Edition of June 30, 2026, continued — page 2 of 2. Back to page 1
| CVE | CVSS | EPSS %ile | Vendor | Product | CWE | Title |
|---|---|---|---|---|---|---|
| CVE-2026-13975 | 5.3 | 16.4 | Chrome | CWE-125 | Out of bounds read in ANGLE in Google Chrome on Mac prior to 150.0.7871.47 al… | |
| CVE-2026-56328 | 7.1 | 16.3 | Capgo | Capgo | CWE-670 | Capgo - Integrity Issue in Release Routing via Multiple Public Channels |
| CVE-2026-14019 | 6.5 | 16.3 | Chrome | CWE-522 | Inappropriate implementation in Passwords in Google Chrome prior to 150.0.787… | |
| CVE-2026-14011 | 8.1 | 16.1 | Chrome | CWE-125 | Out of bounds read in SurfaceCapture in Google Chrome prior to 150.0.7871.47 … | |
| CVE-2026-56777 | 5.3 | 16.0 | n8n | n8n | CWE-184 | n8n - AST Validator Bypass in Python Code Node |
| CVE-2026-58165 | 8.7 | 15.8 | openziti | ziti | CWE-862 | OpenZiti - Privilege Escalation to Admin via Unauthorized Enrollment Creation |
| CVE-2026-14093 | 9.6 | 15.7 | Chrome | CWE-416 | Use after free in Cast in Google Chrome prior to 150.0.7871.47 allowed a remo… | |
| CVE-2026-14095 | 9.6 | 15.7 | Chrome | CWE-20 | Insufficient policy enforcement in Browser in Google Chrome prior to 150.0.78… | |
| CVE-2026-14097 | 9.6 | 15.7 | Chrome | CWE-693 | Inappropriate implementation in WebAppInstalls in Google Chrome on Mac prior … | |
| CVE-2026-14005 | 8.8 | 15.7 | Chrome | CWE-416 | Use after free in Omnibox in Google Chrome on Android prior to 150.0.7871.47 … | |
| CVE-2026-13940 | 6.5 | 15.7 | Chrome | CWE-457 | Uninitialized Use in Cast in Google Chrome prior to 150.0.7871.47 allowed an … | |
| CVE-2026-14056 | 9.6 | 15.6 | Chrome | CWE-20 | Insufficient validation of untrusted input in Media in Google Chrome prior to… | |
| CVE-2026-14084 | 8.8 | 15.6 | Chrome | CWE-20 | Insufficient validation of untrusted input in Chromoting in Google Chrome pri… | |
| CVE-2026-14115 | 7.5 | 15.6 | Chrome | CWE-20 | Insufficient validation of untrusted input in Cast in Google Chrome prior to … | |
| CVE-2026-9836 | 7.5 | 15.4 | IBM | InfoSphere Information Server | CWE-200 | IBM DataStage Flow Designer application is affected by an information disclos… |
| CVE-2025-36321 | 5.7 | 15.5 | IBM | watsonx.data intelligence | CWE-80 | Vulnerabilities found in Watson Data Intelligence |
| CVE-2026-14062 | 5.9 | 15.3 | Chrome | CWE-200 | Inappropriate implementation in Views in Google Chrome on ChromeOS prior to 1… | |
| CVE-2026-53432 | 5.6 | 15.4 | fzf | fzf | CWE-190 | Integer Overflow in fzf |
| CVE-2026-12560 | 4.4 | 15.3 | wpqode | Editorial Rating – Product Review & Rating System | CWE-79 | Editorial Rating <= 4.0.5 - Authenticated (Administrator+) Stored Cross-Site … |
| CVE-2026-14122 | 8.1 | 15.2 | Chrome | CWE-20 | Insufficient validation of untrusted input in WebAppInstalls in Google Chrome… | |
| CVE-2026-12349 | 5.3 | 15.3 | octagonwebstudio | Premium Addons for KingComposer | CWE-862 | Premium Addons for KingComposer <= 1.1.1 - Missing Authorization to Unauthent… |
| CVE-2026-58167 | 7.1 | 15.1 | ccfos | nightingale | CWE-862 | Nightingale < 9.0.0-beta.2 - Datasource Credential Disclosure to Low-Privileg… |
| CVE-2026-14069 | 6.5 | 15.0 | Chrome | CWE-472 | Integer overflow in WebNN in Google Chrome prior to 150.0.7871.47 allowed a r… | |
| CVE-2026-14071 | 6.5 | 15.0 | Chrome | CWE-1300 | Side-channel information leakage in WebAudio in Google Chrome prior to 150.0.… | |
| CVE-2026-14098 | 6.5 | 15.0 | Chrome | CWE-200 | Inappropriate implementation in CSS in Google Chrome prior to 150.0.7871.47 a… | |
| CVE-2026-14100 | 6.5 | 15.0 | Chrome | CWE-20 | Insufficient data validation in NetworkCache in Google Chrome prior to 150.0.… | |
| CVE-2026-14058 | 4.3 | 15.0 | Chrome | CWE-693 | Insufficient policy enforcement in Parser in Google Chrome prior to 150.0.787… | |
| CVE-2026-13973 | 4.2 | 15.0 | Chrome | CWE-451 | Inappropriate implementation in UI in Google Chrome prior to 150.0.7871.47 al… | |
| CVE-2026-10513 | 7.2 | 14.9 | pfefferle | Webmention | CWE-79 | Webmention <= 5.8.0 - Unauthenticated Stored Cross-Site Scripting via MF2 'ph… |
| CVE-2026-54673 | 8.2 | 14.6 | electron-userland | electron-builder | CWE-200 | electron-updater: Cross-origin redirect leaks `PRIVATE-TOKEN` and mixed-case … |
| CVE-2026-58448 | 7.1 | 14.7 | YunaiV | yudao-cloud | CWE-862 | yudao-cloud < 2026.06 - BPM Module Broken Access Control via process-instance… |
| CVE-2026-14101 | 9.6 | 14.5 | Chrome | CWE-269 | Insufficient policy enforcement in Sandbox in Google Chrome on Mac prior to 1… | |
| CVE-2026-12085 | 6.5 | 14.5 | IBM | UCD - IBM UrbanCode Deploy | CWE-201 | IBM DevOps Deploy / IBM UrbanCode Deploy (UCD) is susceptable to an Insertion… |
| CVE-2026-56333 | 5.3 | 14.6 | Capgo | Capgo | CWE-20 | Capgo - Server-Side Validation Bypass via Direct Browser-Side Organization Se… |
| CVE-2026-9576 | 4.9 | 14.6 | Unknown | Fluent Booking | — | Fluent Booking < 2.1.2 - Calendar Manager+ Sensitive Information Disclosure v… |
| CVE-2026-14066 | 4.3 | 14.6 | Chrome | CWE-20 | Insufficient validation of untrusted input in Chrome for iOS in Google Chrome… | |
| CVE-2026-12388 | 6.5 | 14.4 | Red Hat | Red Hat Build of Keycloak | CWE-266 | Keycloak-broker: keycloak: privilege escalation to realm administrator via im… |
| CVE-2026-14117 | 5.3 | 14.4 | Chrome | CWE-20 | Insufficient validation of untrusted input in DevTools in Google Chrome on Wi… | |
| CVE-2026-14034 | 4.3 | 14.4 | Chrome | CWE-284 | Inappropriate implementation in WebXR in Google Chrome on Android prior to 15… | |
| CVE-2026-13449 | 9.1 | 14.3 | IBM | Business Automation Manager Open Editions | CWE-611 | XXE attack in IBM Business Automation Manager Open Editions |
| CVE-2026-44949 | 7.0 | 14.3 | SUSE | Rancher | CWE-306 | Unauthenticated namespace creation and RBAC injection via rancher-webhook Fle… |
| CVE-2026-13978 | 4.3 | 14.1 | Chrome | CWE-451 | Insufficient policy enforcement in PageInfo in Google Chrome prior to 150.0.7… | |
| CVE-2026-13979 | 4.3 | 14.1 | Chrome | CWE-451 | Inappropriate implementation in Paint in Google Chrome prior to 150.0.7871.47… | |
| CVE-2026-14152 | 9.6 | 14.0 | Chrome | CWE-787 | Out of bounds read and write in ANGLE in Google Chrome prior to 150.0.7871.47… | |
| CVE-2026-13980 | 4.3 | 14.1 | Chrome | CWE-451 | Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior … | |
| CVE-2026-13981 | 4.3 | 14.1 | Chrome | CWE-451 | Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior … | |
| CVE-2026-14052 | 4.3 | 14.0 | Chrome | CWE-284 | Insufficient policy enforcement in FileSystem in Google Chrome prior to 150.0… | |
| CVE-2026-44947 | 6.9 | 13.9 | SUSE | Rancher | CWE-281 | Stale PSA ClusterRoleBinding Persists After RoleTemplate Downgrade in Rancher |
| CVE-2026-14035 | 6.5 | 13.9 | Chrome | CWE-284 | Insufficient policy enforcement in Bluetooth in Google Chrome prior to 150.0.… | |
| CVE-2026-14061 | 6.5 | 13.9 | Chrome | CWE-284 | Inappropriate implementation in Dawn in Google Chrome prior to 150.0.7871.47 … | |
| CVE-2026-14096 | 6.5 | 13.9 | Chrome | CWE-200 | Inappropriate implementation in Input in Google Chrome on Android prior to 15… | |
| CVE-2026-56369 | 6.3 | 13.9 | ImageMagick | ImageMagick | CWE-323 | ImageMagick - Information Disclosure via AES-CTR Nonce Reuse in PasskeyEnciph… |
| CVE-2026-14054 | 4.3 | 13.9 | Chrome | CWE-602 | Insufficient policy enforcement in Network in Google Chrome prior to 150.0.78… | |
| CVE-2026-10140 | 9.6 | 13.8 | IBM | Langflow OSS | CWE-639 | Cross-Tenant API Key Reuse and Billing Fraud in Langflow Voice Mode Subsystem |
| CVE-2026-14014 | 6.5 | 13.6 | Chrome | CWE-451 | Inappropriate implementation in Paint in Google Chrome prior to 150.0.7871.47… | |
| CVE-2026-14112 | 5.3 | 13.6 | Chrome | CWE-203 | Inappropriate implementation in Enterprise in Google Chrome prior to 150.0.78… | |
| CVE-2026-58447 | 7.1 | 13.4 | iv-org | Invidious | CWE-639 | Invidious - Cross-User Playlist Video Deletion via Missing Ownership Check |
| CVE-2026-11546 | 9.8 | 13.1 | IBM | WebSphere Application Server - Liberty | CWE-918 | IBM WebSphere Application Server Liberty is affected by a server-side request… |
| CVE-2026-56320 | 7.1 | 13.0 | Capgo | Capgo | CWE-285 | Capgo - Org/App Scope Mismatch in Device Creation Endpoint |
| CVE-2026-27955 | 6.6 | 13.0 | coollabsio | coolify | CWE-78 | Coolify: Command Injection via Single-Quote Breakout in `executeInDocker()` |
| CVE-2026-28322 | 5.6 | 13.0 | SolarWinds | Database Performance Analyzer | CWE-20 | SolarWinds Database Performance Analyzer Stored Cross-Site Scripting Vulnerab… |
| CVE-2026-13995 | 4.3 | 12.9 | Chrome | CWE-20 | Insufficient validation of untrusted input in Autofill in Google Chrome on An… | |
| CVE-2026-14209 | 4.3 | 13.0 | Red Hat | Red Hat build of Keycloak 26.4 | CWE-639 | Keycloak-admin-ui: keycloak-admin-ui:admin ui extension brute-force-user endp… |
| CVE-2026-58376 | 7.2 | 12.9 | Dolibarr | dolibarr | CWE-89 | Dolibarr - SQL Injection via sqlfilters Parameter in Multiple REST API List E… |
| CVE-2026-14148 | 6.5 | 12.8 | Chrome | CWE-843 | Type Confusion in CSS in Google Chrome prior to 150.0.7871.47 allowed a remot… | |
| CVE-2026-13808 | 4.6 | 12.9 | Chrome | CWE-20 | Insufficient data validation in Chrome for iOS in Google Chrome on iOS prior … | |
| CVE-2026-14151 | 8.3 | 12.8 | Chrome | CWE-669 | Inappropriate implementation in AI in Google Chrome prior to 150.0.7871.47 al… | |
| CVE-2026-13996 | 6.5 | 12.6 | Chrome | CWE-451 | Inappropriate implementation in Permissions in Google Chrome prior to 150.0.7… | |
| CVE-2026-14002 | 6.5 | 12.6 | Chrome | CWE-451 | Inappropriate implementation in Geolocation in Google Chrome prior to 150.0.7… | |
| CVE-2025-36328 | 4.3 | 12.7 | IBM | watsonx.data intelligence | CWE-209 | Error Message Containing Sensitive Information found in Watson Data Intelligence |
| CVE-2026-14040 | 8.8 | 12.5 | Chrome | CWE-416 | Use after free in BrowserTag in Google Chrome prior to 150.0.7871.47 allowed … | |
| CVE-2026-13988 | 6.5 | 12.6 | Chrome | CWE-451 | Inappropriate implementation in Paint in Google Chrome prior to 150.0.7871.47… | |
| CVE-2026-14082 | 6.5 | 12.5 | Chrome | CWE-362 | Race in Storage in Google Chrome prior to 150.0.7871.47 allowed a remote atta… | |
| CVE-2026-14049 | 5.3 | 11.9 | Chrome | CWE-200 | Inappropriate implementation in GPU in Google Chrome prior to 150.0.7871.47 a… | |
| CVE-2026-27883 | 5.0 | 11.9 | coollabsio | coolify | CWE-639 | Coolify: IDOR in Deployment API - Cross-Team Deployment Information Disclosure |
| CVE-2026-53433 | 5.7 | 11.8 | fzf | fzf | CWE-407 | Denial of Service in fzf |
| CVE-2026-12114 | 4.4 | 11.8 | wpmart | Team Members – Multi Language Supported Team Plugin | CWE-79 | Team Members <= 8.7 - Authenticated (Administrator+) Stored Cross-Site Script… |
| CVE-2026-14155 | 6.5 | 11.6 | Chrome | CWE-284 | Insufficient policy enforcement in StorageAccessAPI in Google Chrome prior to… | |
| CVE-2026-58371 | 2.3 | 11.4 | seaweedfs | seaweedfs | CWE-79 | SeaweedFS < 4.30 - Cross-Origin Information Disclosure via Unvalidated JSONP … |
| CVE-2025-36327 | 6.5 | 11.4 | IBM | watsonx.data intelligence | CWE-602 | Vulnerabilities found in Watson Data Intelligence |
| CVE-2026-9106 | 4.8 | 11.2 | GitHub | Enterprise Server | CWE-451 | UI misrepresentation vulnerability in GitHub Enterprise Server allowed unauth… |
| CVE-2026-11714 | 9.8 | 11.1 | IBM | WebSphere Application Server - Liberty | CWE-918 | IBM WebSphere Application Server Liberty is affected by an authorization bypa… |
| CVE-2026-57204 | 6.9 | 11.0 | py-pdf | pypdf | CWE-400 | pypdf: Missing stream length values ignore defined limits |
| CVE-2026-14116 | 4.3 | 10.9 | Chrome | CWE-20 | Insufficient validation of untrusted input in DevTools in Google Chrome prior… | |
| CVE-2026-14015 | 6.5 | 10.8 | Chrome | CWE-362 | Race in WebRTC in Google Chrome on Windows prior to 150.0.7871.47 allowed a r… | |
| CVE-2026-14012 | 5.3 | 10.8 | Chrome | CWE-1300 | Side-channel information leakage in CSS in Google Chrome prior to 150.0.7871.… | |
| CVE-2026-13986 | 4.2 | 10.8 | Chrome | CWE-451 | Inappropriate implementation in Media UI in Google Chrome on ChromeOS prior t… | |
| CVE-2026-13982 | 3.1 | 10.8 | Chrome | CWE-451 | Incorrect security UI in Passwords in Google Chrome prior to 150.0.7871.47 al… | |
| CVE-2026-13989 | 5.3 | 10.7 | Chrome | CWE-451 | Inappropriate implementation in PageInfo in Google Chrome prior to 150.0.7871… | |
| CVE-2025-36372 | 6.5 | 10.6 | IBM | Db2 | CWE-538 | IBM® Db2® could disclose sensitive information to an authenticated user from … |
| CVE-2026-14127 | 4.3 | 10.5 | Chrome | CWE-20 | Inappropriate implementation in Printing in Google Chrome prior to 150.0.7871… | |
| CVE-2026-14130 | 4.3 | 10.5 | Chrome | CWE-20 | Incorrect security UI in Omnibox in Google Chrome prior to 150.0.7871.47 allo… | |
| CVE-2026-14140 | 4.3 | 10.5 | Chrome | CWE-20 | Insufficient validation of untrusted input in Input in Google Chrome on Andro… | |
| CVE-2026-14141 | 4.3 | 10.5 | Chrome | CWE-451 | Incorrect security UI in Document Picture-in-Picture in Google Chrome on Andr… | |
| CVE-2025-24816 | 6.5 | 10.3 | Nokia | MantaRay NM | CWE-284 | An Improper Access Control vulnerability in Nokia MantaRay NM |
| CVE-2026-13929 | 5.5 | 10.3 | Chrome | CWE-20 | Insufficient policy enforcement in DevTools in Google Chrome on Android prior… | |
| CVE-2026-14045 | 4.3 | 10.3 | Chrome | CWE-20 | Insufficient validation of untrusted input in Network in Google Chrome prior … | |
| CVE-2026-14156 | 6.5 | 10.2 | Chrome | CWE-862 | Insufficient policy enforcement in StorageAccessAPI in Google Chrome prior to… | |
| CVE-2026-58373 | 5.3 | 10.2 | cvat-ai | cvat | CWE-862 | CVAT < 2.69.0 - Missing Authorization on Quality Reports parent_id Filter Lea… |
| CVE-2026-14075 | 4.3 | 10.2 | Chrome | CWE-602 | Insufficient policy enforcement in Chrome for iOS in Google Chrome on iOS pri… | |
| CVE-2026-10564 | 8.2 | 10.1 | IBM | Langflow OSS | CWE-918 | SSRF Vulnerability in Langflow OSS Legacy Components Bypasses Protection |
| CVE-2026-14016 | 6.5 | 9.9 | Chrome | CWE-352 | Inappropriate implementation in SVG in Google Chrome prior to 150.0.7871.47 a… | |
| CVE-2026-54500 | 5.3 | 9.9 | ohler55 | oj | CWE-125 | Oj: intern.c form_attr has an uninitialized stack read |
| CVE-2026-14020 | 4.3 | 9.9 | Chrome | CWE-20 | Insufficient validation of untrusted input in WebXR in Google Chrome prior to… | |
| CVE-2026-14042 | 4.3 | 9.9 | Chrome | CWE-451 | Inappropriate implementation in Isolated Web Apps in Google Chrome prior to 1… | |
| CVE-2026-14072 | 4.3 | 9.9 | Chrome | CWE-451 | Inappropriate implementation in SplitView in Google Chrome prior to 150.0.787… | |
| CVE-2026-14089 | 4.3 | 9.9 | Chrome | CWE-20 | Insufficient validation of untrusted input in PopupBlocker in Google Chrome p… | |
| CVE-2026-13957 | 4.2 | 10.0 | Chrome | CWE-79 | Incorrect security UI in Extensions in Google Chrome prior to 150.0.7871.47 a… | |
| CVE-2026-10654 | 3.1 | 9.9 | zephyrproject | zephyr | CWE-362 | RFCOMM session-disconnect race leaks session/L2CAP and denies further RFCOMM … |
| CVE-2026-13822 | 6.5 | 9.5 | Chrome | CWE-346 | Inappropriate implementation in Extensions in Google Chrome on Android prior … | |
| CVE-2026-13990 | 6.5 | 9.4 | Chrome | CWE-20 | Insufficient validation of untrusted input in DataTransfer in Google Chrome o… | |
| CVE-2026-56224 | 5.1 | 9.4 | Capgo | Capgo | CWE-384 | Capgo - Login CSRF and Session Fixation via URL Query Parameters |
| CVE-2026-14110 | 4.3 | 9.5 | Chrome | CWE-1021 | Inappropriate implementation in DarkMode in Google Chrome prior to 150.0.7871… | |
| CVE-2026-48192 | 6.8 | 9.4 | Siemens | Mendix Studio Pro 10.11 | CWE-94 | A vulnerability has been identified in Mendix Studio Pro 10.11 (All versions)… |
| CVE-2025-36359 | 6.5 | 9.3 | IBM | DevOps Automation | CWE-613 | IBM DevOps Loop is susceptible to an Insufficient Session Expiration vulnerab… |
| CVE-2026-13945 | 3.1 | 9.3 | Chrome | CWE-451 | Insufficient policy enforcement in Extensions in Google Chrome on Linux prior… | |
| CVE-2026-13948 | 3.1 | 9.3 | Chrome | CWE-451 | Insufficient policy enforcement in Extensions in Google Chrome prior to 150.0… | |
| CVE-2026-56334 | 5.3 | 9.2 | Capgo | Capgo | CWE-284 | Capgo - Missing UPDATE RLS Policy for Build Status Persistence |
| CVE-2026-14013 | 4.3 | 9.0 | Chrome | CWE-451 | Inappropriate implementation in SVG in Google Chrome prior to 150.0.7871.47 a… | |
| CVE-2026-13992 | 4.2 | 9.1 | Chrome | CWE-451 | Inappropriate implementation in UI in Google Chrome on Mac prior to 150.0.787… | |
| CVE-2026-8141 | 7.2 | 9.0 | Connekt Media | Ajax Load More - Filters | CWE-79 | Ajax Load More - Filters <= 3.4.1 - Unauthenticated Stored Cross-Site Scripti… |
| CVE-2026-14068 | 6.1 | 8.9 | Chrome | CWE-79 | Inappropriate implementation in Omnibox in Google Chrome on iOS prior to 150.… | |
| CVE-2026-14083 | 6.1 | 8.9 | Chrome | CWE-20 | Insufficient validation of untrusted input in HTML in Google Chrome prior to … | |
| CVE-2026-14073 | 4.3 | 8.8 | Chrome | CWE-20 | Insufficient validation of untrusted input in WebXR in Google Chrome prior to… | |
| CVE-2026-14076 | 4.3 | 8.8 | Chrome | CWE-693 | Insufficient policy enforcement in Network in Google Chrome prior to 150.0.78… | |
| CVE-2026-14057 | 4.3 | 8.8 | Chrome | CWE-346 | Inappropriate implementation in FedCM in Google Chrome prior to 150.0.7871.47… | |
| CVE-2026-14079 | 4.3 | 8.8 | Chrome | CWE-346 | Insufficient policy enforcement in Network in Google Chrome prior to 150.0.78… | |
| CVE-2026-14080 | 4.3 | 8.8 | Chrome | CWE-20 | Insufficient validation of untrusted input in TabSwitcher in Google Chrome on… | |
| CVE-2026-56809 | 5.1 | 8.6 | Ricoh Company, Ltd. | Multiple laser printers and MFPs which implement Ricoh Web Image Monitor | CWE-79 | Multiple laser printers and MFPs (multifunction printers) which implement Ric… |
| CVE-2026-13942 | 3.3 | 8.6 | Chrome | CWE-20 | Inappropriate implementation in Video Capture in Google Chrome on ChromeOS pr… | |
| CVE-2026-13800 | 7.8 | 8.5 | Chrome | CWE-284 | Inappropriate implementation in Updater in Google Chrome on Windows prior to … | |
| CVE-2026-10129 | 8.5 | 8.4 | IBM | Langflow OSS | CWE-918 | SSRF via HTTP Redirect Following in Langflow API Request Component |
| CVE-2026-13863 | 7.8 | 8.4 | Chrome | CWE-20 | Insufficient validation of untrusted input in CustomTabs in Google Chrome on … | |
| CVE-2026-13927 | 7.8 | 8.4 | Chrome | CWE-20 | Insufficient validation of untrusted input in UI in Google Chrome on Android … | |
| CVE-2026-3602 | 5.5 | 8.4 | IBM | App Connect Enterprise | CWE-89 | IBM App Connect Enterprise and IBM Integration Bus for z/OS toolkit is vulner… |
| CVE-2026-10585 | 6.3 | 8.2 | GitHub | Enterprise Server | CWE-79 | Stored cross-site scripting vulnerability in GitHub Enterprise Server allowed… |
| CVE-2026-13778 | 7.8 | 8.1 | Chrome | CWE-416 | Use after free in WebUSB in Google Chrome on Mac prior to 150.0.7871.47 allow… | |
| CVE-2026-13984 | 4.3 | 8.2 | Chrome | CWE-290 | Incorrect security UI in TabStrip in Google Chrome prior to 150.0.7871.47 all… | |
| CVE-2026-13987 | 4.3 | 8.2 | Chrome | CWE-451 | Incorrect security UI in Mobile in Google Chrome on Android prior to 150.0.78… | |
| CVE-2026-13994 | 4.3 | 8.2 | Chrome | CWE-451 | Inappropriate implementation in Credential Management in Google Chrome on And… | |
| CVE-2026-14126 | 4.3 | 8.2 | Chrome | CWE-451 | Incorrect security UI in UI in Google Chrome on Android prior to 150.0.7871.4… | |
| CVE-2026-14134 | 4.3 | 8.2 | Chrome | CWE-451 | Inappropriate implementation in Autofill in Google Chrome on Android prior to… | |
| CVE-2026-14047 | 4.3 | 8.0 | Chrome | CWE-602 | Insufficient policy enforcement in Extensions in Google Chrome prior to 150.0… | |
| CVE-2026-14081 | 6.5 | 8.0 | Chrome | CWE-602 | Insufficient policy enforcement in DevTools in Google Chrome prior to 150.0.7… | |
| CVE-2026-13914 | 5.5 | 7.9 | Chrome | CWE-284 | Inappropriate implementation in Passwords in Google Chrome on Mac prior to 15… | |
| CVE-2026-14153 | 5.3 | 8.0 | Chrome | CWE-451 | Inappropriate implementation in Glic in Google Chrome prior to 150.0.7871.47 … | |
| CVE-2026-14046 | 4.3 | 7.9 | Chrome | CWE-346 | Inappropriate implementation in CustomTabs in Google Chrome on Android prior … | |
| CVE-2026-13976 | 5.8 | 7.8 | Chrome | CWE-122 | Insufficient data validation in Storage in Google Chrome prior to 150.0.7871.… | |
| CVE-2026-14131 | 5.4 | 7.9 | Chrome | CWE-20 | Insufficient validation of untrusted input in WebAppInstalls in Google Chrome… | |
| CVE-2026-14132 | 5.4 | 7.8 | Chrome | CWE-451 | Inappropriate implementation in WebXR in Google Chrome prior to 150.0.7871.47… | |
| CVE-2026-14123 | 4.3 | 7.8 | Chrome | CWE-451 | Incorrect security UI in Chrome for iOS in Google Chrome on iOS prior to 150.… | |
| CVE-2026-14128 | 4.3 | 7.8 | Chrome | CWE-451 | Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior … | |
| CVE-2026-14136 | 4.3 | 7.7 | Chrome | CWE-451 | Insufficient validation of untrusted input in Chrome for iOS in Google Chrome… | |
| CVE-2026-14143 | 4.3 | 7.8 | Chrome | CWE-451 | Incorrect security UI in Passwords in Google Chrome on iOS prior to 150.0.787… | |
| CVE-2026-14137 | 4.2 | 7.7 | Chrome | CWE-20 | Insufficient validation of untrusted input in Chrome for iOS in Google Chrome… | |
| CVE-2026-56356 | 5.1 | 7.5 | n8n | n8n | CWE-79 | n8n - Stored Cross-Site Scripting in Chat Trigger Node Custom CSS Field |
| CVE-2026-58450 | 5.3 | 7.4 | invoiceninja | invoiceninja | CWE-601 | Invoice Ninja 5.13.26 - Open Redirect in Client Portal Login via intended Par… |
| CVE-2026-13999 | 4.3 | 7.4 | Chrome | CWE-20 | Insufficient validation of untrusted input in Extensions in Google Chrome pri… | |
| CVE-2026-27956 | 4.3 | 7.4 | coollabsio | coolify | CWE-639 | Coolify: Cross-team application domain enumeration via domains_by_server endp… |
| CVE-2026-57082 | 5.9 | 7.3 | SANKO | Net::BitTorrent | CWE-330 | Net::BitTorrent versions before 2.1.0 for Perl generate the MSE Diffie-Hellma… |
| CVE-2026-14031 | 4.3 | 7.3 | Chrome | CWE-451 | Inappropriate implementation in File Input in Google Chrome prior to 150.0.78… | |
| CVE-2026-14077 | 4.3 | 7.3 | Chrome | CWE-451 | Inappropriate implementation in Select in Google Chrome on Mac prior to 150.0… | |
| CVE-2026-11594 | 6.1 | 7.0 | IBM | WebSphere Application Server | CWE-79 | IBM WebSphere Application Server is affected by multiple cross-site scripting… |
| CVE-2026-14135 | 5.4 | 7.0 | Chrome | CWE-20 | Insufficient validation of untrusted input in Network in Google Chrome prior … | |
| CVE-2026-14142 | 5.4 | 7.1 | Chrome | CWE-1021 | Inappropriate implementation in Extensions in Google Chrome prior to 150.0.78… | |
| CVE-2026-14105 | 4.3 | 7.1 | Chrome | CWE-346 | Insufficient policy enforcement in Speech in Google Chrome prior to 150.0.787… | |
| CVE-2026-14114 | 7.5 | 6.9 | Chrome | CWE-451 | Inappropriate implementation in WebAppInstalls in Google Chrome on Android pr… | |
| CVE-2026-13977 | 5.4 | 6.9 | Chrome | CWE-79 | Inappropriate implementation in HTMLParser in Google Chrome prior to 150.0.78… | |
| CVE-2026-14000 | 6.1 | 6.9 | Chrome | CWE-79 | Inappropriate implementation in XML in Google Chrome prior to 150.0.7871.47 a… | |
| CVE-2026-14001 | 6.1 | 6.9 | Chrome | CWE-79 | Inappropriate implementation in Network in Google Chrome prior to 150.0.7871.… | |
| CVE-2026-14053 | 4.3 | 6.8 | Chrome | CWE-346 | Insufficient policy enforcement in Extensions in Google Chrome prior to 150.0… | |
| CVE-2026-13955 | 3.3 | 6.8 | Chrome | CWE-20 | Insufficient validation of untrusted input in CustomTabs in Google Chrome on … | |
| CVE-2025-36333 | 4.3 | 6.7 | IBM | watsonx.data intelligence | CWE-841 | Vulnerabilities found in Watson Data Intelligence |
| CVE-2026-13991 | 4.3 | 6.6 | Chrome | CWE-20 | Insufficient validation of untrusted input in Chrome for iOS in Google Chrome… | |
| CVE-2026-56364 | 1.8 | 6.7 | ImageMagick | ImageMagick | CWE-401 | ImageMagick - Memory Leak in LoadOpenCLDeviceBenchmark() via Malformed XML |
| CVE-2026-7874 | 9.1 | 6.5 | IBM | Langflow OSS | CWE-338 | Weak Cryptographic Key Derivation Exposed All Stored Credentials |
| CVE-2026-9002 | 6.5 | 6.2 | IBM | WebSphere Extreme Scale | CWE-400 | IBM WebSphere eXtremes Scale is affected by uncontrolled resource consumption… |
| CVE-2026-56377 | 4.8 | 6.1 | ImageMagick | ImageMagick | CWE-22 | ImageMagick - Policy Bypass via Incorrect Path Validation |
| CVE-2026-14028 | 4.2 | 6.0 | Chrome | CWE-451 | Incorrect security UI in Chrome for iOS in Google Chrome on iOS prior to 150.… | |
| CVE-2026-14138 | 4.2 | 6.0 | Chrome | CWE-451 | Inappropriate implementation in WebAppInstalls in Google Chrome on Windows pr… | |
| CVE-2026-14139 | 4.2 | 6.0 | Chrome | CWE-451 | Inappropriate implementation in TabStrip in Google Chrome prior to 150.0.7871… | |
| CVE-2026-13849 | 8.6 | 5.9 | Chrome | CWE-20 | Insufficient validation of untrusted input in Chromoting in Google Chrome on … | |
| CVE-2026-13827 | 7.8 | 5.9 | Chrome | CWE-416 | Use after free in Updater in Google Chrome on Mac prior to 150.0.7871.47 allo… | |
| CVE-2026-13844 | 7.8 | 5.9 | Chrome | CWE-416 | Use after free in Updater in Google Chrome on Windows prior to 150.0.7871.47 … | |
| CVE-2026-12084 | 7.5 | 5.9 | IBM | UCD - IBM DevOps Deploy | CWE-942 | IBM DevOps Deploy / IBM UrbanCode Deploy (UCD) is susceptible to a Permissive… |
| CVE-2026-27881 | 5.0 | 5.8 | coollabsio | coolify | CWE-639 | Coolify: Cross-team deployment information disclosure via GET /api/v1/deploym… |
| CVE-2025-36324 | 4.3 | 5.9 | IBM | watsonx.data intelligence | CWE-918 | Vulnerabilities found in Watson Data Intelligence |
| CVE-2026-14039 | 4.3 | 5.8 | Chrome | CWE-346 | Insufficient policy enforcement in GetUserMedia in Google Chrome prior to 150… | |
| CVE-2026-14026 | 4.2 | 5.6 | Chrome | CWE-451 | Incorrect security UI in SplitView in Google Chrome prior to 150.0.7871.47 al… | |
| CVE-2026-14030 | 4.2 | 5.6 | Chrome | CWE-451 | Inappropriate implementation in SplitView in Google Chrome on Linux prior to … | |
| CVE-2025-36336 | 5.9 | 5.4 | IBM | watsonx.data intelligence | CWE-319 | Cleartext Transmission of Sensitive Information in Watson Data Intelligence |
| CVE-2026-13983 | 4.2 | 5.5 | Chrome | CWE-451 | Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior … | |
| CVE-2025-36320 | 6.4 | 5.3 | IBM | watsonx.data intelligence | CWE-79 | Vulnerabilities found in Watson Data Intelligence |
| CVE-2026-35096 | 5.1 | 5.3 | KTM System | e-BOK | CWE-352 | Cross-Site Request Forgery (CSRF) in KTM System e-BOK |
| CVE-2026-13905 | 4.2 | 5.4 | Chrome | CWE-362 | Race in Chrome for iOS in Google Chrome on iOS prior to 150.0.7871.47 allowed… | |
| CVE-2026-13993 | 4.2 | 5.1 | Chrome | CWE-451 | Incorrect security UI in WebAppInstalls in Google Chrome prior to 150.0.7871.… | |
| CVE-2026-13997 | 4.2 | 5.1 | Chrome | CWE-451 | Incorrect security UI in Extensions in Google Chrome on Android prior to 150.… | |
| CVE-2026-13998 | 4.2 | 5.0 | Chrome | CWE-451 | Incorrect security UI in File Input in Google Chrome on Mac prior to 150.0.78… | |
| CVE-2026-14129 | 4.2 | 5.1 | Chrome | CWE-451 | Inappropriate implementation in PreviewTab in Google Chrome on Android prior … | |
| CVE-2026-14150 | 5.4 | 4.9 | Chrome | CWE-20 | Insufficient validation of untrusted input in Speech in Google Chrome prior t… | |
| CVE-2026-58302 | 8.4 | 4.7 | LinuxCNC | LinuxCNC | CWE-22 | rtapi_app in linuxcnc-uspace in LinuxCNC before 2.9.9 allows privilege escala… |
| CVE-2026-8403 | 6.1 | 4.6 | Eksagate Electronic Engineering and Computer Industry Trade Inc. | SYSGUARD 6001 | CWE-79 | Stored XSS in Exagate's SYSGUARD 6001 |
| CVE-2026-14133 | 4.2 | 4.6 | Chrome | CWE-362 | Race in History Embeddings in Google Chrome prior to 150.0.7871.47 allowed a … | |
| CVE-2026-14145 | 6.1 | 4.5 | Chrome | CWE-79 | Inappropriate implementation in CSS in Google Chrome prior to 150.0.7871.47 a… | |
| CVE-2026-14003 | 4.3 | 4.5 | Chrome | CWE-284 | Insufficient policy enforcement in Extensions in Google Chrome prior to 150.0… | |
| CVE-2026-14092 | 4.3 | 4.5 | Chrome | CWE-693 | Insufficient policy enforcement in Privacy in Google Chrome prior to 150.0.78… | |
| CVE-2026-12578 | 8.4 | 4.4 | deltaww | DTMSoft | CWE-502 | DTMSoft - Deserialization of Untrusted Data Vulnerability |
| CVE-2026-10546 | 6.5 | 4.4 | IBM | Langflow OSS | CWE-918 | DNS Rebinding TOCTOU Bypass of SSRF Protection in Langflow OSS URL Component |
| CVE-2026-27882 | 4.8 | 4.4 | coollabsio | coolify | CWE-208 | Coolify: Timing Attack in GitLab Webhook Token Validation |
| CVE-2026-14147 | 6.1 | 4.3 | Chrome | CWE-79 | Inappropriate implementation in CSS in Google Chrome prior to 150.0.7871.47 a… | |
| CVE-2026-35095 | 4.8 | 4.3 | KTM System | e-BOK | CWE-384 | Session fixation in KTM System e-BOK |
| CVE-2026-50110 | 9.3 | 3.9 | StoneFly | Storage Concentrator | CWE-798 | Use of Hard-coded Credentials in StoneFly Storage Concentrator |
| CVE-2026-14063 | 5.7 | 3.9 | Chrome | CWE-125 | Out of bounds read in Chromecast in Google Chrome prior to 150.0.7871.47 allo… | |
| CVE-2026-11581 | 5.9 | 3.8 | Unknown | Kali Forms — Contact Form & Drag-and-Drop Builder | — | Kali Forms < 2.4.13 - Contributor+ Stored XSS via Form Field Caption |
| CVE-2026-56277 | 6.9 | 3.5 | Flowise | Flowise | CWE-346 | Flowise - Hardcoded CORS Wildcard in TTS Endpoint |
| CVE-2025-12530 | 5.9 | 3.5 | IBM | watsonx.data intelligence | CWE-319 | Vulnerabilities found in Watson Data Intelligence |
| CVE-2025-36323 | 5.4 | 3.5 | IBM | watsonx.data intelligence | CWE-79 | Vulnerabilities found in Watson Data Intelligence |
| CVE-2026-14144 | 4.2 | 3.5 | Chrome | CWE-451 | Incorrect security UI in Views in Google Chrome prior to 150.0.7871.47 allowe… | |
| CVE-2026-14154 | 4.8 | 3.0 | Chrome | CWE-451 | Inappropriate implementation in DevTools in Google Chrome prior to 150.0.7871… | |
| CVE-2026-14060 | 7.8 | 3.0 | Chrome | CWE-20 | Insufficient validation of untrusted input in Chromoting in Google Chrome on … | |
| CVE-2026-54672 | 7.8 | 3.0 | electron-userland | electron-builder | CWE-427 | electron-updater: Uncontrolled search path elements within `AppImage` built b… |
| CVE-2026-56361 | 4.8 | 2.9 | ImageMagick | ImageMagick | CWE-125 | ImageMagick - Heap Buffer Overflow via Off-by-One in Morphology Processing |
| CVE-2026-12610 | 6.4 | 2.3 | Red Hat | Red Hat Enterprise Linux 10 | CWE-825 | Sssd: use-after-free crash in sssd' 'sssd_pam' process |
| CVE-2026-14048 | 6.5 | 2.2 | Chrome | CWE-416 | Use after free in Chromecast in Google Chrome prior to 150.0.7871.47 allowed … | |
| CVE-2026-54896 | 2.1 | 2.1 | ohler55 | oj | CWE-122 | Oj: Heap Buffer Overflow in Oj.dump Exception Serialization via Large Indent |
| CVE-2026-13455 | 4.3 | 2.0 | DALIBO | PostgreSQL Anonymizer | CWE-328 | PostgreSQL Anonymizer: Unrestricted function can leak the secret salt |
| CVE-2026-54897 | 2.1 | 2.0 | ohler55 | oj | CWE-416 | Oj : Use-After-Free in Oj::Doc Iterators via Reentrant Close |
| CVE-2026-54898 | 2.1 | 2.0 | ohler55 | oj | CWE-416 | Oj: Use-After-Free in Oj::Parser SAJ Callback via Input Mutation |
| CVE-2026-14119 | 6.5 | 1.9 | Chrome | CWE-843 | Type Confusion in Bluetooth in Google Chrome on Windows prior to 150.0.7871.4… | |
| CVE-2026-56363 | 4.8 | 1.5 | ImageMagick | ImageMagick | CWE-190 | ImageMagick - Division by Zero in Binomial Kernel Processing |
| CVE-2025-24815 | 7.8 | 1.5 | Nokia | MantaRay NM | CWE-434 | An unrestricted file upload vulnerability in Nokia MantaRay NM |
| CVE-2026-14018 | 7.8 | 1.4 | Chrome | CWE-416 | Use after free in Updater in Google Chrome on Windows prior to 150.0.7871.47 … | |
| CVE-2026-8864 | 7.3 | 1.4 | HP Inc. | HP Fan Control App | CWE-428 | HP Fan Control App – Potential Escalation of Privilege |
| CVE-2026-13316 | 4.4 | 1.2 | Red Hat | Red Hat Satellite 6 | CWE-918 | Foreman: ssrf to cloud metada service through unvalidated test_url parameters… |
| CVE-2026-14124 | 7.8 | 1.1 | Chrome | CWE-269 | Inappropriate implementation in CredentialProvider in Google Chrome on Window… | |
| CVE-2026-8944 | 4.3 | 1.1 | engagementanalytics | Plugin for Google Analytics by IO technologies | CWE-352 | Plugin for Google Analytics by IO technologies <= 1.1 - Cross-Site Request Fo… |
| CVE-2026-12086 | 5.5 | 1.1 | IBM | UCD - IBM UrbanCode Deploy | CWE-532 | IBM DevOps Deploy / IBM UrbanCode Deploy (UCD) is susceptible to a Insertion … |
| CVE-2025-7406 | 7.8 | 0.7 | Nokia | MantaRay NM | CWE-269 | A Sudo Privilege Escalation Vulnerability in Nokia MantaRay NM |
| CVE-2026-14094 | 7.8 | 0.6 | Chrome | CWE-416 | Use after free in Installer in Google Chrome on Windows prior to 150.0.7871.4… | |
| CVE-2026-14160 | 5.9 | 0.5 | Samsung Open Source | Escargot | CWE-367 | Time-of-check time-of-use (TOCTOU) race condition vulnerability in Samsung Op… |
| CVE-2026-53692 | 5.9 | 0.3 | Redeight | Redeight CMS | CWE-328 | Weak hashing algorithm in Redeight CMS |