By weakness (CWE)

CWE-20: related vulnerabilities

CVEs classified under CWE-20. Understanding the weakness class helps prioritize systemic fixes over one-off patches.

358 published vulnerabilities · page 2 of 4

  • CVE-2026-11297HIGH 7.7

    A vulnerability in Google Chrome's Reader Mode on Android allows local attackers to bypass navigation restrictions by providing a specially crafted file. While the underlying input validation flaw is classified as low severity by Google's Chromium team, the CVSS scoring reflects the potential for high-impact integrity and availability consequences when successfully exploited. This is a local-only attack, meaning an attacker must already have some level of access to the device to deliver the malicious file.

  • CVE-2026-57985HIGH 7.6

    Microsoft Edge (Chromium-based) contains a flaw in how it validates user input, enabling attackers to execute arbitrary code on a victim's machine via the network. The attack requires user interaction—such as visiting a malicious website or opening a crafted file—but does not require any special privileges or authentication to succeed. This is a high-severity vulnerability that affects confidentiality, integrity, and system availability.

  • CVE-2026-10969HIGH 7.5

    A flaw in Google Chrome's extension validation system allows attackers to escalate privileges if they've already compromised Chrome's rendering engine. An attacker would need to trick a user into viewing a specially crafted webpage while the renderer process is already under their control, leading to unauthorized system-level access. This is a High-severity issue affecting Chrome versions before 149.0.7827.53.

  • CVE-2026-11149HIGH 7.5

    Google Chrome versions before 149.0.7827.53 contain a flaw in how Extensions are validated, allowing an attacker who has already compromised Chrome's rendering engine to bypass security boundaries and gain elevated privileges on the user's system. The attacker would need to trick a user into visiting a specially crafted webpage while the renderer process is already under attacker control. This vulnerability bridges a gap between renderer compromise and full system-level access, making it a serious escalation path in multi-stage attacks.

  • CVE-2026-11151HIGH 7.5

    Google Chrome's Password Manager component fails to properly validate user-supplied input before processing it. This gap allows an attacker who has already compromised Chrome's renderer process—the sandboxed part of the browser that runs web content—to escape the sandbox and gain deeper access to the system. The attacker would need to craft a malicious HTML page and convince a user to visit it, but once the renderer is compromised, the insufficient input validation becomes the bridge to break out of Chrome's security boundaries.

  • CVE-2026-11239HIGH 7.5

    Google Chrome versions before 149.0.7827.53 contain a flaw in how the browser handles extensions that could allow an attacker to escalate privileges if they've already compromised the renderer process—the sandboxed component responsible for running web pages and extensions. An attacker would need to trick a user into visiting a malicious webpage after the renderer is already compromised, but successful exploitation could grant them elevated system access.

  • CVE-2026-11242HIGH 7.5

    Google Chrome versions prior to 149.0.7827.53 contain a vulnerability in how the browser handles untrusted input within plugins. An attacker who has already compromised Chrome's renderer process can craft a malicious HTML page to steal sensitive data from websites the user has visited, potentially exposing information that should remain isolated between different web domains. This requires the renderer to be compromised first, making it a secondary attack in a chain, but the confidentiality risk is significant.

  • CVE-2026-11255HIGH 7.5

    A flaw in Google Chrome's Storage Access API fails to properly check user input, creating a security gap. If an attacker first compromises Chrome's renderer process—the part that runs web content—they could exploit this gap to steal data from websites you've visited, even across security boundaries that normally block such access. The issue affects Chrome versions before 149.0.7827.53, as well as the underlying operating systems on macOS, Linux, and Windows where Chrome runs.

  • CVE-2026-13794HIGH 7.5

    Google Chrome on Windows contains a flaw in its web app installation feature that fails to properly validate user-supplied input. An attacker can craft a malicious HTML page that, when visited by a user who performs specific interactions with Chrome's UI, triggers arbitrary code execution on the affected system. The vulnerability requires user interaction but grants complete control over the compromised machine.

  • CVE-2026-13824HIGH 7.5

    Google Chrome versions before 150.0.7871.47 contain a security flaw in how it enforces policies for browser extensions. An attacker who has already compromised Chrome's renderer process—the component that executes web content—can exploit insufficient policy checks to escalate their privileges and gain deeper control of the browser. The attack requires user interaction (such as visiting a malicious webpage) but bypasses normal security boundaries once the renderer is compromised.

  • CVE-2026-13856HIGH 7.5

    Google Chrome on Android contains a vulnerability in its Speech feature that could allow an attacker to gain elevated privileges on your device. The vulnerability requires two conditions: first, the attacker must have already compromised Chrome's rendering engine (the part that displays web content), and second, you must visit a malicious webpage. If both happen, the attacker could escalate from their limited renderer access to higher system privileges, potentially compromising your device more completely. Google has released Chrome version 150.0.7871.47 or later to fix this issue.

  • CVE-2026-13891HIGH 7.5

    Google Chrome versions before 150.0.7871.47 contain a vulnerability in how the browser's extension system validates user input. An attacker who has already compromised Chrome's rendering engine can exploit this weakness to escape the browser's sandbox and gain system-level privileges. The attack requires a specially crafted web page and user interaction, but once executed allows the attacker to move from browser context to full machine control.

  • CVE-2026-13925HIGH 7.5

    Google Chrome on Windows contains a flaw in how it handles downloaded files that could allow an attacker to run malicious code on your computer. The attack requires tricking a user into performing specific actions (like clicking or dragging) while viewing a specially crafted webpage. Once triggered, the vulnerability grants full control over the affected system, including the ability to read sensitive data, modify files, or disable functionality.

  • CVE-2026-13968HIGH 7.5

    A vulnerability in Google Chrome's DevTools allows attackers to run malicious code within a sandboxed environment if they can trick a user into performing specific actions with a crafted file. The flaw stems from inadequate validation of user-supplied input, making it possible for remote attackers to execute arbitrary code without needing special privileges or system access. While the code runs in a sandbox—which limits potential system-wide damage—successful exploitation could still grant attackers access to sensitive data or capabilities within that sandbox context.

  • CVE-2026-14115HIGH 7.5

    CVE-2026-14115 is a privilege escalation vulnerability in Google Chrome's Cast feature that allows an attacker who has already compromised Chrome's renderer process to gain elevated system privileges through a specially crafted HTML page. While the underlying Chromium defect is rated Low severity by Google's own assessment, the CVSS 3.1 score reflects the potential for complete system compromise (confidentiality, integrity, and availability impact) once an attacker reaches the renderer process. The vulnerability affects Chrome versions before 150.0.7871.47 and impacts Windows, macOS, and Linux users.

  • CVE-2026-15288HIGH 7.5

    The SureForms WordPress plugin contains a flaw that allows anyone on the internet to change the price of products or services during checkout. When customers submit a payment form powered by Stripe, the plugin accepts the payment amount directly from the user's browser without verifying it matches the price configured in the form. An attacker can intercept and modify this amount to charge significantly less—or potentially nothing—before completing the transaction. This affects all versions of the plugin up to and including 2.2.1.

  • CVE-2026-34712HIGH 7.5

    A flaw in Adobe's Content Credentials (C2PA) library allows an attacker to crash applications using the affected versions by sending specially crafted input. No user interaction is required, and no special permissions are needed—an attacker on the network can trigger this denial-of-service condition remotely. The vulnerability stems from the library's failure to properly validate input before processing it.

  • CVE-2026-36501HIGH 7.5

    Controller version 12.0.5 contains a vulnerability in how it processes serialized Java objects. An attacker can send a specially crafted input to the application's deserialization handler, causing it to crash or become unresponsive. This is a denial-of-service vulnerability that requires network access but no authentication or user interaction.

  • CVE-2026-37460HIGH 7.5

    FRRouting, a widely-used open-source routing protocol suite, contains a flaw in how it validates incoming BGP UPDATE messages. An attacker on the network can send a specially crafted message that causes the routing daemon to crash or become unresponsive, disrupting network operations. This is a network-based denial-of-service vulnerability requiring no authentication or user interaction.

  • CVE-2026-38639HIGH 7.5

    A flaw in relibc's date-parsing function allows an attacker to crash applications by sending specially crafted month values to the strptime function. No data theft or system modification occurs—the impact is purely availability. The vulnerability requires no special permissions or user interaction, making it trivial to trigger remotely over a network.

  • CVE-2026-38891HIGH 7.5

    CVE-2026-38891 is a denial-of-service vulnerability in gazebo_plugins version 3.9.0, specifically in the differential drive controller component. An attacker can crash or hang a ROS-based robot system by sending a specially crafted motion command message. The vulnerability stems from insufficient validation of incoming command data, allowing malformed input to trigger a crash condition. No authentication is required; any network-accessible ROS system running the affected code is at risk.

  • CVE-2026-40376HIGH 7.5

    Visual Studio Code contains a vulnerability that allows an attacker to gain elevated privileges on a user's system via network-based exploitation. The flaw stems from inadequate validation of user input, which can be triggered when a user interacts with a specially crafted input. While the vulnerability requires user interaction and is somewhat difficult to exploit (high complexity), successful exploitation grants an attacker significant control over the affected system, including the ability to read sensitive data, modify files, and potentially disrupt availability.

  • CVE-2026-40454HIGH 7.5

    Apache IoTDB's C++ client contains a flaw that causes it to crash when it receives malformed data from a server. An attacker positioned to intercept or manipulate server responses—or operating a malicious IoTDB instance—can send specially crafted messages that trigger an out-of-bounds memory read, crashing the client application. This is a denial-of-service vulnerability affecting IoTDB C++ clients in versions 1.3.5 through 1.3.7 and 2.0.5 through 2.0.9.

  • CVE-2026-45291HIGH 7.5

    Cloudburst Network is a library used by many networked applications to handle low-level communication. A flaw in versions before 1.0.0.CR3-20260418.124334-32 allows anyone on the internet to send specially crafted requests that crash the network connection, causing the affected application to stop communicating. The vulnerability requires no authentication or user interaction—an attacker simply needs network access to trigger it. While the impact is limited to availability (the connection goes down), the ease of exploitation and broad accessibility make this a significant concern for any publicly facing service using vulnerable Cloudburst Network versions.

  • CVE-2026-45678HIGH 7.5

    OpenTelemetry eBPF Instrumentation versions before 0.9.0 contain a denial-of-service vulnerability in their Postgres protocol parser. When the parser processes a specially crafted BIND message with an empty or unterminated portal name, it attempts to read beyond the buffer boundary, causing the instrumentation service to crash. An unauthenticated network attacker can trigger this crash, disrupting observability and monitoring capabilities for applications relying on this instrumentation.

  • CVE-2026-45685HIGH 7.5

    OpenTelemetry eBPF Instrumentation versions 0.1.0 through 0.8.x contain a denial-of-service vulnerability in their MongoDB wire protocol parser. An attacker on the network can send specially crafted MongoDB messages to crash the telemetry agent without needing authentication or user interaction. When the malformed message reaches the parser, it triggers an unhandled panic that terminates telemetry collection for the affected process or entire node. This is a remote, unauthenticated attack that requires only network access to the listening port.

  • CVE-2026-45783HIGH 7.5

    A vulnerability in libp2p (a JavaScript networking library) before version 16.2.6 allows any unauthenticated attacker on the network to crash kad-dht nodes running in server mode by flooding them with specially crafted messages. The attacker doesn't need valid credentials or an established connection—they can simply send a stream of PUT_VALUE messages with keys designed to bypass content validation. These messages accumulate on the target node's disk until storage is exhausted, rendering the node unavailable. The attack is trivial to execute and requires no special network position or protocol manipulation beyond crafting the malicious keys.

  • CVE-2026-46457HIGH 7.5

    Apache Camel's NATS component has a header-handling flaw that allows untrusted message publishers to inject fake control headers into Camel routes. When a NATS client sends a message to a topic that Camel is consuming, those headers—including Camel's own internal directives like CamelHttpUri or CamelFileName—are copied directly into the message flow without filtering. An attacker who can publish to that NATS topic can craft headers that hijack downstream behavior: redirecting HTTP calls, changing file paths, altering database queries, or worse. The vulnerability affects Camel 4.0.0 through 4.21.0 (with fixes in 4.14.8, 4.18.3, and 4.21.0). It requires NATS 2.2+ and is exploitable on out-of-the-box NATS servers that have no authentication.

  • CVE-2026-46585HIGH 7.5

    Apache Camel's Lucene component contains a vulnerability that allows attackers to bypass intended query restrictions and access unauthorized data through HTTP requests. When a Camel route exposes Lucene search functionality via HTTP, an attacker can inject a malicious search query by setting specific HTTP headers, causing the application to execute searches against the full text index that should have been blocked or filtered. This affects Camel versions 4.0.0 through 4.20.x, with no authentication required if the HTTP endpoint is public. The risk ranges from unauthorized document disclosure to resource exhaustion through expensive queries.

  • CVE-2026-46592HIGH 7.5

    Apache Camel's CXF component has a vulnerability that allows an attacker to trick the system into invoking unintended operations on a backend SOAP service. When a Camel route bridges an HTTP request directly to a SOAP backend, an attacker can inject HTTP headers that override which SOAP operation gets executed. This could mean replacing a safe read operation with a destructive write or delete. The vulnerability exists because Camel's header filtering didn't recognize these control headers as needing protection, letting them pass through from untrusted HTTP clients into the routing logic.

  • CVE-2026-46669HIGH 7.5

    OpenVM is a zero-knowledge virtual machine framework used for proving computation. A flaw in how it validates cryptographic pairing checks allows the system to incorrectly accept or process proofs that should be rejected. Specifically, the library fails to verify that an internal scaling factor meets required mathematical constraints, potentially enabling an attacker to craft a proof that passes validation when it shouldn't. This is a cryptographic soundness issue—the affected proofs may look valid but could represent false claims about computation.

  • CVE-2026-46679HIGH 7.5

    A flaw in the @libp2p/gossipsub library allows a single attacker to remotely crash any gossipsub node running the default configuration by exhausting its heap memory. No authentication is required—the attacker needs only network access to the target node. This denial-of-service attack exploits three related implementation gaps that compound to trigger excessive memory allocation. The vulnerability affects libp2p versions prior to 15.0.23 and has been patched.

  • CVE-2026-46726HIGH 7.5

    Apache Camel's Vertx WebSocket component fails to filter incoming connection parameters, allowing unauthenticated attackers to inject Camel control headers through query or path parameters. When a WebSocket consumer feeds data into an HTTP producer downstream, attackers can redirect the HTTP request to arbitrary internal or external servers and extract sensitive information like environment variables, application properties, or vault secrets by embedding property placeholder references in the injected headers. This is a remote attack requiring no authentication if the WebSocket endpoint is publicly exposed.

  • CVE-2026-47430HIGH 7.5

    A vulnerability in the Apache Cordova InAppBrowser plugin (versions 3.1.0–6.0.0) allows attackers to trick iOS apps into executing unintended plugin callbacks. When an app displays untrusted content in InAppBrowser—such as a social login redirect or marketing landing page—an attacker can craft a malicious message that fires callbacks meant for other installed plugins (like Camera, Contacts, or Geolocation). Because Cordova uses predictable callback naming, attackers can enumerate and target these IDs without specialized knowledge. The result is that the attacker can spoof plugin results: falsely approving a camera request, injecting fake contacts, or returning fabricated file data—all appearing to come from legitimate plugin operations.

  • CVE-2026-48110HIGH 7.5

    Russh, a Rust SSH library used for building SSH clients and servers, contains a memory allocation vulnerability affecting versions 0.34.0 through 0.60.x. An attacker connecting over the network can craft malformed SSH protocol messages with oversized or malformed data fields that force the library to allocate large amounts of memory before validating the input. This can cause denial of service by exhausting available memory or slowing the application. The vulnerability has been fixed in version 0.61.0.

  • CVE-2026-48774HIGH 7.5

    ProxySQL versions 3.0.0 through 3.0.8 contain a critical flaw in their GenAI/MCP feature that allows attackers to perform database writes and administrative commands despite the tool being advertised as read-only. An attacker can craft a SQL request that starts with a harmless SELECT statement followed by destructive commands like RENAME TABLE or DROP TABLE. ProxySQL's validation only checks the beginning of the request and uses a blacklist that misses common write operations, so the full multi-statement payload gets executed on the backend. This means anyone with network access to the MCP query endpoint can modify, delete, or lock database tables.

  • CVE-2026-49218HIGH 7.5

    ImageMagick, a widely used image editing and manipulation tool, contains a flaw in how it processes DCM (DICOM medical imaging) files. The vulnerability allows specially crafted DCM files with invalid dimensions to pass validation checks, potentially causing the application to crash when performing subsequent operations on the image. This is a denial-of-service issue affecting the availability of systems that rely on ImageMagick for image processing.

  • CVE-2026-49234HIGH 7.5

    Routinator, an open-source RPKI relying party software maintained by NLnet Labs, crashes when it receives a malformed (non-UTF-8 encoded) query parameter in API requests. An attacker sending a specially crafted string to the /api/v1/origins endpoint can trigger a denial-of-service condition that takes the service offline. The vulnerability only affects deployments that expose the Routinator API to untrusted networks without additional access controls.

  • CVE-2026-49432HIGH 7.5

    Apache ActiveMQ has a flaw that allows an unauthenticated attacker to crash message broker instances by sending malformed network requests through the STOMP protocol connector. By specifying a negative content-length header and streaming body data, the attacker can either exhaust memory on NIO transports or trigger a forced connection closure on blocking transports, resulting in denial of service. No authentication is required, and the attack succeeds if the STOMP port is accessible over the network.

  • CVE-2026-49434HIGH 7.5

    Apache ActiveMQ contains an input validation flaw that allows attackers with LDAP write access to inject malicious configuration. By modifying LDAP entries matching the broker's search criteria, an attacker can force the broker to instantiate unauthorized transports, retrieve external URLs, and spawn a second message broker instance within the same JVM. This effectively gives an attacker the ability to create a parallel, attacker-controlled broker alongside the legitimate one.

  • CVE-2026-49475HIGH 7.5

    FreeSWITCH, a popular open-source telecom platform used to build VoIP and communication systems, contains a flaw in how it processes STUN packets—a protocol used for network address translation and firewall traversal in voice communications. An attacker sending a specially crafted STUN packet with a mismatched attribute length can cause the software to read and write beyond allocated memory buffers. This out-of-bounds memory access occurs in the media buffer handling logic and can crash the affected FreeSWITCH instance, disrupting voice and video services. The vulnerability affects all versions prior to 1.11.0.

  • CVE-2026-50196HIGH 7.5

    Steeltoe is a framework for building cloud-native applications on .NET, and it includes a service discovery component called Steeltoe.Discovery.Eureka. This component reads service registry information from Eureka servers—a common way microservices find each other. A bug in older versions causes the application to reject a valid service type called 'Netflix' data center, which is legitimately defined in the Eureka specification. When this happens, the registry deserialization fails silently during periodic refresh cycles, leaving your local service registry empty or out of date. This can break service-to-service communication in production environments. Updating to version 4.2.0 (or 3.4.0 for older release lines) fixes the issue.

  • CVE-2026-51606HIGH 7.5

    A vulnerability in Tenda CP3 V3.0 devices (firmware V31.1.9.91) causes the RTSP service to crash and terminate connections when it receives requests with oversized field values. Instead of properly rejecting the malformed request per protocol standards, the device sends a TCP reset (RST), disrupting legitimate video streaming traffic. An attacker on the network can trigger this denial-of-service condition by sending crafted RTSP requests without authentication.

  • CVE-2026-54234HIGH 7.5

    vLLM, a widely-used inference engine for large language models, contains a flaw in its speculative decoding logic that can crash the service. When processing certain multi-request workloads, the rejection sampler can generate an invalid token value that the engine mishandles, eventually triggering a GPU-side assertion failure. Because this crash can be triggered remotely via the public gRPC API, an unauthenticated attacker can repeatedly crash shared inference workers, disrupting service for all other users until manual restart. The issue affects all versions prior to 0.24.0.

  • CVE-2026-54299HIGH 7.5

    Astro, a modern web framework, has a vulnerability in its server-side rendering (SSR) feature when prerendered error pages are enabled. When an error occurs at runtime, Astro fetches prerendered 404 or 500 error pages over HTTP. The problem: it constructs the fetch URL using the Host header from the incoming request without validating it against a whitelist of allowed domains. An attacker can craft a malicious Host header to redirect this fetch to a server they control, potentially allowing them to read sensitive response content. This affects Astro versions before 6.4.6.

  • CVE-2026-54405HIGH 7.5

    A vulnerability in Ubiquiti's UniFi Network Application allows an attacker already present on your network to crash or disable the application by sending specially crafted requests. The flaw stems from inadequate validation of incoming data. While an attacker must have network access to exploit this, the impact is significant—your UniFi infrastructure could become unavailable, disrupting network management and potentially affecting connected devices.

  • CVE-2026-55993HIGH 7.5

    Apache Camel's WebSocket component has a critical flaw that allows unauthenticated attackers to redirect server-side HTTP requests and steal sensitive configuration data. When a WebSocket endpoint receives connections, it accepts query parameters that get converted into internal Camel headers without validation. An attacker can inject specially crafted parameters to override the HTTP destination URI and trigger exposure of environment variables, application properties, and vault secrets through placeholder resolution. This is particularly dangerous in deployments where the WebSocket endpoint feeds directly into downstream HTTP producers and lacks authentication controls.

  • CVE-2026-55994HIGH 7.5

    Apache Camel's Iggy component fails to filter incoming message headers before copying them into the application's internal header map. This allows an attacker who can publish messages to a monitored Iggy stream to inject specially crafted headers that override Camel's internal routing directives. When those messages flow through an HTTP request, the injected headers can redirect the request to an attacker-controlled server (SSRF attack) or leak sensitive data like environment variables and secrets. The vulnerability affects Camel versions 4.17.0 through 4.20.x and requires patching to 4.18.3 (for 4.18 branch users) or 4.21.0 (for current releases).

  • CVE-2026-58292HIGH 7.5

    Microsoft Edge (Chromium-based) contains a flaw that fails to properly validate user input, allowing attackers to execute code on affected systems over the network. An attacker would typically need to trick a user into visiting a malicious webpage or interacting with crafted content, but once successful, the attacker gains the ability to run arbitrary code with the privileges of the Edge browser process.

  • CVE-2026-59724HIGH 7.5

    Socket.IO's Engine.IO component versions 6.5.0 through 6.6.6 contain a denial-of-service vulnerability when WebTransport is enabled. An attacker can send a specially crafted session identifier (like '__proto__') that exploits how the server resolves inherited properties of internal objects, triggering a crash that disrupts service for all users. No authentication is required, and exploitation is straightforward from the network. Version 6.6.7 and later address this flaw.

  • CVE-2026-10968HIGH 7.4

    A vulnerability in Chrome's graphics rendering engine (Dawn) on Windows allows attackers to steal sensitive data from websites you're visiting. If an attacker first compromises Chrome's renderer process—the part that runs web content—they can craft a malicious webpage to leak information across website boundaries, bypassing Chrome's security isolation. This requires the attacker to have already gained control of the renderer, making it part of a multi-stage attack but with serious data-theft consequences once achieved.

  • CVE-2026-13341HIGH 7.4

    Kong Konnect's Model Context Protocol (MCP) server before version 1.0.0 contains a flaw that allows remote attackers to inject malicious prompts indirectly, tricking the system into executing API requests the user never intended. An attacker can exploit this by crafting input that, when processed by the MCP server, causes it to perform unauthorized actions on behalf of legitimate users. No authentication is required, and while the attack requires user interaction (such as clicking a link or viewing content), the impact crosses trust boundaries, potentially exposing sensitive data across multiple systems.

  • CVE-2026-11035HIGH 7.3

    Google Chrome on Android contains a flaw in how it handles Custom Tabs—a feature that allows apps to open web content within their own interface. An attacker with local access to a device can exploit this vulnerability by crafting a malicious XML file, potentially gaining elevated privileges on the system. The issue affects Chrome versions prior to 149.0.7827.53. While the base severity from Chromium is listed as Medium, the overall risk score reflects the complete attack chain impact.

  • CVE-2026-11460HIGH 7.3

    Boost Serialization, a widely-used C++ library for object serialization, contains a validation flaw that allows remote attackers to send specially crafted input that bypasses security checks. The vulnerability affects all versions up to 1.91 and can lead to information disclosure, data tampering, or service disruption. No patch currently exists, and the vendor has indefinitely postponed fixing it despite being notified in August 2025 and exceeding the 90-day disclosure deadline.

  • CVE-2026-30760HIGH 7.3

    SourceBans Material Admin, a web-based administration panel, contains a vulnerability that allows unauthenticated attackers to alter user data through a specially crafted XAJAX request. An attacker can send a malicious web request to manipulate account information, permissions, or other critical user attributes without needing valid credentials. This affects versions prior to 1.1.6.

  • CVE-2026-46587HIGH 7.3

    Apache Camel contains an input validation flaw that allows attackers to send specially crafted requests to affected systems without authentication. The vulnerability can lead to information disclosure, unauthorized modifications, and service disruption. Organizations running vulnerable versions of Camel should prioritize upgrading to patched releases.

  • CVE-2026-46588HIGH 7.3

    Apache Camel, a widely-used open-source integration framework, contains a flaw in how it validates user input. This weakness allows an attacker to send specially crafted requests over the network without authentication, potentially compromising the confidentiality, integrity, or availability of affected systems. The vulnerability spans multiple version lines, affecting releases through 4.14.7, versions 4.15.0 through 4.18.2, and versions 4.19.0 through 4.20.0.

  • CVE-2026-49042HIGH 7.3

    Apache Camel, a widely used integration framework, contains an improper input validation vulnerability that allows unauthenticated attackers to send malformed requests over the network. This flaw can lead to information disclosure, data manipulation, or service disruption depending on how the affected application processes untrusted input. The vulnerability affects multiple version lines and requires immediate patching to maintain security posture.

  • CVE-2026-10651HIGH 7.1

    A Bluetooth protocol parser in Zephyr has a boundary-checking flaw that allows a remote device to read one byte past the allocated buffer. When a specially crafted SDP (Service Discovery Protocol) record arrives, the parser validates only that three bytes are present, then immediately tries to read a fourth byte without proper bounds checking. The over-read itself is limited and not exploitable for data theft, but it can crash the device if that fourth byte sits at a memory boundary or trigger a debug assertion. This affects devices running Zephyr 4.3.0 and 4.4.0 and requires no authentication—any paired or nearby Bluetooth peer can send the malicious record.

  • CVE-2026-43725HIGH 7.1

    A sandbox escape vulnerability in Apple's Safari browser and related platforms allows malicious websites to execute code outside the intended security boundary. By exploiting improper input validation, an attacker can craft a malicious webpage that, when visited by a user, breaks out of the sandbox protection that normally isolates web content. This could allow the attacker to access restricted system resources or data that should be inaccessible to web content.

  • CVE-2026-45329HIGH 7.1

    CVE-2026-45329 is a memory disclosure vulnerability in Espressif's IoT Development Framework (ESP-IDF) affecting versions 5.5.4 and 6.0. The issue stems from inadequate input validation in secure-service wrapper functions that interface with TEE (Trusted Execution Environment) hardware. An attacker with local access can supply carefully crafted memory pointers to these wrappers, causing the underlying TEE-protected peripherals (such as ECC, SHA, or SPI engines) to read sensitive data from TEE-exclusive memory regions and return it to the untrusted realm. The disclosure occurs through direct byte leakage, computed results, or bit-level oracles, enabling incremental extraction of secrets stored in the TEE.

  • CVE-2026-46243HIGH 7.1

    A Linux kernel vulnerability allows unprivileged local users to manipulate CIFS (Common Internet File System) authentication credentials by creating spoofed credential requests. The vulnerability exists because the kernel's SMB client accepts cifs.spnego key descriptions that contain sensitive fields—like process ID, user ID, and credential UID—regardless of whether those fields come from the kernel itself or from untrusted userspace. An attacker with local access can forge these fields to impersonate legitimate credential requests, potentially gaining unauthorized access to network resources or intercepting authentication flows. The fix restricts acceptance of cifs.spnego keys only when they originate from the kernel's own credential handler.

  • CVE-2026-48569HIGH 7.1

    A flaw in Visual Studio Code's input handling allows a local attacker to circumvent a security mechanism without requiring elevated privileges or special user setup. The attacker must interact with the application through the user interface, but once triggered, the exploit can affect system-wide settings and processes beyond the application's normal scope. This is a local-attack surface issue that could allow an unauthorized actor to modify or access protected features.

  • CVE-2026-11218MEDIUM 6.8

    A flaw in Google Chrome's platform integration layer on Windows allows attackers to trick users into running malicious files that execute arbitrary code on their system. The vulnerability requires specific user interaction—the attacker must convince the victim to perform particular UI gestures when opening a crafted file. While Chrome's vendor assessment rates this as low severity, the combination of remote reach and code execution capability elevates the practical risk for organizations with large user populations.

  • CVE-2026-36175MEDIUM 6.8

    CVE-2026-36175 is a physical authentication bypass vulnerability affecting GNCC GP5 v7.1.76. An attacker with direct physical access to a device can interrupt the boot process and inject malicious kernel boot arguments, circumventing security controls to obtain root-level access. The vulnerability requires the attacker to be present at the device during startup, making it a targeted risk rather than a remote threat.

  • CVE-2025-5089MEDIUM 6.5

    CVE-2025-5089 is a denial-of-service vulnerability affecting Arista EOS switches and CloudVision eXchange (CVX) servers when they communicate with each other. When either device receives specially crafted messages over their management connection, it can crash internal system processes, causing the EOS switch to reset or the CVX cluster to become unstable. An attacker would need legitimate administrative access to one of these connected devices to exploit this vulnerability—it cannot be triggered remotely by an unauthenticated outsider.

  • CVE-2025-5090MEDIUM 6.5

    CVX, a network control platform, crashes when it receives malformed or unexpected messages from a connected network switch. An attacker with administrative access to that switch could exploit this instability to repeatedly trigger crashes, disrupting the CVX cluster's availability. This is a denial-of-service vulnerability that requires high privilege on the switch infrastructure to execute.

  • CVE-2025-58175MEDIUM 6.5

    GeoServer, an open-source geospatial data sharing platform, contains a Server-Side Request Forgery (SSRF) vulnerability in versions before 2.26.4 and 2.27.3. An attacker without authentication can exploit this flaw to make the server perform unauthorized network requests on their behalf, potentially accessing internal resources or sensitive data. The vulnerability is only active when GeoServer is configured with a proxy base URL lacking a path component or trailing slash, and when entity resolution allowlist is enabled (the default since version 2.25.0).

  • CVE-2026-0051MEDIUM 6.5

    A vulnerability in Google Android's UBSan (Undefined Behavior Sanitizer) runtime component allows an authenticated attacker to crash the system by sending malformed input to multiple functions in ubsan_throwing_runtime.cpp. The vulnerability requires valid credentials to exploit but no special privileges, and the attacker doesn't need to interact with the device user. The impact is denial of service—the system becomes unavailable—but data confidentiality and integrity are not compromised.

  • CVE-2026-0282MEDIUM 6.5

    Palo Alto Networks PAN-OS contains a vulnerability that allows an attacker on the network to delete files from a temporary directory on the management interface without authentication. The actual risk depends heavily on your deployment posture—Palo Alto emphasizes that restricting management access to trusted internal networks significantly reduces exposure. Cloud NGFW and Prisma Access deployments are unaffected.

  • CVE-2026-10004MEDIUM 6.5

    Google Chrome versions before 148.0.7778.216 contain a flaw in how they validate user input within the password-handling component. An attacker can craft a malicious HTML page that, when visited by a user, tricks the browser into displaying fake password prompts or other UI elements that appear legitimate. This is a spoofing attack—the attacker doesn't steal data directly, but deceives users into believing they're interacting with genuine Chrome interface elements, potentially leading them to enter credentials or take other unintended actions.

  • CVE-2026-10912MEDIUM 6.5

    A flaw in Google Chrome's extension handling allows an attacker who has already compromised the renderer process to bypass the browser's same-origin policy—a core security boundary that prevents JavaScript from one website accessing data from another. An attacker would need to trick a user into visiting a specially crafted webpage to exploit this. The vulnerability affects Chrome versions prior to 149.0.7827.53 across Windows, macOS, and Linux.

  • CVE-2026-10938MEDIUM 6.5

    Google Chrome versions before 149.0.7827.53 contain a flaw in how the browser handles certain HTML input that could allow an attacker to circumvent site isolation protections, but only if they have already compromised the renderer process. Site isolation is Chrome's core defense that prevents a compromised website from accessing data from other open websites. This vulnerability narrows that protection in specific scenarios.

  • CVE-2026-10980MEDIUM 6.5

    Google Chrome versions before 149.0.7827.53 contain a flaw in DevTools that allows an attacker who has already compromised the browser's rendering engine to bypass the same-origin policy—a core security boundary that prevents websites from accessing each other's data. An attacker could craft a malicious HTML page to exploit this, potentially gaining unauthorized access to sensitive information from other websites.

  • CVE-2026-10981MEDIUM 6.5

    CVE-2026-10981 is a cross-origin data leak vulnerability in Google Chrome's video codec handling. An attacker who has already compromised Chrome's renderer process can craft a malicious video file to exfiltrate sensitive data from other websites the user is visiting. The vulnerability requires user interaction (opening or playing a video file) and relies on prior compromise of the rendering engine, limiting the attack surface but creating risk for users who already have malware or who visit compromised sites.

  • CVE-2026-10992MEDIUM 6.5

    Google Chrome versions prior to 149.0.7827.53 contain a flaw in how the Animation feature validates user-supplied data. An attacker can craft a malicious HTML page that, when opened in a vulnerable Chrome browser, leaks sensitive information stored in the browser's process memory. The attack requires user interaction (opening the page) but no authentication or special browser configuration.

  • CVE-2026-11007MEDIUM 6.5

    A flaw in Google Chrome's WebView on Android allows an attacker who has already compromised Chrome's renderer process to steal sensitive data from other websites. The vulnerability stems from inadequate validation of user-supplied input, making it possible for an attacker to craft a malicious webpage that leaks cross-origin information—data that should remain isolated between websites. While the attacker must first gain control of the renderer process, the subsequent data leakage requires only that a user visit a crafted page, making this a meaningful risk in multi-stage attack chains.

  • CVE-2026-11008MEDIUM 6.5

    A flaw in Google Chrome's web app installation feature fails to properly validate user input, allowing an attacker who has already compromised Chrome's renderer process to extract sensitive data from other websites through a malicious webpage. The attacker would need to trick a user into visiting a crafted HTML page, but once the renderer is compromised, the vulnerability creates a pathway to leak cross-origin information that should remain isolated.

  • CVE-2026-11013MEDIUM 6.5

    Google Chrome versions before 149.0.7827.53 contain a flaw in how the browser validates user-supplied input within its networking code. An attacker who has already compromised Chrome's renderer process—the sandboxed component that executes web content—can craft a malicious HTML page to leak sensitive data from the renderer's memory. This is a post-compromise attack vector; the attacker must first gain code execution in the renderer sandbox, but once there, they can extract information that should remain private.

  • CVE-2026-11016MEDIUM 6.5

    Google Chrome versions before 149.0.7827.53 contain a flaw where insufficient validation of network input allows a remote attacker who has already compromised the browser's renderer process to bypass the same-origin policy. An attacker could craft a malicious HTML page to force the compromised renderer to access resources or data from a different origin, violating the security boundary that normally prevents cross-origin access. This requires initial renderer process compromise—the attacker cannot trigger the vulnerability from an unauthenticated network position alone.

  • CVE-2026-11022MEDIUM 6.5

    CVE-2026-11022 is a same-origin policy bypass vulnerability in Google Chrome's DevTools that requires an attacker to have already compromised the renderer process. An attacker could then use a specially crafted HTML page to escape origin restrictions, potentially accessing or modifying data from other websites in the same browser session. This is not a remote code execution vector but rather a privilege escalation within an already-compromised rendering context.

  • CVE-2026-11023MEDIUM 6.5

    Google Chrome versions prior to 149.0.7827.53 contain a flaw in how the browser handles web app installation that allows an attacker who has already compromised the browser's renderer process to bypass the same-origin policy. This means a specially crafted web page could be used to access or modify content from other websites in ways the browser is supposed to prevent. The attacker needs prior renderer compromise, limiting the immediate threat to users, but the bypass itself is reliable once that initial foothold exists.

  • CVE-2026-11027MEDIUM 6.5

    A vulnerability in Google Chrome's Glic component fails to properly validate untrusted input, allowing an attacker who has already compromised Chrome's renderer process to extract sensitive data across website boundaries using a specially crafted webpage. The attacker needs initial renderer process compromise but then gains the ability to read data from sites the user visits, bypassing normal browser security boundaries.

  • CVE-2026-11038MEDIUM 6.5

    Google Chrome versions before 149.0.7827.53 contain a flaw in how Subresource Integrity (SRI) policies are enforced, allowing attackers to bypass Content Security Policy (CSP) protections through crafted network traffic. An attacker would need to trick a user into visiting a malicious webpage to exploit this vulnerability. The issue is classified as medium severity because it enables content injection attacks but does not directly compromise confidentiality or system availability.

  • CVE-2026-11045MEDIUM 6.5

    Google Chrome versions before 149.0.7827.53 contain a flaw in GPU input validation that can leak sensitive data from memory. An attacker who has already compromised Chrome's renderer process can craft a malicious HTML page to read protected information. This is a stepping-stone attack—it requires prior renderer compromise but can extract valuable secrets afterward.

  • CVE-2026-11069MEDIUM 6.5

    Google Chrome versions before 149.0.7827.53 contain a flaw in how the Cast feature validates user input, allowing an attacker to craft a malicious HTML page that bypasses the browser's same-origin policy. If a user visits the attacker's page, it could potentially access or modify data from other websites the user is logged into, though without stealing that data directly. This is a moderate-severity issue affecting Windows, macOS, and Linux users.

  • CVE-2026-11078MEDIUM 6.5

    Google Chrome versions before 149.0.7827.53 contain a flaw in how the browser's FileSystem implementation validates cross-origin requests. If an attacker compromises Chrome's renderer process—the sandboxed component that executes web content—they can craft a malicious HTML page to bypass the same-origin policy, a foundational browser security mechanism that prevents one website from accessing data or resources belonging to another. The vulnerability requires the renderer to already be compromised, meaning an attacker would need to have successfully exploited a prior vulnerability to reach this point, making it a secondary but meaningful risk in a multi-stage attack chain.

  • CVE-2026-11093MEDIUM 6.5

    Google Chrome versions before 149.0.7827.53 contain a flaw in how the browser handles printing functionality that could allow an attacker who has already compromised Chrome's rendering engine to steal sensitive data from websites the user visits. The attacker would need to trick the user into visiting a malicious webpage after gaining control of the renderer process. This is a medium-severity issue because it requires an intermediate compromise and user interaction, but the potential for cross-origin data leakage makes it worth prompt attention.

  • CVE-2026-11105MEDIUM 6.5

    A flaw in Google Chrome's WebUI component fails to properly validate user-supplied input, allowing an attacker who has already compromised Chrome's renderer process to trick the browser into leaking sensitive data from other websites. The vulnerability requires the renderer to be compromised first, which significantly limits the attack surface. Chrome versions before 149.0.7827.53 are affected.

  • CVE-2026-11121MEDIUM 6.5

    CVE-2026-11121 is a medium-severity vulnerability in Skia, the graphics rendering engine used by Google Chrome. The flaw involves improper validation of untrusted input that could allow an attacker who has already compromised the browser's renderer process to extract sensitive data across origin boundaries using a specially crafted web page. This is not an initial entry point into systems, but rather a post-compromise escalation vector that broadens the damage an attacker can do once inside the browser process.

  • CVE-2026-11128MEDIUM 6.5

    Google Chrome versions before 149.0.7827.53 contain a flaw in the Web Share feature that allows attackers to steal data from other websites. The vulnerability requires tricking a user into clicking or interacting with elements on a malicious webpage. Once triggered, an attacker can access information from cross-origin sources—essentially reading data they shouldn't have access to. This is a client-side issue affecting individual users rather than servers, and the bar for exploitation is user interaction on a crafted page.

  • CVE-2026-11140MEDIUM 6.5

    A memory reading vulnerability in Google Chrome's Chromecast feature allows an attacker who has already compromised the browser's renderer process to steal sensitive data from the browser's memory by serving a specially crafted web page. The vulnerability requires the attacker to have control of the renderer—the component that displays websites—but once achieved, they can extract information without needing special privileges or modifying the page's normal function.

  • CVE-2026-11189MEDIUM 6.5

    A flaw in Google Chrome's developer tools allowed attackers to bypass navigation restrictions through malicious browser extensions. If a user installed a crafted extension, an attacker could manipulate Chrome's navigation controls to reach restricted pages or resources. The vulnerability requires user action—specifically, convincing someone to install the malicious extension—but once installed, no additional user interaction is needed for the bypass itself.

  • CVE-2026-11220MEDIUM 6.5

    A flaw in Google Chrome's navigation handling prior to version 149.0.7827.53 allows a remote attacker who has already compromised the renderer process to bypass the browser's site isolation protection using a specially crafted HTML page. Site isolation is a critical Chrome security boundary designed to prevent malicious websites from accessing data from other sites. This vulnerability requires the attacker to have already gained code execution in the renderer process, making it a secondary or chained attack rather than a direct entry point.

  • CVE-2026-11223MEDIUM 6.5

    A vulnerability in Google Chrome allows an attacker who has already compromised the browser's renderer process to bypass the same-origin policy—a fundamental security boundary that prevents malicious websites from accessing data belonging to other sites. The attacker would craft a specially designed HTML page to exploit insufficient input validation in Chrome's network handling. This requires the renderer process to be compromised first, making it a secondary attack that compounds an existing breach rather than a standalone entry point.

  • CVE-2026-11283MEDIUM 6.5

    Google Chrome on macOS contains a flaw in how it validates input when processing Shortcuts—a macOS feature that allows automation of tasks across applications. An attacker can craft a malicious file that, when opened by a user, bypasses Chrome's navigation restrictions, potentially redirecting the user to unintended web destinations. This requires user interaction (opening the file) but does not require special system privileges or network complexity. The vulnerability was patched in Chrome version 149.0.7827.53.

  • CVE-2026-11287MEDIUM 6.5

    A vulnerability in Google Chrome on Android allows an attacker who has already compromised the browser's renderer process to bypass navigation controls and direct users to unintended destinations using specially crafted web pages. The attacker must first gain control of the renderer process—a significant prerequisite—but once achieved, can manipulate where the browser navigates without proper restrictions. This affects Chrome versions prior to 149.0.7827.53.

  • CVE-2026-11653MEDIUM 6.5

    Google Chrome versions before 149.0.7827.103 contain a flaw in how browser extensions are implemented that could allow an attacker to bypass site isolation—Chrome's core security mechanism that prevents websites from accessing each other's data. The attack requires two conditions: the attacker must first compromise Chrome's renderer process (the component that executes web pages), and then serve a specially crafted HTML page to the victim. While the technical barrier is high, successful exploitation would let malicious code access data across site boundaries, violating the security boundary that normally isolates sensitive information from different origins.

  • CVE-2026-11658MEDIUM 6.5

    A vulnerability in Google Chrome's extension validation system allows an attacker who has already compromised Chrome's renderer process to bypass site isolation—a critical security boundary that prevents malicious websites from accessing data across different sites. The flaw stems from insufficient checking of untrusted input in the Extensions subsystem. An attacker would need to trick a user into visiting a specially crafted HTML page while the renderer is already compromised, making this a secondary attack that compounds an existing breach rather than a standalone entry point.

  • CVE-2026-13816MEDIUM 6.5

    A vulnerability in Google Chrome for Android allows attackers to steal private data from different websites through a crafted web page. The flaw exists in how Chrome handles file inputs without properly validating untrusted data. An attacker would need to trick a user into visiting a malicious page, but once that happens, sensitive cross-origin information—data meant to be isolated between websites—can be extracted. This affects Chrome versions prior to 150.0.7871.47 on Android devices.