Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
26848
Total
1978
Critical
8065
High
8299
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-8513 | HIGH | 8.3 | Use after free in Input in Google Chrome on Android prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to potentially … | May 14, 2026 |
| CVE-2026-8512 | HIGH | 8.3 | Use after free in FileSystem in Google Chrome prior to 148.0.7778.168 allowed a remote attacker who convinced a user to engage in specific UI gestures … | May 14, 2026 |
| CVE-2026-8511 | CRITICAL | 9.6 | Use after free in UI in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML … | May 14, 2026 |
| CVE-2026-8510 | HIGH | 7.5 | Integer overflow in Skia in Google Chrome on Windows prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to perform an … | May 14, 2026 |
| CVE-2026-8509 | HIGH | 8.8 | Heap buffer overflow in WebML in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted … | May 14, 2026 |
| CVE-2026-46356 | UNKNOWN | — | Fleet is open source device management software. Prior to version 4.80.1, a vulnerability in Fleet's IP extraction logic allows unauthenticated attackers to bypass API rate … | May 14, 2026 |
| CVE-2026-44638 | LOW | 2.5 | libsixel is a SIXEL encoder/decoder implementation derived from kmiya's sixel. From to 1.8.7-r1, a wrong NULL check after an allocation call in sixel_decode_raw and sixel_decode … | May 14, 2026 |
| CVE-2026-44637 | HIGH | 7.1 | libsixel is a SIXEL encoder/decoder implementation derived from kmiya's sixel. From to 1.8.7-r1, a signed integer overflow in the SIXEL parser's image-buffer doubling loop can … | May 14, 2026 |
| CVE-2026-44636 | HIGH | 7.4 | libsixel is a SIXEL encoder/decoder implementation derived from kmiya's sixel. From to 1.8.7-r1, signed integer overflow in sixel_encode_highcolor's allocation size calculation can lead to a … | May 14, 2026 |
| CVE-2026-43996 | MEDIUM | 5.5 | OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation. Prior to 3.0.18.0 and … | May 14, 2026 |
| CVE-2026-43909 | HIGH | 8.8 | OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation. Prior to 3.0.18.0 and … | May 14, 2026 |
| CVE-2026-43908 | HIGH | 8.8 | OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation. Prior to 3.0.18.0 and … | May 14, 2026 |
| CVE-2026-43907 | HIGH | 8.3 | OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation. Prior to 3.0.18.0 and … | May 14, 2026 |
| CVE-2026-43906 | UNKNOWN | — | OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation. Prior to 3.0.18.0 and … | May 14, 2026 |
| CVE-2026-43905 | UNKNOWN | — | OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation. Prior to 3.0.18.0 and … | May 14, 2026 |
| CVE-2026-43904 | UNKNOWN | — | OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation. Prior to 3.0.18.0 and … | May 14, 2026 |
| CVE-2026-43903 | UNKNOWN | — | OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation. Prior to 3.0.18.0 and … | May 14, 2026 |
| CVE-2026-3290 | UNKNOWN | — | Timing limitations of the HRNG in RS9116 when power save mode is enabled results in predictable values | May 14, 2026 |
| CVE-2026-26191 | UNKNOWN | — | Fleet is open source device management software. Prior to version 4.81.0, a vulnerability in Fleet's software installer pipeline could allow a crafted software package to … | May 14, 2026 |
| CVE-2026-26062 | UNKNOWN | — | Fleet is open source device management software. Prior to version 4.81.0, Fleet contained a denial-of-service (DoS) issue in the gRPC Launcher `PublishLogs` endpoint. In affected … | May 14, 2026 |
| CVE-2026-24899 | UNKNOWN | — | Fleet is open source device management software. Prior to version 4.82.0, a vulnerability in Fleet's Windows MDM enrollment flow allows authentication tokens from any Azure … | May 14, 2026 |
| CVE-2026-24000 | UNKNOWN | — | Fleet is open source device management software. Prior to version 4.80.1, Fleet trusted client-supplied IP address headers when determining the source IP for incoming requests. … | May 14, 2026 |
| CVE-2026-8621 | HIGH | 8.8 | Crabbox prior to v0.12.0 contains an authentication bypass vulnerability that allows non-admin shared-token callers to impersonate other owners or organizations by spoofing identity headers. Attackers … | May 14, 2026 |
| CVE-2026-45375 | CRITICAL | 9.0 | SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, SiYuan's Bazaar (community marketplace) renders the name and version fields of a package's plugin.json … | May 14, 2026 |
| CVE-2026-45371 | UNKNOWN | — | SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, SiYuan publish-mode Reader can mutate Conf and SQL index via 8 ungated APIs. POST … | May 14, 2026 |