Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
26398
Total
1955
Critical
7975
High
8226
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-47373 | HIGH | 7.5 | Crypt::SaltedHash versions through 0.09 for Perl is susceptible to timing attacks. These versions use Perl's built-in eq comparison. Discrepencies in timing could be used to … | May 20, 2026 |
| CVE-2026-9144 | HIGH | 7.6 | Taiko AG1000-01A SMS Alert Gateway Rev 7.3 and Rev 8 contains a stored cross-site scripting vulnerability in the embedded web configuration interface that allows authenticated … | May 20, 2026 |
| CVE-2026-9141 | CRITICAL | 9.8 | Taiko AG1000-01A SMS Alert Gateway Rev 7.3 and Rev 8 contains an authentication bypass vulnerability in the embedded web configuration interface that allows unauthenticated attackers … | May 20, 2026 |
| CVE-2026-9139 | CRITICAL | 9.8 | Taiko AG1000-01A SMS Alert Gateway Rev 7.3 and Rev 8 contains a hard-coded credential vulnerability in the embedded web configuration interface where authentication is implemented … | May 20, 2026 |
| CVE-2026-9137 | UNKNOWN | — | The CSP report endpoint intended to limit logged CSP reports to 1 KB but incorrectly allowed reports up to 1 MB before truncation. On deployments … | May 20, 2026 |
| CVE-2026-9136 | UNKNOWN | — | A vulnerability was identified in the ShadowAttribute proposal creation workflow. The add action accepted user-controlled ShadowAttribute request data without removing the id field before saving … | May 20, 2026 |
| CVE-2026-9133 | HIGH | 7.7 | Active debug code exists in the ARN resolver of amazon-mq rabbitmq-aws before version 0.2.1. A debug ARN scheme (arn:aws-debug:file) accepted by the PUT /api/aws/arn/validate validation … | May 20, 2026 |
| CVE-2026-9129 | UNKNOWN | — | A path traversal vulnerability exists in the Altium Enterprise Server Viewer StorageController due to improper handling of file path route parameters. On on-premise deployments that … | May 20, 2026 |
| CVE-2026-9126 | HIGH | 8.8 | Use after free in DOM in Google Chrome on prior to 148.0.7778.179 allowed a remote attacker to execute arbitrary code inside a sandbox via a … | May 20, 2026 |
| CVE-2026-9124 | MEDIUM | 5.3 | Insufficient validation of untrusted input in Input in Google Chrome on prior to 148.0.7778.179 allowed a remote attacker who had compromised the renderer process to … | May 20, 2026 |
| CVE-2026-9123 | HIGH | 7.5 | Heap buffer overflow in Chromecast in Google Chrome on Android, Linux, ChromeOS prior to 148.0.7778.179 allowed a local attacker to execute arbitrary code inside a … | May 20, 2026 |
| CVE-2026-9122 | MEDIUM | 6.5 | Out of bounds read in GPU in Google Chrome on Mac prior to 148.0.7778.179 allowed a remote attacker to obtain potentially sensitive information from process … | May 20, 2026 |
| CVE-2026-9121 | HIGH | 8.8 | Out of bounds read in GPU in Google Chrome on prior to 148.0.7778.179 allowed a remote attacker to potentially exploit heap corruption via a crafted … | May 20, 2026 |
| CVE-2026-9120 | HIGH | 8.8 | Use after free in WebRTC in Google Chrome prior to 148.0.7778.179 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium … | May 20, 2026 |
| CVE-2026-9119 | HIGH | 8.8 | Heap buffer overflow in WebRTC in Google Chrome on prior to 148.0.7778.179 allowed a remote attacker to execute arbitrary code inside a sandbox via a … | May 20, 2026 |
| CVE-2026-9118 | HIGH | 8.8 | Use after free in XR in Google Chrome on Windows prior to 148.0.7778.179 allowed a remote attacker to execute arbitrary code via a crafted HTML … | May 20, 2026 |
| CVE-2026-9117 | HIGH | 7.5 | Type Confusion in GFX in Google Chrome on Linux, ChromeOS prior to 148.0.7778.179 allowed a remote attacker who had compromised the renderer process to potentially … | May 20, 2026 |
| CVE-2026-9116 | MEDIUM | 4.3 | Insufficient policy enforcement in ServiceWorker in Google Chrome on prior to 148.0.7778.179 allowed a remote attacker to leak cross-origin data via a crafted HTML page. … | May 20, 2026 |
| CVE-2026-9115 | MEDIUM | 4.3 | Insufficient policy enforcement in Service Worker in Google Chrome on prior to 148.0.7778.179 allowed a remote attacker to bypass same origin policy via a crafted … | May 20, 2026 |
| CVE-2026-9114 | HIGH | 8.8 | Use after free in QUIC in Google Chrome on prior to 148.0.7778.179 allowed a remote attacker to execute arbitrary code inside a sandbox via malicious … | May 20, 2026 |
| CVE-2026-9113 | MEDIUM | 4.3 | Out of bounds read in GPU in Google Chrome on Mac prior to 148.0.7778.179 allowed a remote attacker to perform an out of bounds memory … | May 20, 2026 |
| CVE-2026-9112 | HIGH | 8.8 | Use after free in GPU in Google Chrome on Windows prior to 148.0.7778.179 allowed a remote attacker to execute arbitrary code inside a sandbox via … | May 20, 2026 |
| CVE-2026-9111 | HIGH | 8.8 | Use after free in WebRTC in Google Chrome on Linux prior to 148.0.7778.179 allowed a remote attacker to execute arbitrary code via a crafted HTML … | May 20, 2026 |
| CVE-2026-9110 | MEDIUM | 4.2 | Inappropriate implementation in UI in Google Chrome on Windows prior to 148.0.7778.179 allowed a remote attacker who had compromised the renderer process to perform UI … | May 20, 2026 |
| CVE-2026-9102 | UNKNOWN | — | A path traversal vulnerability exists in the Altium Enterprise Server ComparisonService due to missing filename sanitization in the Gerber file upload APIs. A regular authenticated … | May 20, 2026 |