| CVE-2026-17758 | 9.6 | — | — | — | google / chrome | Heap buffer overflow in Dawn in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to potentially perf | 38d ago |
| CVE-2026-17749 | 9.6 | — | — | — | google / chrome | Insufficient validation of untrusted input in Extensions in Google Chrome prior to 151.0.7922.72 allowed an attack | 38d ago |
| CVE-2026-17738 | 9.6 | — | — | — | google / chrome | Insufficient validation of untrusted input in Payments in Google Chrome prior to 151.0.7922.72 allowed a remote at | 38d ago |
| CVE-2026-17727 | 9.6 | — | — | — | google / chrome | Out of bounds write in WebGL in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker to poten | 38d ago |
| CVE-2026-17726 | 9.6 | — | — | — | google / chrome | Integer overflow in WebGL in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker to potentia | 38d ago |
| CVE-2026-17721 | 9.6 | — | — | — | google / chrome | Out of bounds write in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to potentially perf | 38d ago |
| CVE-2026-17718 | 9.6 | — | — | — | google / chrome | Use after free in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to potentially perform a | 38d ago |
| CVE-2026-17717 | 9.6 | — | — | — | google / chrome | Integer overflow in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to potentially perform | 38d ago |
| CVE-2026-17713 | 9.6 | — | — | — | — | Insufficient validation of untrusted input in Accessibility in Google Chrome on Android prior to 151.0.7922.72 all | 38d ago |
| CVE-2026-17711 | 9.6 | — | — | — | google / chrome | Race in Downloads in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker who had compromised the | 38d ago |
| CVE-2026-17710 | 9.6 | — | — | — | google / chrome | Inappropriate implementation in MHTML in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker who | 38d ago |
| CVE-2026-17709 | 9.6 | — | — | — | google / chrome | Race in Downloads in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker who had compromised the | 38d ago |
| CVE-2026-17708 | 9.6 | — | — | — | google / chrome | Use after free in Audio in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the | 38d ago |
| CVE-2026-17704 | 9.6 | — | — | — | google / chrome | Use after free in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the | 38d ago |
| CVE-2026-17701 | 9.6 | — | — | — | — | Insufficient validation of untrusted input in ANGLE in Google Chrome on Mac prior to 151.0.7922.72 allowed a remot | 38d ago |
| CVE-2026-17697 | 9.6 | — | — | — | google / chrome | Type Confusion in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to potentially perform a | 38d ago |
| CVE-2026-17695 | 9.6 | — | — | — | google / chrome | Inappropriate implementation in ANGLE in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker to | 38d ago |
| CVE-2026-17692 | 9.6 | — | — | — | google / chrome | Use after free in DataTransfer in Google Chrome on Windows prior to 151.0.7922.72 allowed a remote attacker who ha | 38d ago |
| CVE-2026-17691 | 9.6 | — | — | — | google / chrome | Out of bounds write in ANGLE in Google Chrome on Windows prior to 151.0.7922.72 allowed a remote attacker to poten | 38d ago |
| CVE-2026-17688 | 9.6 | — | — | — | google / chrome | Use after free in Input in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the | 38d ago |
| CVE-2026-17687 | 9.6 | — | — | — | google / chrome | Type Confusion in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the | 38d ago |
| CVE-2026-17684 | 9.6 | — | — | — | google / chrome | Insufficient validation of untrusted input in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowe | 38d ago |
| CVE-2026-17682 | 9.6 | — | — | — | google / chrome | Integer overflow in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised th | 38d ago |
| CVE-2026-17681 | 9.6 | — | — | — | google / chrome | Insufficient validation of untrusted input in Web Authentication in Google Chrome on Android prior to 151.0.7922.7 | 38d ago |
| CVE-2026-17680 | 9.6 | — | — | — | google / chrome | Heap buffer overflow in Color in Google Chrome on ChromeOS prior to 151.0.7922.72 allowed a remote attacker who ha | 38d ago |
| CVE-2026-17676 | 9.6 | — | — | — | google / chrome | Inappropriate implementation in ANGLE in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker | 38d ago |
| CVE-2026-17675 | 9.6 | — | — | — | google / chrome | Out of bounds write in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised | 38d ago |
| CVE-2026-17673 | 9.6 | — | — | — | google / chrome | Integer overflow in QUIC in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the | 38d ago |
| CVE-2026-17672 | 9.6 | — | — | — | google / chrome | Insufficient validation of untrusted input in Chromecast in Google Chrome prior to 151.0.7922.72 allowed a remote | 38d ago |
| CVE-2026-17671 | 9.6 | — | — | — | google / chrome | Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attac | 38d ago |
| CVE-2026-17670 | 9.6 | — | — | — | google / chrome | Use after free in Views in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the | 38d ago |
| CVE-2026-17669 | 9.6 | — | — | — | google / chrome | Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote att | 38d ago |
| CVE-2026-17656 | 9.6 | — | — | — | google / chrome | Use after free in Ozone in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to potentially perform a | 38d ago |
| CVE-2026-17655 | 9.6 | — | — | — | google / chrome | Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attac | 38d ago |
| CVE-2026-17652 | 9.6 | — | — | — | google / chrome | Use after free in Views in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the | 38d ago |
| CVE-2026-17651 | 9.6 | — | — | — | google / chrome | Insufficient validation of untrusted input in Dawn in Google Chrome on Android prior to 151.0.7922.72 allowed a re | 38d ago |
| CVE-2026-66395 | 9.6 | — | — | — | — | SiYuan desktop before v3.7.2 contains a reflected cross-site scripting vulnerability in the bazaar plugin readme h | 40d ago |
| CVE-2026-65606 | 9.6 | — | — | — | — | SiYuan before v3.7.2 contains a cross-site scripting vulnerability in the siyuan:// protocol handler. | 45d ago |
| CVE-2026-65605 | 9.6 | — | — | — | — | SiYuan before v3.7.2 contains a stored cross-site scripting vulnerability in Attribute View (database) cell render | 45d ago |
| CVE-2026-65471 | 9.6 | — | — | — | — | Unauthenticated Cross Site Request Forgery (CSRF) in Avada Core <= 5.15.6 versions. | 45d ago |
| CVE-2026-57784 | 9.6 | — | — | — | — | Unauthenticated Cross Site Request Forgery (CSRF) in Ninja Forms File Uploads Extension <= 3.3.26 versions. | 45d ago |
| CVE-2026-16624 | 9.6 | — | — | — | — | Cal.com OSS ships lacks authorization on webhook teamId creation, allowing any authenticated user to create a webh | 45d ago |
| CVE-2026-16424 | 9.6 | — | — | — | google / chrome | Use after free in GPU in Google Chrome on Android prior to 150.0.7871.182 allowed a remote attacker who had compro | 46d ago |
| CVE-2026-16419 | 9.6 | — | — | — | google / chrome | Out of bounds read and write in ANGLE in Google Chrome on Android prior to 150.0.7871.182 allowed a remote attacke | 46d ago |
| CVE-2026-62549 | 9.6 | — | — | — | oracle / human resources management system | Vulnerability in the Oracle HRMS (UK) product of Oracle E-Business Suite (component: UK Payroll). | 46d ago |
| CVE-2026-61097 | 9.6 | — | — | — | oracle / banking trade finance process management | Vulnerability in the Oracle Banking Trade Finance Process Management product of Oracle Financial Services Applicat | 46d ago |
| CVE-2026-60773 | 9.6 | — | — | — | oracle / application object library | Vulnerability in the Oracle Application Object Library product of Oracle E-Business Suite (component: Core). | 46d ago |
| CVE-2026-60564 | 9.6 | — | — | — | oracle / webcenter portal | Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Runtime Tools). | 46d ago |
| CVE-2026-60540 | 9.6 | — | — | — | oracle / soa suite | Vulnerability in the Oracle SOA Suite product of Oracle Fusion Middleware (component: Integration Business Insight | 46d ago |
| CVE-2026-60239 | 9.6 | — | — | — | oracle / coherence | Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). | 46d ago |
| CVE-2026-16441 | 9.6 | — | — | — | eclipse / openj9 | In Eclipse OpenJ9 versions up to 0.60, when executing class files where a previously concrete superclass method ha | 46d ago |
| CVE-2026-47416 | 9.6 | — | — | — | — | PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. | 46d ago |
| CVE-2026-47413 | 9.6 | — | — | — | — | PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. | 46d ago |
| CVE-2026-65007 | 9.6 | — | — | — | — | The Grav api plugin (grav-plugin-api) before 1.0.8 fails to properly authorize API key generation and revocation: | 47d ago |
| CVE-2026-15901 | 9.6 | — | — | — | google / chrome | Use after free in Network in Google Chrome prior to 150.0.7871.128 allowed a remote attacker to potentially exploi | 47d ago |
| CVE-2026-15900 | 9.6 | — | — | — | google / chrome | Use after free in GPU in Google Chrome on Android prior to 150.0.7871.128 allowed a remote attacker to potentially | 47d ago |
| CVE-2026-15899 | 9.6 | — | — | — | google / chrome | Use after free in CameraCapture in Google Chrome on Mac prior to 150.0.7871.128 allowed a remote attacker to poten | 47d ago |
| CVE-2026-55518 | 9.6 | — | — | — | — | Avo is a framework to create admin panels for Ruby on Rails apps. | 50d ago |
| CVE-2026-22752 | 9.6 | — | — | — | broadcom / spring authorization server | Authentication bypass by primary weakness vulnerability in Spring Security Spring Authorization Server. | 52d ago |
| CVE-2026-54458 | 9.6 | — | — | — | — | WWBN AVideo is an open source video platform. | 52d ago |