Export limit exceeded: 403962 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (1286 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-17931 | 1 Google | 1 Chrome | 2026-07-30 | 6.5 Medium |
| Inappropriate implementation in DevTools in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Low) | ||||
| CVE-2026-17943 | 1 Google | 1 Chrome | 2026-07-30 | 4.3 Medium |
| Inappropriate implementation in Parser in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to bypass content security policy via a crafted HTML page. (Chromium security severity: Low) | ||||
| CVE-2026-17923 | 1 Google | 1 Chrome | 2026-07-30 | 6.5 Medium |
| Policy bypass in Enterprise in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to bypass navigation restrictions via a crafted domain name. (Chromium security severity: Low) | ||||
| CVE-2026-17936 | 1 Google | 1 Chrome | 2026-07-30 | 6.5 Medium |
| Inappropriate implementation in DevTools in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who convinced a user to engage in specific UI gestures to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Low) | ||||
| CVE-2026-17677 | 1 Google | 2 Android, Chrome | 2026-07-30 | 8.8 High |
| Inappropriate implementation in ANGLE in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) | ||||
| CVE-2026-17710 | 2 Apple, Google | 2 Macos, Chrome | 2026-07-30 | 9.6 Critical |
| Inappropriate implementation in MHTML in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) | ||||
| CVE-2026-17695 | 2 Apple, Google | 2 Macos, Chrome | 2026-07-30 | 9.6 Critical |
| Inappropriate implementation in ANGLE in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) | ||||
| CVE-2026-67427 | 1 Flytohub | 1 Flyto-core | 2026-07-30 | 8.6 High |
| Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.6, the workflow engine variable resolver expands ${env.VAR} for any host environment variable without an allowlist or capability policy check, allowing a workflow parameter to bypass the default capability policy denylist for env.get and env.load_dotenv and exfiltrate secrets through allowed modules. This issue is fixed in version 2.26.6. | ||||
| CVE-2026-44108 | 2 Phoenix Contact, Phoenixcontact | 8 Charx Sec 3000, Charx Sec 3050, Charx Sec 3100 and 5 more | 2026-07-30 | 9.8 Critical |
| Due to a flaw in the execution order of scripts during shutdown, the firewall is terminated prematurely during system shutdown. This creates a temporary window in which internal services may become externally accessible, potentially allowing an unauthenticated remote attacker to connect to these services, resulting in full system compromise. | ||||
| CVE-2026-17899 | 1 Google | 1 Chrome | 2026-07-30 | 8.8 High |
| Insufficient policy enforcement in DevTools in Google Chrome prior to 151.0.7922.72 allowed an attacker who convinced a user to install a malicious extension to perform privilege escalation via a crafted Chrome Extension. (Chromium security severity: Low) | ||||
| CVE-2026-17919 | 1 Google | 1 Chrome | 2026-07-30 | 6.8 Medium |
| Insufficient policy enforcement in Enterprise in Google Chrome on Mac prior to 151.0.7922.72 allowed a local attacker to perform privilege escalation via physical access to the device. (Chromium security severity: Low) | ||||
| CVE-2026-17659 | 1 Google | 1 Chrome | 2026-07-30 | 4.2 Medium |
| Inappropriate implementation in SiteIsolation in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: High) | ||||
| CVE-2026-46634 | 2 Symfony, Twigphp | 2 Twig, Twig | 2026-07-29 | 9.8 Critical |
| Twig is a template language for PHP. From 3.9.0 until 3.26.0, template_from_string() compiles an inner template under a synthesized __string_template__<hash> name that can fall outside a SourcePolicyInterface sandbox decision, allowing a sandboxed template that can call template_from_string and include to render an inner template without security policy enforcement. This issue is fixed in version 3.26.0. | ||||
| CVE-2026-67217 | 1 Davegamble | 1 Cjson | 2026-07-29 | 5.3 Medium |
| cJSON through 1.7.19 applies RFC 6902 JSON Patch operations non-atomically in apply_patch() in cJSON_Utils.c. For a replace operation that is missing its value member, or a move operation whose destination path cannot be resolved, the existing target member is detached and deleted before the operation is fully validated, so the target document is mutated while cJSONUtils_ApplyPatches() or cJSONUtils_ApplyPatchesCaseSensitive() returns a failure status. An attacker who can supply the patch document can destroy addressable members of the target document even though the API reports that the patch failed, defeating the all-or-nothing behavior callers rely on to reject bad patches. | ||||
| CVE-2026-14169 | 2 Ads-tec Industrial It, Ads Tec | 8 Dvg-irf1401, Dvg-irf1421, Dvg-irf3401 and 5 more | 2026-07-28 | 8.1 High |
| Due to incorrect behavior order a low privileged remote attacker could trigger account inconsistent state via crafted input and overwrites existing user passwords which could result in complete administrative unavailability of the device. | ||||
| CVE-2025-50327 | 1 Fcorbelli | 1 Zpaqfranz | 2026-07-28 | 8.8 High |
| An issue in Franco Corbelli ZPAQFRANZ v.61.3 and before allows a remote attacker to escalate privileges and execute arbitrary code via a bypass of the Mark-of-the-Web protection mechanism | ||||
| CVE-2026-56585 | 1 Hcltech | 1 Intelliops Event Management | 2026-07-27 | 3.1 Low |
| HCL IEM was affected with the Anti Clickjacking XFrame Options Header Missing. It may allow attackers to embed the application in malicious pages and induce unauthorized user actions. | ||||
| CVE-2026-66391 | 1 Apache | 1 Wicket | 2026-07-27 | 6.5 Medium |
| Use of Insufficiently Random Values, Protection Mechanism Failure vulnerability in Apache Wicket. This issue affects Apache Wicket: from 9.0.0 through 9.23.0, from 10.0.0 through 10.9.0. Users are recommended to upgrade to version 10.10.0, which fixes the issue. | ||||
| CVE-2026-48032 | 1 Kerberosmansour | 1 Hulumi | 2026-07-27 | N/A |
| Hulumi is an open-source toolkit that ships secure-by-default cloud and platform infrastructure components for Pulumi. Prior to version 1.4.0, IAM-role policy checks can be bypassed when the role trusts multiple OIDC providers. This issue has been patched in version 1.4.0. | ||||
| CVE-2026-65899 | 1 Cure53 | 1 Dompurify | 2026-07-27 | 6.1 Medium |
| DOMPurify 3.0.0 before 3.4.9 does not reset the retained Trusted Types policy when clearConfig() is called, so a DOMPurify instance reused across trust boundaries stays bound to a previously supplied TRUSTED_TYPES_POLICY. A later caller that requests RETURN_TRUSTED_TYPE output receives a TrustedHTML object created by the old (potentially unsafe) policy rather than a clean default, which can lead to script execution at a Trusted Types sink. Passing TRUSTED_TYPES_POLICY: null on the later call also does not clear the retained policy. | ||||