6E 5G Portable WiFi Router | CWE-78 | Instruction Injection via FieldX MDM |
| CVE-2026-11118 | 8.8 | 31.8 | Chrome | CWE-416 | Use after free in WebRTC in Google Chrome prior to 149.0.7827.53 allowed a re… | |
| CVE-2026-11102 | 8.8 | 31.8 | Chrome | CWE-474 | Inappropriate implementation in Isolated Web Apps in Google Chrome prior to 1… | |
| CVE-2025-8873 | 8.7 | 31.7 | Arista Networks | EOS | CWE-1286 | Arista EOS Dataplane Denial of Service via Malformed IPsec Packet |
| CVE-2025-71316 | 9.2 | 31.6 | SQLite | sqldiff | CWE-176 | SQLite sqldiff remote code execution via argument injection |
| CVE-2026-10955 | 8.8 | 31.2 | Chrome | CWE-843 | Type Confusion in ANGLE in Google Chrome on Windows prior to 149.0.7827.53 al… | |
| CVE-2026-10885 | 8.8 | 30.5 | Chrome | CWE-416 | Use after free in Chrome for iOS in Google Chrome on iOS prior to 149.0.7827.… | |
| CVE-2026-10896 | 8.8 | 30.5 | Chrome | CWE-416 | Use after free in Chrome for iOS in Google Chrome on iOS prior to 149.0.7827.… | |
| CVE-2026-10946 | 7.5 | 30.6 | Chrome | CWE-122 | Heap buffer overflow in Media in Google Chrome prior to 149.0.7827.53 allowed… | |
| CVE-2026-3820 | 7.2 | 30.1 | SMCI | AS-2115HS-TNR | CWE-78 | Supermicro BMC's SMTP service contains a command injection vulnerability |
| CVE-2026-40898 | 7.5 | 29.8 | quic-go | quic-go | CWE-770 | quic-go: HTTP/3 QPACK Trailer Expansion Memory Exhaustion |
| CVE-2026-41236 | 8.8 | 29.7 | froxlor | froxlor | CWE-59 | Froxlor has privilege escalation in SSH key synchronization via symlinked `au… |
| CVE-2026-10957 | 8.8 | 29.2 | Chrome | CWE-416 | Use after free in Glic in Google Chrome prior to 149.0.7827.53 allowed a remo… | |
| CVE-2026-10958 | 8.8 | 29.2 | Chrome | CWE-416 | Use after free in Chrome for iOS in Google Chrome on iOS prior to 149.0.7827.… | |
| CVE-2026-10959 | 8.8 | 29.2 | Chrome | CWE-416 | Use after free in Input in Google Chrome on Android prior to 149.0.7827.53 al… | |
| CVE-2026-10963 | 8.8 | 29.2 | Chrome | CWE-472 | Integer overflow in V8 in Google Chrome prior to 149.0.7827.53 allowed a remo… | |
| CVE-2026-10964 | 8.8 | 29.2 | Chrome | CWE-472 | Integer overflow in V8 in Google Chrome prior to 149.0.7827.53 allowed a remo… | |
| CVE-2026-10965 | 8.8 | 29.2 | Chrome | CWE-472 | Integer overflow in DevTools in Google Chrome prior to 149.0.7827.53 allowed … | |
| CVE-2026-10987 | 8.8 | 29.2 | Chrome | CWE-472 | Integer overflow in V8 in Google Chrome prior to 149.0.7827.53 allowed a remo… | |
| CVE-2026-10991 | 8.8 | 29.2 | Chrome | CWE-416 | Use after free in V8 in Google Chrome prior to 149.0.7827.53 allowed a remote… | |
| CVE-2026-11000 | 8.8 | 29.2 | Chrome | CWE-416 | Use after free in Fonts in Google Chrome on Linux prior to 149.0.7827.53 allo… | |
| CVE-2026-11028 | 8.8 | 29.2 | Chrome | CWE-416 | Use after free in Media in Google Chrome on Linux and ChromeOS prior to 149.0… | |
| CVE-2026-11046 | 8.8 | 29.2 | Chrome | CWE-20 | Insufficient validation of untrusted input in Media in Google Chrome prior to… | |
| CVE-2026-10893 | 8.8 | 29.0 | Chrome | CWE-416 | Use after free in Chromoting in Google Chrome prior to 149.0.7827.53 allowed … | |
| CVE-2026-10945 | 8.8 | 29.0 | Chrome | CWE-416 | Use after free in PDF in Google Chrome prior to 149.0.7827.53 allowed a remot… | |
| CVE-2026-11054 | 8.8 | 28.6 | Chrome | CWE-416 | Use after free in WebRTC in Google Chrome prior to 149.0.7827.53 allowed a re… | |
| CVE-2026-11068 | 8.8 | 28.6 | Chrome | CWE-416 | Use after free in WebSockets in Google Chrome prior to 149.0.7827.53 allowed … | |
| CVE-2026-11074 | 8.8 | 28.6 | Chrome | CWE-416 | Use after free in WebRTC in Google Chrome on Linux prior to 149.0.7827.53 all… | |
| CVE-2026-11147 | 8.8 | 28.5 | Chrome | CWE-416 | Use after free in WebML in Google Chrome on Windows prior to 149.0.7827.53 al… | |
| CVE-2026-10995 | 8.8 | 28.2 | Chrome | CWE-122 | Heap buffer overflow in TabStrip in Google Chrome prior to 149.0.7827.53 allo… | |
| CVE-2026-11024 | 8.8 | 28.2 | Chrome | CWE-121 | Stack buffer overflow in Skia in Google Chrome prior to 149.0.7827.53 allowed… | |
| CVE-2026-10923 | 8.8 | 28.1 | Chrome | CWE-416 | Use after free in WebAppInstalls in Google Chrome on Android prior to 149.0.7… | |
| CVE-2026-10938 | 6.5 | 28.1 | Chrome | CWE-20 | Inappropriate implementation in Input in Google Chrome prior to 149.0.7827.53… | |
| CVE-2019-25738 | 9.3 | 27.8 | framework-y | Hybrid Composer | CWE-306 | WordPress Hybrid Composer 1.4.6 Unauthenticated Settings Change |
| CVE-2026-10886 | 9.6 | 27.6 | Chrome | CWE-416 | Use after free in FileSystem in Google Chrome prior to 149.0.7827.53 allowed … | |
| CVE-2026-45433 | 8.7 | 27.5 | GX INDIA | GX Earth 2022 | CWE-321 | Hardcoded Cryptographic Key Vulnerability in GX Earth ONT Models |
| CVE-2026-10901 | 7.5 | 27.1 | Chrome | CWE-416 | Use after free in Passwords in Google Chrome on Mac prior to 149.0.7827.53 al… | |
| CVE-2026-10976 | 7.4 | 26.5 | Chrome | CWE-457 | Uninitialized Use in Dawn in Google Chrome prior to 149.0.7827.53 allowed a r… | |
| CVE-2026-10977 | 6.5 | 26.5 | Chrome | CWE-457 | Uninitialized Use in Skia in Google Chrome prior to 149.0.7827.53 allowed a r… | |
| CVE-2026-10994 | 6.5 | 26.5 | Chrome | CWE-457 | Uninitialized Use in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a … | |
| CVE-2026-10978 | 8.8 | 26.2 | Chrome | CWE-416 | Use after free in Chromoting in Google Chrome on Windows prior to 149.0.7827.… | |
| CVE-2026-10986 | 8.8 | 26.2 | Chrome | CWE-472 | Integer overflow in Media in Google Chrome prior to 149.0.7827.53 allowed a r… | |
| CVE-2026-10993 | 6.5 | 26.2 | Chrome | CWE-122 | Heap buffer overflow in Skia in Google Chrome prior to 149.0.7827.53 allowed … | |
| CVE-2026-10898 | 8.3 | 26.1 | Chrome | CWE-121 | Stack buffer overflow in GPU in Google Chrome prior to 149.0.7827.53 allowed … | |
| CVE-2026-49941 | 7.5 | 25.8 | RRWO | Net::CIDR::Set | CWE-674 | Net::CIDR::Set versions through 0.20 for Perl did not validate IP addresses |
| CVE-2026-10843 | 7.2 | 25.7 | Red Hat | Red Hat OpenShift Container Platform 4 | CWE-250 | Cloud-credential-operator: cco mint-mode credentialsrequest manifests grant a… |
| CVE-2026-10980 | 6.5 | 25.6 | Chrome | CWE-20 | Insufficient validation of untrusted input in DevTools in Google Chrome prior… | |
| CVE-2026-36499 | 6.5 | 25.6 | n/a | n/a | CWE-770 | A missing upper-bound check in the udpif_set_threads() function of Open vSwit… |
| CVE-2026-10877 | 5.5 | 25.7 | SourceCodester | Ship Ferry Ticket Reservation System | CWE-74 | SourceCodester Ship Ferry Ticket Reservation System Admin Login login.php sql… |
| CVE-2025-46638 | 7.5 | 25.6 | Dell | BSAFE SSL-J | CWE-770 | Dell BSAFE SSL-J contains an allocation of resources without limits or thrott… |
| CVE-2019-25740 | 7.1 | 25.6 | Joomsky | JS Jobs | CWE-22 | Joomla com_jsjobs 1.2.6 Arbitrary File Deletion |
| CVE-2026-10906 | 7.5 | 25.4 | Chrome | CWE-416 | Use after free in WebAuthentication in Google Chrome prior to 149.0.7827.53 a… | |
| CVE-2026-10892 | 9.6 | 25.4 | Chrome | CWE-787 | Out of bounds write in GPU in Google Chrome on Android prior to 149.0.7827.53… | |
| CVE-2026-10931 | 9.6 | 25.4 | Chrome | CWE-416 | Use after free in FileSystem in Google Chrome prior to 149.0.7827.53 allowed … | |
| CVE-2026-10972 | 9.6 | 25.4 | Chrome | CWE-416 | Use after free in Ozone in Google Chrome on Linux prior to 149.0.7827.53 allo… | |
| CVE-2026-10974 | 9.6 | 25.4 | Chrome | CWE-20 | Insufficient validation of untrusted input in ANGLE in Google Chrome prior to… | |
| CVE-2026-10983 | 9.6 | 25.4 | Chrome | CWE-20 | Insufficient validation of untrusted input in Dawn in Google Chrome prior to … | |
| CVE-2026-11009 | 9.6 | 25.4 | Chrome | CWE-416 | Use after free in USB in Google Chrome on Windows prior to 149.0.7827.53 allo… | |
| CVE-2026-11021 | 9.6 | 25.4 | Chrome | CWE-20 | Insufficient validation of untrusted input in GPU in Google Chrome on Windows… | |
| CVE-2026-11065 | 9.6 | 25.4 | Chrome | CWE-416 | Use after free in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a rem… | |
| CVE-2026-10891 | 8.8 | 25.4 | Chrome | CWE-416 | Use after free in GFX in Google Chrome on Linux prior to 149.0.7827.53 allowe… | |
| CVE-2026-10897 | 8.8 | 25.4 | Chrome | CWE-787 | Inappropriate implementation in GPU in Google Chrome prior to 149.0.7827.53 a… | |
| CVE-2026-10907 | 8.8 | 25.4 | Chrome | CWE-787 | Out of bounds write in ANGLE in Google Chrome prior to 149.0.7827.53 allowed … | |
| CVE-2026-10988 | 8.8 | 25.4 | Chrome | CWE-416 | Use after free in Views in Google Chrome prior to 149.0.7827.53 allowed a rem… | |
| CVE-2026-10989 | 8.8 | 25.4 | Chrome | CWE-122 | Inappropriate implementation in V8 in Google Chrome prior to 149.0.7827.53 al… | |
| CVE-2026-10971 | 9.6 | 25.2 | Chrome | CWE-20 | Insufficient validation of untrusted input in Printing in Google Chrome on Wi… | |
| CVE-2026-11322 | 7.1 | 25.1 | nesquena | Hermes WebUI | CWE-59 | Hermes WebUI before 0.51.221 Path Traversal via Symlink Workspace Bypass |
| CVE-2026-5066 | 8.8 | 24.8 | zephyrproject-rtos | Zephyr | CWE-787 | net: sockets: tls: Potential out-of-bounds write/read in socket_op_vtable::co… |
| CVE-2026-49186 | 8.6 | 24.7 | Acer | Connect M6E 5G Portable WiFi Router | CWE-287 | Lack of MQTT Broker Topic Access Control Lists |
| CVE-2026-49188 | 8.7 | 24.5 | Acer | Connect M6E 5G Portable WiFi Router | CWE-489 | Elevated Root Command Execution via ai_cmd Sockets |
| CVE-2023-5502 | 8.2 | 24.5 | Arista Networks | EOS | CWE-287 | On affected platforms running Arista EOS with 802.1x authentication configure… |
| CVE-2026-11088 | 9.6 | 24.3 | Chrome | CWE-472 | Integer overflow in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a r… | |
| CVE-2026-10930 | 8.1 | 24.4 | Chrome | CWE-125 | Out of bounds read in ANGLE in Google Chrome on Mac prior to 149.0.7827.53 al… | |
| CVE-2026-11015 | 8.1 | 24.4 | Chrome | CWE-125 | Out of bounds read in WebGPU in Google Chrome prior to 149.0.7827.53 allowed … | |
| CVE-2026-50292 | 9.8 | 24.0 | freedesktop | libinput | CWE-93 | In libinput before 1.30.4 and 1.31.x before 1.31.3, libinput-device-group une… |
| CVE-2026-10951 | 8.8 | 24.0 | Chrome | CWE-416 | Use after free in Autofill in Google Chrome on iOS prior to 149.0.7827.53 all… | |
| CVE-2026-10952 | 8.8 | 24.0 | Chrome | CWE-416 | Use after free in Chrome for iOS in Google Chrome on iOS prior to 149.0.7827.… | |
| CVE-2026-11076 | 8.8 | 23.9 | Chrome | CWE-843 | Type Confusion in CSS in Google Chrome prior to 149.0.7827.53 allowed a remot… | |
| CVE-2026-49942 | 7.3 | 23.9 | RRWO | Net::CIDR::Set | CWE-1289 | Net::CIDR::Set versions through 0.20 for Perl did not validate network masks |
| CVE-2026-10929 | 8.3 | 23.6 | Chrome | CWE-122 | Heap buffer overflow in ANGLE in Google Chrome on Android prior to 149.0.7827… | |
| CVE-2026-10949 | 8.3 | 23.6 | Chrome | CWE-122 | Heap buffer overflow in Video in Google Chrome prior to 149.0.7827.53 allowed… | |
| CVE-2026-11011 | 8.1 | 23.7 | Chrome | CWE-602 | Insufficient policy enforcement in Password Manager in Google Chrome prior to… | |
| CVE-2026-10802 | 2.1 | 23.6 | keystonejs | keystone | CWE-400 | keystonejs keystone GraphQL API Endpoint output-field.ts resource consumption |
| CVE-2026-49771 | 7.6 | 23.4 | 10Web | Photo Gallery by 10Web | CWE-89 | WordPress Photo Gallery by 10Web plugin <= 1.8.41 - SQL Injection vulnerability |
| CVE-2026-10968 | 7.4 | 23.4 | Chrome | CWE-20 | Insufficient validation of untrusted input in Dawn in Google Chrome on Window… | |
| CVE-2026-10979 | 6.5 | 23.4 | Chrome | CWE-125 | Out of bounds read in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a… | |
| CVE-2026-10985 | 6.5 | 23.4 | Chrome | CWE-125 | Out of bounds read in Skia in Google Chrome prior to 149.0.7827.53 allowed a … | |
| CVE-2026-10992 | 6.5 | 23.4 | Chrome | CWE-20 | Insufficient data validation in Animation in Google Chrome prior to 149.0.782… | |
| CVE-2026-11006 | 6.5 | 23.4 | Chrome | CWE-125 | Out of bounds read in Dawn in Google Chrome prior to 149.0.7827.53 allowed a … | |
| CVE-2026-11007 | 6.5 | 23.4 | Chrome | CWE-20 | Insufficient validation of untrusted input in WebView in Google Chrome on And… | |
| CVE-2026-11008 | 6.5 | 23.4 | Chrome | CWE-20 | Insufficient validation of untrusted input in WebAppInstalls in Google Chrome… | |
| CVE-2026-11013 | 6.5 | 23.4 | Chrome | CWE-20 | Insufficient validation of untrusted input in Network in Google Chrome prior … | |
| CVE-2026-11117 | 8.8 | 23.2 | Chrome | CWE-416 | Use after free in Views in Google Chrome on Windows prior to 149.0.7827.53 al… | |
| CVE-2026-10911 | 8.3 | 23.2 | Chrome | CWE-20 | Insufficient validation of untrusted input in Media in Google Chrome prior to… | |
| CVE-2026-10917 | 8.3 | 23.2 | Chrome | CWE-20 | Insufficient validation of untrusted input in Media in Google Chrome prior to… | |
| CVE-2026-10920 | 8.3 | 23.2 | Chrome | CWE-20 | Insufficient validation of untrusted input in WebShare in Google Chrome on Ma… | |
| CVE-2026-10990 | 9.6 | 23.0 | Chrome | CWE-416 | Use after free in Glic in Google Chrome prior to 149.0.7827.53 allowed a remo… | |
| CVE-2026-11002 | 9.6 | 23.0 | Chrome | CWE-416 | Use after free in Autofill in Google Chrome prior to 149.0.7827.53 allowed a … | |
| CVE-2026-10922 | 8.8 | 22.9 | Chrome | CWE-20 | Insufficient validation of untrusted input in DevTools in Google Chrome prior… | |
| CVE-2026-40605 | 5.7 | 22.9 | Tautulli | Tautulli | CWE-22 | Tautulli Vulnerable to Authenticated Path Traversal in Cache Deletion API |
| CVE-2026-10874 | 2.1 | 22.9 | projectworlds | Online Art Gallery Shop Project | CWE-74 | projectworlds Online Art Gallery Shop Project adminHome.php sql injection |
| CVE-2026-10875 | 2.1 | 22.9 | projectworlds | Online Art Gallery Shop Project | CWE-74 | projectworlds Online Art Gallery Shop Project adminHome.ph sql injection |
| CVE-2026-4104 | 9.8 | 22.7 | Akmer Informatics Automation Industry and Trade Ltd. Co. | TeknoPass | CWE-89 | SQLi in Akmer Informatics' TeknoPass |
| CVE-2024-27892 | 7.2 | 22.8 | Arista Networks | EOS | CWE-306 | On affected platforms running Arista EOS with OpenConfig configured, a gNMI S… |
| CVE-2026-11043 | 9.6 | 22.7 | Chrome | CWE-787 | Out of bounds write in ANGLE in Google Chrome on Mac prior to 149.0.7827.53 a… | |
| CVE-2026-11047 | 9.6 | 22.7 | Chrome | CWE-20 | Inappropriate implementation in Base in Google Chrome on Windows prior to 149… | |
| CVE-2026-10932 | 8.8 | 22.7 | Chrome | CWE-416 | Use after free in UI in Google Chrome on Android prior to 149.0.7827.53 allow… | |
| CVE-2026-11042 | 8.8 | 22.7 | Chrome | CWE-416 | Use after free in Views in Google Chrome prior to 149.0.7827.53 allowed a rem… | |
| CVE-2026-10966 | 9.6 | 22.6 | Chrome | CWE-20 | Inappropriate implementation in Codecs in Google Chrome prior to 149.0.7827.5… | |
| CVE-2026-10944 | 6.5 | 22.1 | Chrome | CWE-693 | Insufficient policy enforcement in Autofill in Google Chrome on iOS prior to … | |
| CVE-2026-10950 | 6.5 | 22.1 | Chrome | CWE-693 | Insufficient policy enforcement in Autofill in Google Chrome on iOS prior to … | |
| CVE-2026-47706 | 5.3 | 22.1 | strawberry-graphql | strawberry | CWE-400 | Strawberry GraphQL has a Circular Fragment Reference DOS |
| CVE-2026-49191 | 9.3 | 21.7 | Acer | Connect M6E 5G Portable WiFi Router | CWE-287 | Exposed Hard-coded M3WebServer Backend API Key |
| CVE-2026-11279 | 8.8 | 21.5 | Chrome | CWE-125 | Out of bounds read in DevTools in Google Chrome prior to 149.0.7827.53 allowe… | |
| CVE-2026-10960 | 8.3 | 21.6 | Chrome | CWE-457 | Uninitialized Use in Codecs in Google Chrome prior to 149.0.7827.53 allowed a… | |
| CVE-2026-50211 | 8.8 | 21.5 | Acer | Connect M6E 5G Portable WiFi Router | CWE-134 | Exposed Factory Testing App Boundaries |
| CVE-2026-50219 | 5.9 | 21.3 | libexpat project | libexpat | CWE-416 | libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_GetB… |
| CVE-2026-10999 | 6.5 | 21.2 | Chrome | CWE-190 | Integer overflow in ANGLE in Google Chrome on Windows prior to 149.0.7827.53 … | |
| CVE-2026-10884 | 8.3 | 21.1 | Chrome | CWE-416 | Use after free in Chromecast in Google Chrome prior to 149.0.7827.53 allowed … | |
| CVE-2026-10889 | 8.3 | 21.1 | Chrome | CWE-125 | Out of bounds read in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a… | |
| CVE-2026-10894 | 8.3 | 21.1 | Chrome | CWE-416 | Use after free in Printing in Google Chrome on Linux prior to 149.0.7827.53 a… | |
| CVE-2026-10905 | 8.3 | 21.1 | Chrome | CWE-416 | Use after free in Network in Google Chrome prior to 149.0.7827.53 allowed a r… | |
| CVE-2026-10908 | 8.3 | 21.1 | Chrome | CWE-416 | Use after free in FullScreen in Google Chrome on Windows prior to 149.0.7827.… | |
| CVE-2026-10909 | 8.3 | 21.1 | Chrome | CWE-416 | Use after free in Dawn in Google Chrome prior to 149.0.7827.53 allowed a remo… | |
| CVE-2026-10918 | 8.3 | 21.1 | Chrome | CWE-416 | Use after free in Viz in Google Chrome prior to 149.0.7827.53 allowed a remot… | |
| CVE-2026-10919 | 8.3 | 21.1 | Chrome | CWE-416 | Use after free in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a rem… | |
| CVE-2026-10921 | 8.3 | 21.1 | Chrome | CWE-190 | Integer overflow in Dawn in Google Chrome prior to 149.0.7827.53 allowed a re… | |
| CVE-2026-10924 | 8.3 | 21.1 | Chrome | CWE-190 | Integer overflow in Chromecast in Google Chrome prior to 149.0.7827.53 allowe… | |
| CVE-2026-10925 | 8.3 | 21.1 | Chrome | CWE-787 | Out of bounds write in Skia in Google Chrome on Mac prior to 149.0.7827.53 al… | |
| CVE-2026-10927 | 8.3 | 21.1 | Chrome | CWE-125 | Out of bounds read in Dawn in Google Chrome prior to 149.0.7827.53 allowed a … | |
| CVE-2026-10953 | 8.3 | 21.1 | Chrome | CWE-416 | Use after free in Core in Google Chrome on Android prior to 149.0.7827.53 all… | |
| CVE-2026-11010 | 8.3 | 21.1 | Chrome | CWE-416 | Use after free in WebShare in Google Chrome on Android prior to 149.0.7827.53… | |
| CVE-2026-11012 | 8.3 | 21.1 | Chrome | CWE-416 | Use after free in Serial in Google Chrome on Android prior to 149.0.7827.53 a… | |
| CVE-2026-10899 | 7.5 | 21.1 | Chrome | CWE-416 | Use after free in Ozone in Google Chrome on Linux prior to 149.0.7827.53 allo… | |
| CVE-2026-10900 | 7.5 | 21.1 | Chrome | CWE-416 | Use after free in Passwords in Google Chrome on Mac prior to 149.0.7827.53 al… | |
| CVE-2026-10970 | 8.3 | 21.0 | Chrome | CWE-20 | Insufficient validation of untrusted input in InterestGroups in Google Chrome… | |
| CVE-2026-10969 | 7.5 | 21.0 | Chrome | CWE-20 | Insufficient validation of untrusted input in Extensions in Google Chrome pri… | |
| CVE-2026-11027 | 6.5 | 21.0 | Chrome | CWE-20 | Insufficient validation of untrusted input in Glic in Google Chrome prior to … | |
| CVE-2026-11044 | 6.5 | 21.0 | Chrome | CWE-472 | Integer overflow in ANGLE in Google Chrome on Mac prior to 149.0.7827.53 allo… | |
| CVE-2026-11045 | 6.5 | 21.0 | Chrome | CWE-20 | Insufficient validation of untrusted input in GPU in Google Chrome prior to 1… | |
| CVE-2026-10981 | 6.5 | 20.9 | Chrome | CWE-20 | Insufficient validation of untrusted input in Codecs in Google Chrome prior t… | |
| CVE-2026-44917 | 4.9 | 20.8 | OpenStack | Ironic | CWE-669 | OpenStack Ironic before 35.0.2 allows a malicious authenticated project admin… |
| CVE-2026-11116 | 8.8 | 20.7 | Chrome | CWE-416 | Use after free in Chromoting in Google Chrome prior to 149.0.7827.53 allowed … | |
| CVE-2024-27891 | 6.9 | 20.6 | Arista Networks | EOS | CWE-284 | On affected platforms running Arista EOS with MACsec and egress ACLs configur… |
| CVE-2026-11049 | 8.8 | 20.5 | Chrome | CWE-416 | Use after free in Password Manager in Google Chrome prior to 149.0.7827.53 al… | |
| CVE-2026-11050 | 8.8 | 20.5 | Chrome | CWE-416 | Use after free in V8 in Google Chrome prior to 149.0.7827.53 allowed a remote… | |
| CVE-2026-11055 | 8.8 | 20.5 | Chrome | CWE-416 | Use after free in ANGLE in Google Chrome on Windows prior to 149.0.7827.53 al… | |
| CVE-2026-11059 | 8.8 | 20.5 | Chrome | CWE-416 | Use after free in Blink in Google Chrome prior to 149.0.7827.53 allowed a rem… | |
| CVE-2026-11060 | 8.8 | 20.5 | Chrome | CWE-416 | Use after free in Media in Google Chrome on Windows prior to 149.0.7827.53 al… | |
| CVE-2026-11077 | 8.8 | 20.5 | Chrome | CWE-125 | Bad cast in Dawn in Google Chrome prior to 149.0.7827.53 allowed a remote att… | |
| CVE-2026-11086 | 8.8 | 20.5 | Chrome | CWE-20 | Inappropriate implementation in Dawn in Google Chrome prior to 149.0.7827.53 … | |
| CVE-2026-11125 | 8.8 | 20.5 | Chrome | CWE-416 | Use after free in Compositing in Google Chrome prior to 149.0.7827.53 allowed… | |
| CVE-2026-11130 | 8.8 | 20.5 | Chrome | CWE-416 | Use after free in Media in Google Chrome prior to 149.0.7827.53 allowed a rem… | |
| CVE-2026-11136 | 8.8 | 20.5 | Chrome | CWE-416 | Use after free in Canvas in Google Chrome prior to 149.0.7827.53 allowed a re… | |
| CVE-2026-11164 | 8.8 | 20.5 | Chrome | CWE-416 | Use after free in Blink in Google Chrome prior to 149.0.7827.53 allowed a rem… | |
| CVE-2026-11171 | 8.8 | 20.5 | Chrome | CWE-472 | Integer overflow in Blink in Google Chrome prior to 149.0.7827.53 allowed a r… | |
| CVE-2026-11173 | 8.8 | 20.5 | Chrome | CWE-787 | Out of bounds write in V8 in Google Chrome prior to 149.0.7827.53 allowed a r… | |
| CVE-2026-11211 | 8.8 | 20.5 | Chrome | CWE-472 | Integer overflow in V8 in Google Chrome prior to 149.0.7827.53 allowed a remo… | |
| CVE-2026-11262 | 8.8 | 20.5 | Chrome | CWE-416 | Use after free in TabStrip in Google Chrome prior to 149.0.7827.53 allowed a … | |
| CVE-2026-10912 | 6.5 | 20.5 | Chrome | CWE-20 | Insufficient validation of untrusted input in Extensions in Google Chrome pri… | |
| CVE-2026-11016 | 6.5 | 20.5 | Chrome | CWE-20 | Insufficient validation of untrusted input in Network in Google Chrome prior … | |
| CVE-2026-11018 | 6.5 | 20.5 | Chrome | CWE-602 | Insufficient policy enforcement in Actor in Google Chrome prior to 149.0.7827… | |
| CVE-2026-11022 | 6.5 | 20.5 | Chrome | CWE-20 | Insufficient validation of untrusted input in DevTools in Google Chrome prior… | |
| CVE-2026-11025 | 6.5 | 20.5 | Chrome | CWE-602 | Insufficient policy enforcement in Navigation in Google Chrome on Android pri… | |
| CVE-2026-11037 | 9.6 | 20.3 | Chrome | CWE-787 | Out of bounds write in Codecs in Google Chrome prior to 149.0.7827.53 allowed… | |
| CVE-2026-11030 | 8.8 | 20.3 | Chrome | CWE-416 | Use after free in Network in Google Chrome prior to 149.0.7827.53 allowed a r… | |
| CVE-2026-38570 | 7.5 | 20.3 | n/a | n/a | CWE-125 | bacnet_stack 1.3.1 contains an Out-of-bounds Read in bacnet_tag_number_decode… |
| CVE-2026-11095 | 9.6 | 20.0 | Chrome | CWE-20 | Insufficient validation of untrusted input in Codecs in Google Chrome prior t… | |
| CVE-2026-11113 | 9.6 | 20.0 | Chrome | CWE-20 | Insufficient validation of untrusted input in ANGLE in Google Chrome prior to… | |
| CVE-2026-11120 | 9.6 | 20.0 | Chrome | CWE-20 | Insufficient validation of untrusted input in Enterprise Reporting in Google … | |
| CVE-2026-10915 | 8.3 | 19.9 | Chrome | CWE-416 | Use after free in Core in Google Chrome on iOS prior to 149.0.7827.53 allowed… | |
| CVE-2026-11004 | 5.3 | 19.8 | Chrome | CWE-125 | Out of bounds read in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a… | |
| CVE-2026-11005 | 5.3 | 19.8 | Chrome | CWE-125 | Out of bounds read in ANGLE in Google Chrome on Windows prior to 149.0.7827.5… | |
| CVE-2026-10937 | 6.5 | 19.7 | Chrome | CWE-346 | Inappropriate implementation in Passwords in Google Chrome prior to 149.0.782… | |
| CVE-2026-10810 | 2.1 | 19.7 | itsourcecode | Fees Management System | CWE-79 | itsourcecode Fees Management System navbar.php cross site scripting |
| CVE-2026-11191 | 8.8 | 19.5 | Chrome | CWE-125 | Out of bounds memory access in ANGLE in Google Chrome prior to 149.0.7827.53 … | |
| CVE-2019-25726 | 8.8 | 19.3 | Nicheoffice | All in One Video Downloader | CWE-89 | All in One Video Downloader 1.2 SQL Injection via admin page-edit |
| CVE-2019-25730 | 8.8 | 19.3 | Themerig | Listing Hub CMS | CWE-89 | Listing Hub CMS 1.0 SQL Injection via pages.php id |
| CVE-2026-41234 | 7.6 | 19.2 | froxlor | froxlor | CWE-74 | Froxlor: BIND Zone File Injection via TXT Record Content |
| CVE-2026-11017 | 6.5 | 19.2 | Chrome | CWE-284 | Inappropriate implementation in Link Preview in Google Chrome prior to 149.0.… | |
| CVE-2026-10876 | 2.1 | 19.2 | SourceCodester | Ship Ferry Ticket Reservation System | CWE-266 | SourceCodester Ship Ferry Ticket Reservation System admin improper authorization |
| CVE-2026-41237 | 8.6 | 19.1 | froxlor | froxlor | CWE-74 | Froxlor has an incomplete fix for CVE-2026-30932 |
| CVE-2025-59874 | 8.1 | 19.0 | HCL | Hive | CWE-1027 | HCL Hive Telco Observability is affected by a Required directives missing fro… |
| CVE-2026-10933 | 8.3 | 18.9 | Chrome | CWE-416 | Use after free in Audio in Google Chrome on Windows prior to 149.0.7827.53 al… | |
| CVE-2026-10934 | 8.3 | 18.9 | Chrome | CWE-416 | Use after free in Autofill in Google Chrome on Android prior to 149.0.7827.53… | |
| CVE-2026-10961 | 8.3 | 18.9 | Chrome | CWE-416 | Use after free in Chrome for iOS in Google Chrome on iOS prior to 149.0.7827.… | |
| CVE-2026-10967 | 8.3 | 18.9 | Chrome | CWE-416 | Use after free in SurfaceCapture in Google Chrome on Android prior to 149.0.7… | |
| CVE-2026-11153 | 9.1 | 18.4 | Chrome | CWE-1300 | Side-channel information leakage in Forms in Google Chrome prior to 149.0.782… | |
| CVE-2026-11242 | 7.5 | 18.4 | Chrome | CWE-20 | Insufficient validation of untrusted input in Plugins in Google Chrome prior … | |
| CVE-2026-11255 | 7.5 | 18.4 | Chrome | CWE-20 | Insufficient validation of untrusted input in Storage Access API in Google Ch… | |
| CVE-2026-10586 | 7.2 | 18.4 | wpdevteam | Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns | CWE-918 | Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns <= … |
| CVE-2026-43986 | 9.9 | 18.1 | Tautulli | Tautulli | CWE-918 | Tautulli vulnerable to unauthenticated SSRF in /image/<hash> via attacker-see… |
| CVE-2019-25728 | 8.8 | 18.1 | care2x | Care2x | CWE-89 | Care2x 2.7 Hospital Information System SQL Injection via ck_config |
| CVE-2019-25732 | 8.8 | 18.0 | eitube | EI-Tube | CWE-89 | PHP EI-Tube Script 3 SQL Injection via search parameter |
| CVE-2019-25745 | 8.8 | 18.0 | jgwhite33 | Google Review Slider | CWE-89 | WordPress Plugin Google Review Slider 6.1 SQL Injection via tid |
| CVE-2026-46741 | 7.5 | 18.1 | SANBEG | Etsy::StatsD | CWE-93 | Etsy::StatsD versions through 1.002002 for Perl allow metric injections |
| CVE-2026-10996 | 6.5 | 18.1 | Chrome | CWE-346 | Inappropriate implementation in Workers in Google Chrome prior to 149.0.7827.… | |
| CVE-2026-11019 | 6.5 | 18.1 | Chrome | CWE-290 | Inappropriate implementation in Payments in Google Chrome on Android prior to… | |
| CVE-2026-50266 | 2.2 | 18.1 | OpenStack | Neutron | CWE-863 | In OpenStack Neutron before 28.0.1, a project manager can create or update a … |
| CVE-2026-11144 | 8.8 | 17.7 | Chrome | CWE-416 | Use after free in Media in Google Chrome prior to 149.0.7827.53 allowed a rem… | |
| CVE-2019-25729 | 9.3 | 17.7 | simcy_creative | PDF Signer | CWE-352 | PDF Signer 3.0 Server-Side Template Injection RCE via CSRF Cookie |
| CVE-2026-46739 | 5.3 | 17.7 | COSIMO | Net::Statsd | CWE-93 | Net::Statsd versions before 0.13 for Perl allow metric injections |
| CVE-2026-49202 | 8.8 | 17.5 | Acer | Connect M6E 5G Portable WiFi Router | CWE-287 | Unverified Meeting Recording Endpoints & Permissive CORS |
| CVE-2026-11263 | 6.5 | 17.4 | Chrome | CWE-693 | Insufficient policy enforcement in WebAuthentication in Google Chrome on Andr… | |
| CVE-2026-11052 | 9.6 | 17.3 | Chrome | CWE-843 | Type Confusion in GPU in Google Chrome on Windows prior to 149.0.7827.53 allo… | |
| CVE-2026-11100 | 9.6 | 17.3 | Chrome | CWE-416 | Use after free in File Input in Google Chrome on Mac prior to 149.0.7827.53 a… | |
| CVE-2026-5589 | 6.3 | 17.2 | zephyrproject-rtos | Zephyr | CWE-787 | Out-of-bounds write caused by an integer underflow in the Bluetooth Mesh subs… |
| CVE-2026-11061 | 9.6 | 17.0 | Chrome | CWE-125 | Type Confusion in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a rem… | |
| CVE-2026-11066 | 9.6 | 17.0 | Chrome | CWE-20 | Insufficient validation of untrusted input in ANGLE in Google Chrome prior to… | |
| CVE-2026-11033 | 6.5 | 16.6 | Chrome | CWE-457 | Uninitialized Use in WebML in Google Chrome on Mac prior to 149.0.7827.53 all… | |
| CVE-2026-11039 | 6.5 | 16.6 | Chrome | CWE-457 | Uninitialized Use in Skia in Google Chrome prior to 149.0.7827.53 allowed a r… | |
| CVE-2026-11057 | 6.5 | 16.6 | Chrome | CWE-457 | Uninitialized Use in Skia in Google Chrome prior to 149.0.7827.53 allowed a r… | |
| CVE-2026-11064 | 6.5 | 16.6 | Chrome | CWE-457 | Race in GPU in Google Chrome on Android prior to 149.0.7827.53 allowed a remo… | |
| CVE-2026-11067 | 6.5 | 16.6 | Chrome | CWE-457 | Uninitialized Use in Dawn in Google Chrome prior to 149.0.7827.53 allowed a r… | |
| CVE-2026-11087 | 6.5 | 16.6 | Chrome | CWE-457 | Uninitialized Use in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a … | |
| CVE-2026-11089 | 6.5 | 16.6 | Chrome | CWE-457 | Uninitialized Use in Media in Google Chrome prior to 149.0.7827.53 allowed a … | |
| CVE-2026-11090 | 6.5 | 16.6 | Chrome | CWE-457 | Uninitialized Use in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a … | |
| CVE-2026-11101 | 6.5 | 16.6 | Chrome | CWE-457 | Uninitialized Use in Dawn in Google Chrome on Windows prior to 149.0.7827.53 … | |
| CVE-2026-11104 | 6.5 | 16.6 | Chrome | CWE-457 | Uninitialized Use in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a … | |
| CVE-2026-11109 | 6.5 | 16.6 | Chrome | CWE-457 | Uninitialized Use in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a … | |
| CVE-2026-11110 | 6.5 | 16.6 | Chrome | CWE-457 | Uninitialized Use in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a … | |
| CVE-2026-11123 | 6.5 | 16.6 | Chrome | CWE-457 | Uninitialized Use in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a … | |
| CVE-2026-11137 | 6.5 | 16.6 | Chrome | CWE-457 | Uninitialized Use in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a … | |
| CVE-2026-11138 | 6.5 | 16.6 | Chrome | CWE-457 | Uninitialized Use in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a … | |
| CVE-2026-11141 | 6.5 | 16.6 | Chrome | CWE-457 | Uninitialized Use in Audio in Google Chrome prior to 149.0.7827.53 allowed a … | |
| CVE-2026-11268 | 6.5 | 16.6 | Chrome | CWE-457 | Uninitialized Use in ANGLE in Google Chrome on Windows prior to 149.0.7827.53… | |
| CVE-2026-11085 | 8.8 | 16.2 | Chrome | CWE-472 | Integer overflow in GPU in Google Chrome on Android prior to 149.0.7827.53 al… | |
| CVE-2026-11091 | 8.8 | 16.2 | Chrome | CWE-125 | Inappropriate implementation in Dawn in Google Chrome prior to 149.0.7827.53 … | |
| CVE-2026-11182 | 6.5 | 16.3 | Chrome | CWE-200 | Inappropriate implementation in SVG in Google Chrome prior to 149.0.7827.53 a… | |
| CVE-2026-41522 | 7.1 | 16.1 | dfir-iris | iris-web | CWE-285 | Iris has an Improper Authorization issue |
| CVE-2026-5228 | 8.8 | 16.0 | Kurt Software Studio | WriteUp Mobile App | CWE-284 | Improper Access Control in Kurt Software Studio's WriteUp Mobile App |
| CVE-2026-49187 | 8.7 | 16.0 | Acer | Connect M6E 5G Portable WiFi Router | CWE-200 | Hard-coded APK Resource Credentials & Scepters |
| CVE-2026-49193 | 8.7 | 16.0 | Acer | Connect M6E 5G Portable WiFi Router | CWE-200 | Publicly Readable AWS S3 Telemetry Buckets |
| CVE-2026-41858 | 7.5 | 16.0 | Cloud Foundry Foundation | windows-utilities-release | CWE-338 | Weak Randomness / Insecure Cryptographic Primitive (CWE-338) in Get-RandomPas… |
| CVE-2026-50210 | 6.9 | 16.0 | Acer | Connect M6E 5G Portable WiFi Router | CWE-200 | Weak Static Cryptographic Initialization Vectors |
| CVE-2026-45432 | 8.7 | 15.8 | GX INDIA | GX Earth 2022 | CWE-319 | Cleartext Transmission of Credentials Vulnerability in GX Earth ONT Models |
| CVE-2026-11224 | 8.1 | 15.8 | Chrome | CWE-416 | Use after free in Chromoting in Google Chrome on Linux prior to 149.0.7827.53… | |
| CVE-2026-10597 | 6.9 | 15.9 | ITPison | OMICARD EDM | CWE-639 | ITPison|OMICARD EDM - Insecure Direct Object Reference |
| CVE-2026-11282 | 9.6 | 15.7 | Chrome | CWE-693 | Insufficient policy enforcement in Sandbox in Google Chrome on Linux prior to… | |
| CVE-2026-50225 | 8.8 | 15.7 | Acer | Connect M6E 5G Portable WiFi Router | CWE-306 | Account Creation Exhaustion |
| CVE-2026-11096 | 6.5 | 15.7 | Chrome | CWE-125 | Out of bounds read in WebRTC in Google Chrome prior to 149.0.7827.53 allowed … | |
| CVE-2026-11105 | 6.5 | 15.8 | Chrome | CWE-20 | Insufficient validation of untrusted input in WebUI in Google Chrome prior to… | |
| CVE-2026-11230 | 8.8 | 15.6 | Chrome | CWE-416 | Use after free in Extensions in Google Chrome prior to 149.0.7827.53 allowed … | |
| CVE-2026-11235 | 8.8 | 15.6 | Chrome | CWE-20 | Insufficient policy enforcement in Compositing in Google Chrome prior to 149.… | |
| CVE-2026-11248 | 8.8 | 15.5 | Chrome | CWE-693 | Inappropriate implementation in Google Lens in Google Chrome prior to 149.0.7… | |
| CVE-2026-10997 | 6.5 | 15.4 | Chrome | CWE-732 | Insufficient policy enforcement in Extensions in Google Chrome prior to 149.0… | |
| CVE-2026-11250 | 9.6 | 15.2 | Chrome | CWE-416 | Inappropriate implementation in DevTools in Google Chrome prior to 149.0.7827… | |
| CVE-2026-10868 | 9.0 | 15.3 | misp | misp | CWE-269 | MISP user edit endpoint mass assignment vulnerability allows unauthorized use… |
| CVE-2026-50205 | 8.8 | 15.0 | Acer | Connect M6E 5G Portable WiFi Router | CWE-532 | Plaintext Log Credential Leakage |
| CVE-2026-11170 | 8.1 | 15.1 | Chrome | CWE-693 | Inappropriate implementation in Chromoting in Google Chrome on Linux prior to… | |
| CVE-2026-11284 | 6.5 | 15.0 | Chrome | CWE-1300 | Side-channel information leakage in PerformanceAPIs in Google Chrome prior to… | |
| CVE-2026-41178 | 5.3 | 14.9 | open-telemetry | go.opentelemetry.io/otel/baggage | CWE-789 | OpenTelemetry-Go's baggage parsing no longer caps raw header length |
| CVE-2026-11303 | 8.8 | 14.9 | Chrome | CWE-416 | Use after free in PDFium in Google Chrome prior to 149.0.7827.53 allowed a re… | |
| CVE-2026-11056 | 9.6 | 14.6 | Chrome | CWE-20 | Insufficient validation of untrusted input in SiteIsolation in Google Chrome … | |
| CVE-2026-11063 | 9.6 | 14.6 | Chrome | CWE-20 | Insufficient validation of untrusted input in WebNN in Google Chrome on Windo… | |
| CVE-2026-11082 | 9.6 | 14.6 | Chrome | CWE-416 | Race in GPU in Google Chrome on Android prior to 149.0.7827.53 allowed a remo… | |
| CVE-2026-11094 | 9.6 | 14.5 | Chrome | CWE-416 | Use after free in Codecs in Google Chrome on Windows prior to 149.0.7827.53 a… | |
| CVE-2026-11114 | 9.6 | 14.5 | Chrome | CWE-416 | Use after free in Device Trust in Google Chrome on Mac prior to 149.0.7827.53… | |
| CVE-2026-11119 | 9.6 | 14.5 | Chrome | CWE-20 | Inappropriate implementation in GPU in Google Chrome on Android prior to 149.… | |
| CVE-2026-11131 | 9.6 | 14.5 | Chrome | CWE-416 | Use after free in Autofill in Google Chrome on Android prior to 149.0.7827.53… | |
| CVE-2026-11146 | 9.6 | 14.6 | Chrome | CWE-20 | Insufficient validation of untrusted input in Chromoting in Google Chrome pri… | |
| CVE-2026-11152 | 9.6 | 14.6 | Chrome | CWE-416 | Object lifecycle issue in Dawn in Google Chrome prior to 149.0.7827.53 allowe… | |
| CVE-2026-11163 | 9.6 | 14.6 | Chrome | CWE-416 | Use after free in Messages in Google Chrome on Android prior to 149.0.7827.53… | |
| CVE-2026-11165 | 9.6 | 14.6 | Chrome | CWE-416 | Use after free in WebMIDI in Google Chrome on iOS prior to 149.0.7827.53 allo… | |
| CVE-2026-11167 | 9.6 | 14.6 | Chrome | CWE-250 | Inappropriate implementation in WebView in Google Chrome on Android prior to … | |
| CVE-2026-11041 | 8.8 | 14.6 | Chrome | CWE-20 | Insufficient validation of untrusted input in Media in Google Chrome on Windo… | |
| CVE-2026-11071 | 8.8 | 14.6 | Chrome | CWE-416 | Use after free in Base in Google Chrome on Linux prior to 149.0.7827.53 allow… | |
| CVE-2026-11080 | 8.8 | 14.6 | Chrome | CWE-416 | Use after free in WebView in Google Chrome on Android prior to 149.0.7827.53 … | |
| CVE-2026-11124 | 8.8 | 14.5 | Chrome | CWE-122 | Integer overflow in Skia in Google Chrome prior to 149.0.7827.53 allowed a re… | |
| CVE-2026-11172 | 8.8 | 14.6 | Chrome | CWE-451 | Incorrect security UI in Contact Picker in Google Chrome on Android prior to … | |
| CVE-2026-11175 | 8.8 | 14.5 | Chrome | CWE-451 | Incorrect security UI in Messages in Google Chrome on Android prior to 149.0.… | |
| CVE-2026-11177 | 8.8 | 14.6 | Chrome | CWE-416 | Use after free in Omnibox in Google Chrome prior to 149.0.7827.53 allowed a r… | |
| CVE-2026-11188 | 8.8 | 14.5 | Chrome | CWE-416 | Use after free in USB in Google Chrome on Android prior to 149.0.7827.53 allo… | |
| CVE-2026-11202 | 8.8 | 14.5 | Chrome | CWE-20 | Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior … | |
| CVE-2026-11272 | 8.8 | 14.6 | Chrome | CWE-20 | Insufficient validation of untrusted input in Reading List in Google Chrome o… | |
| CVE-2026-50224 | 6.9 | 14.6 | Acer | Connect M6E 5G Portable WiFi Router | CWE-200 | Unauthenticated IPv6 WAN Management Exposure |
| CVE-2026-11029 | 9.6 | 14.4 | Chrome | CWE-20 | Insufficient validation of untrusted input in Drag and Drop in Google Chrome … | |
| CVE-2026-11287 | 6.5 | 14.4 | Chrome | CWE-20 | Insufficient policy enforcement in Navigation in Google Chrome on Android pri… | |
| CVE-2026-10984 | 5.4 | 14.4 | Chrome | CWE-451 | Inappropriate implementation in Accessibility in Google Chrome on Android pri… | |
| CVE-2026-11098 | 5.3 | 14.4 | Chrome | CWE-20 | Insufficient validation of untrusted input in GPU in Google Chrome prior to 1… | |
| CVE-2026-49194 | 9.4 | 14.3 | Acer | Connect M6E 5G Portable WiFi Router | CWE-287 | SCREEN_CLICK Authentication Bypass |
| CVE-2026-50213 | 8.7 | 14.3 | Acer | Connect M6E 5G Portable WiFi Router | CWE-798 | Bulk User Private Data Harvesting |
| CVE-2026-42539 | 6.5 | 14.3 | dfir-iris | iris-web | CWE-201 | IRIS has an Excessive Data Exposure issue |
| CVE-2026-11051 | 6.5 | 13.9 | Chrome | CWE-125 | Out of bounds read in ANGLE in Google Chrome on Linux prior to 149.0.7827.53 … | |
| CVE-2026-11073 | 6.5 | 13.9 | Chrome | CWE-416 | Use after free in WebGL in Google Chrome prior to 149.0.7827.53 allowed a rem… | |
| CVE-2026-11075 | 6.5 | 13.9 | Chrome | CWE-125 | Out of bounds read in V8 in Google Chrome prior to 149.0.7827.53 allowed a re… | |
| CVE-2026-11093 | 6.5 | 13.9 | Chrome | CWE-20 | Inappropriate implementation in Printing in Google Chrome prior to 149.0.7827… | |
| CVE-2026-11097 | 6.5 | 13.9 | Chrome | CWE-474 | Inappropriate implementation in WebView in Google Chrome on Android prior to … | |
| CVE-2026-11121 | 6.5 | 13.9 | Chrome | CWE-20 | Insufficient validation of untrusted input in Skia in Google Chrome prior to … | |
| CVE-2026-11128 | 6.5 | 13.9 | Chrome | CWE-20 | Inappropriate implementation in Web Share in Google Chrome prior to 149.0.782… | |
| CVE-2026-11140 | 6.5 | 13.9 | Chrome | CWE-20 | Out of bounds read in Chromecast in Google Chrome prior to 149.0.7827.53 allo… | |
| CVE-2026-11160 | 6.5 | 13.9 | Chrome | CWE-125 | Out of bounds read in Input in Google Chrome on Linux prior to 149.0.7827.53 … | |
| CVE-2026-11168 | 6.5 | 13.9 | Chrome | CWE-200 | Inappropriate implementation in Extensions in Google Chrome prior to 149.0.78… | |
| CVE-2026-11180 | 6.5 | 13.9 | Chrome | CWE-200 | Inappropriate implementation in SVG in Google Chrome prior to 149.0.7827.53 a… | |
| CVE-2026-11203 | 6.5 | 13.9 | Chrome | CWE-200 | Inappropriate implementation in GPU in Google Chrome on Mac prior to 149.0.78… | |
| CVE-2026-11206 | 6.5 | 13.9 | Chrome | CWE-693 | Insufficient policy enforcement in ServiceWorker in Google Chrome prior to 14… | |
| CVE-2026-11208 | 6.5 | 13.9 | Chrome | CWE-416 | Use after free in Codecs in Google Chrome prior to 149.0.7827.53 allowed a re… | |
| CVE-2026-11209 | 6.5 | 13.9 | Chrome | CWE-200 | Inappropriate implementation in Passwords in Google Chrome prior to 149.0.782… | |
| CVE-2026-11271 | 6.5 | 13.9 | Chrome | CWE-200 | Inappropriate implementation in Passwords in Google Chrome prior to 149.0.782… | |
| CVE-2026-11305 | 8.8 | 13.8 | Chrome | CWE-416 | Use after free in PDFium in Google Chrome prior to 149.0.7827.53 allowed a re… | |
| CVE-2026-11307 | 8.8 | 13.8 | Chrome | CWE-416 | Use after free in PDFium in Google Chrome prior to 149.0.7827.53 allowed a re… | |
| CVE-2026-10940 | 8.3 | 13.9 | Chrome | CWE-362 | Race in Codecs in Google Chrome on Windows prior to 149.0.7827.53 allowed a r… | |
| CVE-2026-11111 | 8.1 | 13.8 | Chrome | CWE-125 | Out of bounds read in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a… | |
| CVE-2026-11196 | 6.5 | 13.9 | Chrome | CWE-843 | Type Confusion in XML in Google Chrome prior to 149.0.7827.53 allowed a remot… | |
| CVE-2026-11179 | 8.8 | 13.7 | Chrome | CWE-284 | Inappropriate implementation in ORB in Google Chrome prior to 149.0.7827.53 a… | |
| CVE-2026-41235 | 8.6 | 13.7 | froxlor | froxlor | CWE-863 | Froxlor has an authorization bypass in FTP shell assignment via missing serve… |
| CVE-2026-11107 | 4.3 | 13.6 | Chrome | CWE-451 | Inappropriate implementation in Downloads in Google Chrome prior to 149.0.782… | |
| CVE-2026-11108 | 8.8 | 13.5 | Chrome | CWE-269 | Inappropriate implementation in NFC in Google Chrome on Android prior to 149.… | |
| CVE-2026-11023 | 6.5 | 13.5 | Chrome | CWE-20 | Inappropriate implementation in WebAppInstalls in Google Chrome prior to 149.… | |
| CVE-2026-10863 | 6.4 | 13.3 | misp | misp | CWE-20 | MISP User-controlled order parameter in correlations over-correlation endpoint |
| CVE-2026-11306 | 8.8 | 13.2 | Chrome | CWE-416 | Use after free in PDFium in Google Chrome prior to 149.0.7827.53 allowed a re… | |
| CVE-2026-10861 | 5.1 | 13.1 | misp | misp | CWE-601 | MISP post-login open redirect via pre_login_requested_url |
| CVE-2026-11040 | 8.3 | 13.1 | Chrome | CWE-416 | Use after free in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a rem… | |
| CVE-2026-11149 | 7.5 | 12.9 | Chrome | CWE-20 | Insufficient validation of untrusted input in Extensions in Google Chrome pri… | |
| CVE-2026-11151 | 7.5 | 12.9 | Chrome | CWE-20 | Insufficient validation of untrusted input in Password Manager in Google Chro… | |
| CVE-2026-11239 | 7.5 | 12.9 | Chrome | CWE-20 | Inappropriate implementation in Extensions in Google Chrome prior to 149.0.78… | |
| CVE-2026-11020 | 6.5 | 12.9 | Chrome | CWE-346 | Inappropriate implementation in Extensions in Google Chrome prior to 149.0.78… | |
| CVE-2026-11231 | 8.1 | 12.5 | Chrome | CWE-94 | Inappropriate implementation in Safe Browsing in Google Chrome on Mac prior t… | |
| CVE-2026-45739 | 4.3 | 12.5 | strawberry-graphql | strawberry | CWE-200 | Strawberry GraphQL: Default GraphiQL may expose HTTP headers in URLs |
| CVE-2026-8653 | 6.5 | 12.4 | StylemixThemes | MasterStudy LMS Pro | CWE-89 | MasterStudy LMS Pro Plus <= 4.8.20 - Authenticated (Instructor+) SQL Injectio… |
| CVE-2026-11001 | 6.5 | 12.4 | Chrome | CWE-290 | Inappropriate implementation in Payments in Google Chrome prior to 149.0.7827… | |
| CVE-2026-43926 | 6.3 | 12.4 | FOSSBilling | FOSSBilling | CWE-204 | FOSSBilling's password reset confirmation endpoint lacks rate limiting |
| CVE-2026-11070 | 9.6 | 12.3 | Chrome | CWE-20 | Insufficient validation of untrusted input in Chromoting in Google Chrome on … | |
| CVE-2026-11112 | 9.6 | 12.3 | Chrome | CWE-20 | Insufficient validation of untrusted input in Chromoting in Google Chrome on … | |
| CVE-2026-11198 | 9.6 | 12.3 | Chrome | CWE-20 | Insufficient validation of untrusted input in Codecs in Google Chrome prior t… | |
| CVE-2026-11207 | 9.6 | 12.3 | Chrome | CWE-20 | Insufficient validation of untrusted input in Autofill in Google Chrome prior… | |
| CVE-2026-11079 | 8.8 | 12.3 | Chrome | CWE-20 | Insufficient validation of untrusted input in Codecs in Google Chrome prior t… | |
| CVE-2026-11193 | 6.5 | 12.2 | Chrome | CWE-284 | Insufficient policy enforcement in Password Manager in Google Chrome prior to… | |
| CVE-2025-65640 | 6.3 | 12.3 | n/a | n/a | CWE-79 | Cross Site Scripting (XSS) vulnerability in the "Task in Progress / Recent" p… |
| CVE-2026-11014 | 6.5 | 12.0 | Chrome | CWE-602 | Insufficient policy enforcement in Extensions in Google Chrome prior to 149.0… | |
| CVE-2026-10916 | 6.1 | 11.9 | Chrome | CWE-20 | Insufficient validation of untrusted input in DevTools in Google Chrome prior… | |
| CVE-2026-11277 | 4.3 | 11.8 | Chrome | CWE-284 | Insufficient policy enforcement in Chrome for iOS in Google Chrome on iOS pri… | |
| CVE-2026-11256 | 8.3 | 11.7 | Chrome | CWE-125 | Integer overflow in GPU in Google Chrome prior to 149.0.7827.53 allowed a rem… | |
| CVE-2026-11169 | 8.1 | 11.7 | Chrome | CWE-91 | Inappropriate implementation in XML in Google Chrome prior to 149.0.7827.53 a… | |
| CVE-2026-10840 | 7.1 | 11.6 | Red Hat | Red Hat OpenShift Builds 1.7.4 | CWE-732 | Openshift-pipelines-operator-rh: openshift-pipelines-operator: tekton-schedul… |
| CVE-2019-25731 | 5.3 | 11.6 | Zuz | Zuz Music | CWE-79 | Zuz Music 2.1 Persistent Cross-site Scripting via zuzconsole Contact |
| CVE-2019-25737 | 5.3 | 11.6 | Screets | Live Chat Unlimited | CWE-79 | Live Chat Unlimited 2.8.3 Stored Cross-Site Scripting |
| CVE-2026-4881 | 6.0 | 11.5 | Octopus Deploy | Octopus Server | CWE-862 | In affected versions of Octopus Server, permissions were not checked correctl… |
Results continue: ranks 401–624.
Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.
Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.
Day boundary. A day is a UTC calendar day. This page covers 2026-06-04 00:00:00–23:59:59 UTC. All times shown are UTC.
Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.
Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.