By severity
High-severity vulnerabilities
CVEs rated High by CVSS, with SEC.co remediation and prioritization guidance.
4140 published vulnerabilities · page 3 of 42
- CVE-2026-11589HIGH 8.8
The WP Support Plus Responsive Ticket System WordPress plugin has a file upload vulnerability that allows attackers to upload malicious files without needing to log in. These files—such as HTML or SVG documents containing JavaScript—are stored in publicly accessible locations on the website, where they can execute in users' browsers and steal data or compromise accounts. This is a stored cross-site scripting (XSS) vulnerability affecting all versions through 9.1.2.
- CVE-2026-11610HIGH 8.8
A heap buffer overflow vulnerability exists in 389 Directory Server's SASL authentication layer. After an authenticated user successfully logs in with integrity protection enabled, they can send a malformed LDAP packet that causes the server to write up to 2 megabytes of data into a 512-byte memory buffer. This memory corruption crashes the server. In FreeIPA and Red Hat Identity Management environments, any domain user, enrolled host, or service account with valid credentials can exploit this over the network to cause an outage.
- CVE-2026-11616HIGH 8.8
The Events Calendar for GeoDirectory WordPress plugin contains a privilege escalation flaw that allows authenticated users with Subscriber-level permissions to become Administrator. An attacker can manipulate input fields in a specific AJAX handler to inject WordPress capability data directly into their user profile, granting them full admin rights. This affects versions up to 2.3.28 and requires only valid WordPress account credentials to exploit.
- CVE-2026-11629HIGH 8.8
A use-after-free vulnerability in Google Chrome's Ozone component allows attackers to crash the browser or corrupt its memory by tricking users into visiting a specially crafted webpage. The attacker needs the victim to click a link or visit a malicious site—no special privileges are required. Chrome versions before 149.0.7827.103 are affected.
- CVE-2026-11630HIGH 8.8
Google Chrome versions prior to 149.0.7827.103 contain a use-after-free vulnerability in its file input handling. An attacker can craft a malicious HTML page that, when visited by a user, triggers improper memory management in Chrome's file handling code. This allows the attacker to corrupt memory on the victim's computer, potentially leading to arbitrary code execution. The vulnerability requires user interaction (visiting a malicious webpage) but affects users across Windows, macOS, and Linux systems.
- CVE-2026-11633HIGH 8.8
Google Chrome on macOS contains a use-after-free vulnerability in its Bluetooth handling code. This flaw allows a remote attacker to execute arbitrary code on a victim's machine if that person connects to or interacts with a malicious Bluetooth peripheral while using an unpatched version of Chrome. The vulnerability affects Chrome versions prior to 149.0.7827.103 on Mac systems.
- CVE-2026-11637HIGH 8.8
A use-after-free vulnerability exists in Google Chrome's Views component on macOS that allows attackers to execute arbitrary code on a victim's machine. The flaw is triggered when a user visits a specially crafted webpage, requiring no special privileges or complex setup. Google has classified this as a critical severity issue in the underlying Chromium project. This vulnerability affects Chrome versions prior to 149.0.7827.103 on macOS systems.
- CVE-2026-11646HIGH 8.8
A use-after-free flaw in Google Chrome's ViewTransitions feature allows attackers to run arbitrary code within Chrome's sandbox by tricking users into visiting a malicious website. The vulnerability exists in Chrome versions before 149.0.7827.103 and requires user interaction—specifically clicking or otherwise engaging with a crafted HTML page. While the code runs in a sandboxed environment (limiting direct system access), it still represents a significant threat because sandbox escapes are a known attack progression.
- CVE-2026-11648HIGH 8.8
A use-after-free memory flaw exists in Google Chrome's full-screen functionality on Windows. An attacker can craft a malicious web page that, when visited, exploits this flaw to corrupt the browser's memory heap. This could allow the attacker to execute arbitrary code on the victim's machine with the same privileges as the user running Chrome. The vulnerability requires user interaction (clicking or navigating to the malicious page) but no special privileges or complex setup.
- CVE-2026-11649HIGH 8.8
Google Chrome versions before 149.0.7827.103 contain a use-after-free vulnerability in the V8 JavaScript engine that allows attackers to execute arbitrary code within the Chrome sandbox by serving a malicious HTML page. The flaw requires user interaction (clicking a link or visiting a site) but does not require special privileges. While the sandbox limits the immediate blast radius, successful exploitation could grant an attacker control over the browser process and access to user data like credentials, session tokens, and browsing history.
- CVE-2026-11650HIGH 8.8
A use-after-free flaw in Google Chrome's V8 JavaScript engine allows attackers to execute arbitrary code within the browser's sandbox by tricking users into visiting a malicious website. The vulnerability affects Chrome versions before 149.0.7827.103 and requires user interaction (clicking a link or visiting a page). While the code runs in a sandboxed environment, successful exploitation could allow attackers to break out of the sandbox or pivot to other browser features, making this a serious but not trivial attack vector.
- CVE-2026-11657HIGH 8.8
Google Chrome on macOS contains a use-after-free memory flaw in its Payments feature that allows an attacker to run malicious code on a user's machine. The vulnerability is triggered when a user visits a specially crafted website, making it relatively easy to exploit in the wild. Chrome versions before 149.0.7827.103 on macOS are affected. This is a remote code execution risk that requires user interaction (clicking a link or visiting a site) but no special privileges.
- CVE-2026-11662HIGH 8.8
A type confusion vulnerability in Google Chrome's bindings mechanism allows attackers to execute arbitrary code within the Chrome sandbox by serving a specially crafted HTML page. The flaw affects Chrome versions before 149.0.7827.103 and requires user interaction (visiting a malicious page) to trigger. While sandboxed, successful exploitation could lead to complete compromise of the affected Chrome process, including data theft and system-level attacks if combined with additional vulnerabilities.
- CVE-2026-11664HIGH 8.8
A use-after-free vulnerability exists in Google Chrome's Payments component that could allow an attacker to corrupt browser memory and potentially execute arbitrary code. An attacker would need to trick a user into visiting a malicious website to trigger the flaw. The issue affects Chrome versions prior to 149.0.7827.103 and is considered high-severity by Google's security team.
- CVE-2026-11670HIGH 8.8
A use-after-free vulnerability in Google Chrome's PDF renderer allows attackers to run malicious code within the browser's sandbox by crafting a specially designed PDF file. The attack requires user interaction—specifically, opening a malicious PDF—but once triggered, it can lead to complete compromise of the affected browser process. This affects Chrome versions prior to 149.0.7827.103 across Windows, macOS, and Linux systems.
- CVE-2026-11673HIGH 8.8
A use-after-free vulnerability in Google Chrome's InterestGroups feature allows attackers to execute arbitrary code within the browser's sandbox by tricking users into visiting a malicious webpage. The vulnerability affects Chrome versions prior to 149.0.7827.103 and can be exploited without requiring user privileges beyond normal web browsing.
- CVE-2026-11674HIGH 8.8
A use-after-free flaw in Google Chrome's Guest View feature allows attackers to run malicious code within the browser sandbox by tricking users into visiting a specially crafted webpage. While the exploit runs in a sandboxed environment, a successful attack could still compromise sensitive data or enable further system compromise. The vulnerability affects Chrome versions before 149.0.7827.103 and requires user interaction to trigger.
- CVE-2026-11680HIGH 8.8
Google Chrome contains a use-after-free vulnerability in its Media component that could allow an attacker to run malicious code within Chrome's sandbox by tricking a user into visiting a specially crafted website. The flaw affects Windows systems running Chrome versions prior to 149.0.7827.103. While the exploit requires user interaction (clicking a link or visiting a site), the potential impact is severe: an attacker could steal sensitive data, modify files, or cause denial of service, all while operating within Chrome's restricted sandbox environment.
- CVE-2026-11681HIGH 8.8
A use-after-free vulnerability exists in the Ozone display layer of Google Chrome on Linux systems. An attacker can craft a malicious HTML page that, when visited by a user, triggers improper memory management and causes heap corruption. This can lead to a crash or arbitrary code execution on the victim's machine. The vulnerability requires user interaction (clicking a link or visiting a site) but does not require any special browser configuration or elevated privileges.
- CVE-2026-11683HIGH 8.8
Google Chrome contains a use-after-free vulnerability in its WebCodecs component that allows remote attackers to execute arbitrary code within the browser sandbox. An attacker would need to trick a user into visiting a specially crafted webpage to trigger the flaw. Once exploited, the attacker gains code execution privileges within Chrome's sandbox environment, which limits but does not eliminate the potential for system compromise depending on sandbox escape possibilities.
- CVE-2026-11687HIGH 8.8
A memory safety flaw in Google Chrome's graphics rendering engine (Dawn) on macOS allows attackers to corrupt memory on a victim's computer by tricking them into visiting a malicious website. The vulnerability exists in Chrome versions before 149.0.7827.103 and can lead to complete compromise of the affected system.
- CVE-2026-11688HIGH 8.8
Google Chrome versions prior to 149.0.7827.103 contain a flaw in how the browser handles SVG (Scalable Vector Graphics) content. An attacker can craft a malicious HTML page that, when visited by a user, executes arbitrary code within Chrome's sandbox environment. While the sandbox is designed to limit damage, this vulnerability allows an attacker to breach that boundary, potentially compromising user data and system integrity.
- CVE-2026-11698HIGH 8.8
Google Chrome on macOS contains a use-after-free vulnerability in its Bluetooth handling code that allows attackers to corrupt heap memory when a victim visits a malicious website. The vulnerability affects Chrome versions before 149.0.7827.103 and requires user interaction (clicking a link or visiting a site) but does not require special privileges. Successful exploitation can lead to data theft, system compromise, or application crash.
- CVE-2026-11699HIGH 8.8
A use-after-free vulnerability exists in the Bluetooth component of Google Chrome on macOS. An attacker can craft a malicious webpage that, when visited by a user, exploits this flaw to corrupt the browser's memory and potentially execute arbitrary code. The vulnerability requires user interaction (visiting a link or webpage) but does not require the victim to have any special privileges. Google has assigned it high severity and has released a patch in Chrome version 149.0.7827.103.
- CVE-2026-11769HIGH 8.8
The Grafana Operator, a popular tool for managing Grafana instances in Kubernetes environments, contains a security flaw that allows attackers with dashboard creation permissions to steal the operator's service account token. The vulnerability stems from the operator's support for jsonnet templating—a data definition language evaluated within the operator's pod context—which can be exploited to access sensitive credentials. This affects all versions up to and including 5.23, with version 5.24.0 providing the fix.
- CVE-2026-11855HIGH 8.8
A vulnerability exists in the Simple Membership WordPress plugin (before version 4.7.5) where the plugin fails to properly validate Stripe webhook requests when no signing secret is configured. This allows attackers to send forged webhook messages containing malicious code. The plugin also fails to properly sanitize data from these webhooks before displaying it to administrators, enabling the attacker to inject and execute arbitrary JavaScript in the admin interface. Any logged-in administrator viewing the affected notice becomes a target, making this a practical attack vector for account compromise or further site infiltration.
- CVE-2026-11933HIGH 8.8
MongoDB Server contains a use-after-free vulnerability in its server-side JavaScript engine when processing BSON documents. An authenticated user with read access who can execute server-side JavaScript code—through operators like $where or $function—can trigger the server to read memory that has already been freed. This can leak sensitive data from the mongod process or crash the server entirely.
- CVE-2026-11962HIGH 8.8
The FileOrganizer WordPress plugin has a file-upload vulnerability that lets authenticated users with file-manager access upload and execute malicious PHP files on a website. This is a partial regression—the vendor previously patched direct uploads in CVE-2024-7985, but other file-management operations were left unprotected. Users who install the premium add-on can grant sub-administrator roles file-manager permissions, expanding the attack surface. The issue is fixed in version 1.2.0.
- CVE-2026-12007HIGH 8.8
A use-after-free vulnerability in Google Chrome's core rendering engine on Windows allows attackers to execute arbitrary code by tricking users into visiting a malicious webpage. The flaw exists in memory management logic—when Chrome processes certain HTML constructs, it may attempt to access memory that has already been freed, enabling an attacker to overwrite that freed memory with malicious code. No special user privileges or system access are required; the attack succeeds if a user simply visits a crafted page in a vulnerable Chrome version.
- CVE-2026-12018HIGH 8.8
A flaw in Chrome's Mojo implementation on Windows allows a local attacker to gain system-level control by tricking a user into opening a malicious file. The vulnerability affects Chrome versions before 149.0.7827.115 and has been rated High severity by Google's security team.
- CVE-2026-12020HIGH 8.8
A use-after-free vulnerability exists in Google Chrome's Autofill feature on macOS. When a user visits a malicious website, an attacker can craft HTML that triggers heap memory corruption. The flaw allows potential arbitrary code execution with the same privileges as the Chrome browser process. All macOS users running Chrome versions prior to 149.0.7827.115 are at risk.
- CVE-2026-12035HIGH 8.8
Google Chrome on Windows contains a use-after-free vulnerability in its Views component that could allow an attacker to corrupt memory on a victim's computer. The flaw requires user interaction—clicking or interacting with a malicious webpage—but once triggered, an attacker could potentially execute arbitrary code with the privileges of the Chrome process. This is a remote attack that does not require the victim to install software or bypass authentication.
- CVE-2026-12043HIGH 8.8
AWS Common Runtime's HTTP/2 library contains a flaw in how it processes dynamic table size updates from remote servers. An attacker operating a malicious server could send a carefully crafted sequence of HTTP/2 frames to corrupt memory in client applications that connect to it, potentially allowing arbitrary code execution. This affects any application using the aws-c-http library for HTTP/2 communication.
- CVE-2026-12044HIGH 8.8
A SQL injection flaw in pgAdmin 4 allows an authenticated user to break out of database description fields by injecting a single quote, then execute arbitrary SQL commands. The vulnerability exists across 16 template locations where user-supplied descriptions are rendered directly into SQL without proper escaping—in dialogs for Domains, Foreign Tables, Languages, Event Triggers, and Views. An attacker with superuser or similar elevated database roles could escalate further to run OS commands on the PostgreSQL host. However, the flaw does not grant new database access; it only bypasses application-layer controls a DBA may have configured to restrict direct SQL execution.
- CVE-2026-12059HIGH 8.8
CelloOS, a system developed by Cellopoint, contains a flaw in its SSH service that allows authorized users to break free from command restrictions and run arbitrary operating system commands they shouldn't have access to. An attacker with valid credentials can exploit this to escalate privileges or gain broader system control than their account should permit.
- CVE-2026-12158HIGH 8.8
The RegistrationMagic plugin for WordPress has a cross-site request forgery (CSRF) vulnerability affecting all versions through 6.0.9.1. An attacker can craft a malicious link or automation task that, when clicked by a site administrator, escalates an arbitrary user's privileges to administrator level without the admin's knowledge or consent. The attack exploits insufficient protection against forged requests in the plugin's form processing function.
- CVE-2026-12161HIGH 8.8
A vulnerability in Devolutions Remote Desktop Manager's SSH Elevate Shell feature allows authenticated users to bypass input validation and execute arbitrary commands on remote SSH hosts. An attacker with permission to create or modify shared SSH entries can craft a malicious alternate username that, when combined with user interaction to trigger the Elevate Shell action, will execute unauthorized commands using the stored elevation credentials. This is a post-authentication attack that leverages credential misuse within the application's own features.
- CVE-2026-12165HIGH 8.8
The Contest Gallery WordPress plugin contains a privilege escalation flaw affecting versions up to 30.0.2. A contributor-level user can manipulate a plugin setting to trick the system into promoting their Google sign-in account to administrator. The vulnerability exists because the plugin grants access to its admin pages at a low capability level (allowing contributors through) but fails to validate that a critical user role setting stays within safe bounds. Once changed, any new Google account signing in via that setting gets those elevated permissions.
- CVE-2026-12174HIGH 8.8
D-Link DCS-935L cameras running firmware version 1.10.01 contain a format string vulnerability in their web interface. An attacker with valid login credentials can send specially crafted requests to a specific CGI handler to read sensitive memory, modify system behavior, or execute code on the device. The vulnerability requires authentication but offers no other barriers; it can be exploited over the network without user interaction.
- CVE-2026-12186HIGH 8.8
GL.iNet's GL-MT3000 router contains a command injection vulnerability in its Tor proxy configuration feature. An authenticated attacker can manipulate the replace_country function to execute arbitrary system commands remotely. The vendor has released version 4.7 as a fix. This is a serious issue affecting routers running versions up to 4.4.5, though it requires valid login credentials to exploit.
- CVE-2026-12187HIGH 8.8
GL.iNet GL-MT3000 routers running firmware versions up to 4.4.5 contain a command injection vulnerability in the online firmware upgrade mechanism. An authenticated attacker can exploit this flaw to execute arbitrary commands on the device with full system privileges. The vulnerability has been publicly disclosed and proof-of-concept code is available, increasing the risk of active exploitation. GL.iNet has released a patch in version 4.7 that resolves the issue.
- CVE-2026-12192HIGH 8.8
GALAYOU Y4 version 1.0.0 contains a buffer overflow vulnerability in its web server component that allows attackers on the same local network to crash the service or potentially execute code with full system privileges. No user interaction is required to trigger the vulnerability, and exploit code has already been made public. The vendor has not responded to early disclosure attempts, leaving affected users without an official patch path.
- CVE-2026-12224HIGH 8.8
The Dokan Pro WordPress plugin contains a privilege escalation vulnerability in its REST API endpoint for managing user capabilities. An authenticated user with Vendor-level access can manipulate the update_capabilities endpoint to assign administrator privileges to staff accounts without restriction, effectively gaining full control of the WordPress site. The vulnerability affects all versions through 5.0.4 and requires the Vendor Staff module to be active.
- CVE-2026-12242HIGH 8.8
A WordPress plugin called AdRotate Banner Manager contains a code injection flaw that allows attackers with basic publishing privileges to run malicious code on websites. The vulnerability exists in how the plugin processes shortcode attributes when certain caching tools are active. An authenticated attacker—someone with a Contributor account or higher—can exploit this to take control of the server and steal data, modify content, or disrupt operations.
- CVE-2026-12244HIGH 8.8
NSD, the authoritative DNS server from NLnet Labs, contains a critical vulnerability in how it processes zone transfers from a primary DNS server. When configured as a secondary server, NSD can be crashed and potentially exploited for remote code execution if an attacker controls the primary server and sends a specially crafted DNS SVCB record during a zone transfer. The vulnerability stems from an integer overflow in a variable used to allocate memory for the record, allowing an attacker to write up to 65,509 bytes to heap memory.
- CVE-2026-12289HIGH 8.8
A privilege escalation vulnerability exists in Firefox and Thunderbird's WebRender graphics component. An attacker can exploit this through a malicious webpage to gain elevated privileges on a user's system. The vulnerability requires user interaction (visiting a crafted site) but needs no authentication and can be triggered remotely over the network. The impact is severe—an attacker could read sensitive files, modify system data, or execute arbitrary code with higher-level access.
- CVE-2026-12291HIGH 8.8
CVE-2026-12291 is a use-after-free vulnerability in Firefox and Thunderbird's HTTP networking component. When a browser or email client processes certain HTTP interactions, freed memory can be incorrectly accessed, allowing an attacker to execute arbitrary code on the user's system. The vulnerability requires user interaction—such as clicking a malicious link or visiting a compromised website—but does not require any special system privileges. An attacker with network access can deliver the exploit to any user.
- CVE-2026-12407HIGH 8.8
The E2Pdf plugin for WordPress contains a privilege escalation vulnerability that allows authenticated users with a specific custom role to become administrators. The flaw exists in how the plugin handles screen options updates—it fails to properly verify user permissions and validate input, allowing attackers to modify critical WordPress settings like the default user role. An administrator must have explicitly granted the attacker's role the 'e2pdf_templates' capability for this to be exploitable, but the plugin itself allows administrators to assign this capability to any role, including Subscriber or Contributor.
- CVE-2026-12439HIGH 8.8
Google Chrome contains a use-after-free vulnerability in its Digital Credentials component that could allow an attacker to corrupt heap memory and potentially execute arbitrary code. The flaw requires user interaction—specifically, visiting a specially crafted webpage—but poses a critical risk because it affects a widely deployed browser across multiple operating systems. Users running Chrome versions prior to 149.0.7827.155 are at risk.
- CVE-2026-12441HIGH 8.8
A use-after-free vulnerability exists in Google Chrome's file input handling on Linux systems. An attacker can craft a malicious HTML page that, when visited by a user, exploits this memory safety flaw to corrupt the browser's heap and potentially execute arbitrary code. The vulnerability affects Chrome versions prior to 149.0.7827.155 and requires user interaction (clicking or interacting with the page).
- CVE-2026-12442HIGH 8.8
A use-after-free flaw in Google Chrome's password handling on Android allows remote attackers to run malicious code on a victim's device. An attacker could craft a deceptive HTML page that, when visited by an Android user, exploits freed memory in Chrome's password system to gain arbitrary code execution. This is a critical-severity bug that requires user interaction—the victim must visit the malicious page—but once triggered, can fully compromise the device.
- CVE-2026-12443HIGH 8.8
A use-after-free vulnerability in Google Chrome's Web Authentication subsystem allows attackers to execute arbitrary code by tricking users into visiting a malicious website. The flaw affects Chrome versions before 149.0.7827.155 across Windows, macOS, and Linux. An attacker would need to craft a deceptive HTML page and convince a user to visit it; successful exploitation grants the attacker the same privileges as the compromised browser process.
- CVE-2026-12447HIGH 8.8
A vulnerability in Google Chrome's WebRTC component allows attackers to crash the browser or run malicious code within Chrome's sandbox protection by tricking users into visiting a specially crafted website. The attack requires user interaction—specifically, a user must open or be redirected to the malicious page—but no special privileges are needed on the target system. While the code execution is limited to the Chrome sandbox environment, successful exploitation could still enable data theft or further system compromise.
- CVE-2026-12448HIGH 8.8
A weakness in Google Chrome's WebView component on Android devices allows attackers to trick users into visiting a specially crafted webpage that can escape the security boundaries of the browser and gain elevated privileges on the device. This is a remote attack that requires user interaction—the victim must click a link or visit a malicious site—but once triggered, it bypasses normal Android permission models. The vulnerability affects Chrome versions prior to 149.0.7827.155.
- CVE-2026-12452HIGH 8.8
A use-after-free memory flaw in Google Chrome's Downloads feature on Android devices allows an attacker to corrupt heap memory and potentially take control of your browser by getting you to visit a malicious website. No special user permissions or browser configuration is required—the vulnerability triggers automatically when you land on a crafted page. The issue is confirmed fixed in Chrome version 149.0.7827.155 and later.
- CVE-2026-12466HIGH 8.8
A memory safety flaw in Chrome's WebRTC component allows attackers to run malicious code on Windows machines. An attacker can craft a deceptive webpage that, when visited by an unaware user, exploits the heap buffer overflow to gain control of the browser process. This is a remote attack requiring only that a user click or visit a malicious link—no special permissions or prior system compromise needed.
- CVE-2026-12806HIGH 8.8
A buffer overflow vulnerability affects Edimax BR-6478AC V2 running firmware version 1.23. The flaw exists in a wireless site survey function accessible via HTTP POST requests and can be exploited by an authenticated attacker to corrupt memory and potentially execute arbitrary code on the router. The vendor has not responded to early disclosure attempts, and proof-of-concept details are now public, elevating the risk posture for exposed instances.
- CVE-2026-12856HIGH 8.8
A security flaw in the vscode-java extension allows attackers to execute arbitrary commands through specially crafted JavaDoc popups. When a developer clicks a malicious link embedded in a JavaDoc hover tooltip, the extension runs whatever VS Code command the attacker specifies. In trusted workspaces, this can escalate to full system compromise. The attack requires user interaction—clicking the link—but no special credentials or complex setup.
- CVE-2026-13026HIGH 8.8
A use-after-free flaw in Chrome's Digital Credentials feature on macOS could let an attacker trick a user into visiting a malicious webpage, potentially corrupting Chrome's memory and achieving arbitrary code execution. The vulnerability affects Chrome versions before 149.0.7827.197 on Apple's macOS platform.
- CVE-2026-13027HIGH 8.8
A use-after-free vulnerability in Google Chrome's FileSystem component allows attackers to corrupt memory and potentially execute arbitrary code when a user visits a malicious website. The flaw affects Chrome versions before 149.0.7827.197 across Windows, macOS, and Linux systems. Exploitation requires user interaction—specifically visiting a crafted HTML page—but once triggered, the vulnerability can lead to complete system compromise.
- CVE-2026-13031HIGH 8.8
A use-after-free memory vulnerability exists in Chrome's Blink rendering engine that could allow an attacker to run malicious code within Chrome's sandbox by tricking a user into visiting a specially crafted website. The flaw affects Chrome versions before 149.0.7827.197 and impacts users across Windows, macOS, and Linux systems.
- CVE-2026-13033HIGH 8.8
A memory safety vulnerability in Google Chrome's interest groups feature allows attackers to read and write data outside intended memory boundaries. An attacker can craft a malicious HTML page that, when visited by a user, triggers the flaw to execute arbitrary code on the victim's machine. The vulnerability affects Chrome versions before 149.0.7827.197 and is classified as critical by Chrome's security team.
- CVE-2026-13035HIGH 8.8
A use-after-free vulnerability in Chrome's Bluetooth implementation on macOS allows an attacker to execute arbitrary code on a victim's computer. The flaw requires user interaction—specifically, a user must connect to or interact with a malicious Bluetooth peripheral—but once triggered, it grants the attacker full control over the affected system. This is a remote code execution (RCE) risk that bypasses Chrome's sandbox protections.
- CVE-2026-13036HIGH 8.8
A use-after-free memory vulnerability exists in Google Chrome's Blink rendering engine that allows remote attackers to execute arbitrary code within the browser's sandbox. The flaw requires user interaction—specifically opening a malicious HTML page—but poses a direct threat to confidentiality, integrity, and availability once triggered. Attackers can escape the sandbox's execution context and potentially gain control over the affected system.
- CVE-2026-13038HIGH 8.8
Google Chrome on Windows contains a use-after-free memory vulnerability in its Autofill feature that allows attackers to execute arbitrary code on a user's system. An attacker can craft a malicious HTML page that, when visited by a Chrome user, triggers memory corruption in the Autofill subsystem. Because the vulnerability requires only user interaction (visiting a webpage) and no special privileges, it presents a high bar for exploitation chains and a significant risk to Chrome users. The vulnerability affects Chrome versions prior to 149.0.7827.197 on Windows.
- CVE-2026-13125HIGH 8.8
GeoWebPlayer, a browser plugin component used by GeoVision's video management software suite (GV-VMS, GV-Cloud), operates a websocket server that lacks any authentication mechanism. This means any website you visit can attempt to connect to that server and request sensitive operations—including retrieving live screenshots of your screen without your knowledge or consent. The vulnerability requires user interaction (visiting a malicious site), but once triggered, an attacker gains unauthorized access to screen capture functionality and other privileged APIs.
- CVE-2026-13228HIGH 8.8
The LatePoint appointment booking plugin for WordPress contains a privilege escalation flaw that allows agents and staff members with lower-level access to become administrators. An authenticated agent can manipulate customer records to overwrite an administrator's email address, then exploit a missing security check to log in as that administrator. This requires existing access to the plugin but no special interaction from victims.
- CVE-2026-13492HIGH 8.8
The UsersWP WordPress plugin contains a file deletion flaw affecting versions up to 1.2.65. Attackers with basic user accounts (Subscriber level or higher) can delete arbitrary files from the web server, including critical WordPress configuration files. The vulnerability exists because the plugin fails to properly validate and restrict file paths during deletion operations, allowing directory-traversal tricks like `../../../` sequences to escape the intended uploads directory and target sensitive system files.
- CVE-2026-13515HIGH 8.8
Tenda JD12L router version 16.03.53.23 contains a stack-based buffer overflow vulnerability in its PPTP server configuration function. An authenticated attacker can exploit this flaw by sending a specially crafted request with an oversized startIp parameter, potentially causing the application to crash or allowing arbitrary code execution. The vulnerability is reachable over the network and has been publicly disclosed.
- CVE-2026-13516HIGH 8.8
Tenda JD12L routers running firmware version 16.03.53.23 contain a stack-based buffer overflow vulnerability in the guest Wi-Fi configuration function. An authenticated attacker can exploit this by sending a specially crafted request to manipulate the 'shareSpeed' parameter, potentially allowing arbitrary code execution or device compromise. Public exploit code is available, elevating the practical risk.
- CVE-2026-13517HIGH 8.8
A stack-based buffer overflow vulnerability exists in Tenda JD12L firmware version 16.03.53.23. An authenticated remote attacker can exploit this flaw by sending a specially crafted request to the Wi-Fi configuration endpoint, potentially allowing them to execute arbitrary code or crash the device. The vulnerability affects the security_5g parameter handling in the Wi-Fi basic settings function. Public exploit code is available, increasing the practical risk of exploitation.
- CVE-2026-13518HIGH 8.8
Tenda JD12L routers running firmware version 16.03.53.23 contain a stack-based buffer overflow vulnerability in the network address translation (NAT) settings interface. An authenticated attacker can overflow a buffer by sending a specially crafted request to the `/goform/addressNat` endpoint with a malicious `page` parameter, leading to code execution on the device. The vulnerability requires valid login credentials but poses a significant risk because exploitation is straightforward and public proof-of-concept code is available.
- CVE-2026-13519HIGH 8.8
A stack-based buffer overflow vulnerability exists in Tenda JD12L routers running firmware version 16.03.53.23. An authenticated attacker can trigger the overflow by sending a specially crafted request to the NAT Static Setting function, potentially allowing them to execute arbitrary code or crash the device. Public exploit code is available, increasing the practical risk.
- CVE-2026-13539HIGH 8.8
A stack-based buffer overflow vulnerability exists in Wavlink WL-NU516U1-A routers running firmware M16U1_V240425. An authenticated attacker can send a malicious POST request to the wireless configuration endpoint with an oversized Guest_ssid parameter, causing the application to write beyond allocated memory. This memory corruption can lead to unauthorized access, data theft, or complete device compromise. The vulnerability is remotely exploitable and public exploits are available, though the vendor has released a patched firmware version.
- CVE-2026-13545HIGH 8.8
D-Link DCS-935L network cameras running firmware version 1.10.01 contain a critical flaw in their web configuration interface. An authenticated attacker can inject arbitrary operating system commands through the UID parameter in the setconf.cgi handler, gaining the ability to execute code with the privileges of the camera process. Because the vulnerability requires authentication but offers full system compromise once inside, it represents a high-severity risk for organizations relying on these devices for surveillance infrastructure.
- CVE-2026-13562HIGH 8.8
A buffer overflow vulnerability has been discovered in Edimax EW-7478APC wireless extender running firmware version 1.04. An authenticated attacker can exploit this flaw by sending a specially crafted request to the device's web interface, specifically by manipulating the selSSID parameter in the NIC site survey function. Successful exploitation allows the attacker to execute arbitrary code with full device privileges, potentially compromising network traffic and allowing lateral movement into the network.
- CVE-2026-13563HIGH 8.8
A stack-based buffer overflow vulnerability exists in Edimax EW-7478APC wireless extender firmware version 1.04. The vulnerability is triggered when an attacker sends a specially crafted POST request to the L2TP setup endpoint, with an oversized username parameter that overwrites the call stack. An authenticated attacker can exploit this remotely to execute arbitrary code or crash the device. The vendor has not responded to early disclosure attempts, and the vulnerability details are now public.
- CVE-2026-13564HIGH 8.8
A stack-based buffer overflow vulnerability exists in Edimax EW-7478APC wireless access point model running firmware version 1.04. An authenticated remote attacker can exploit this flaw by sending a specially crafted POST request with an oversized username parameter to the PPPoE setup interface, allowing them to execute arbitrary code with full system privileges. Public exploit code is available, elevating the practical risk.
- CVE-2026-13580HIGH 8.8
A buffer overflow vulnerability exists in Edimax EW-7478APC wireless access point (firmware 1.04) that allows an authenticated attacker to crash the device or execute arbitrary code. The flaw resides in the QoS configuration endpoint and can be triggered by sending a specially crafted POST request with an oversized value in the selSSID parameter. An attacker with valid login credentials can exploit this remotely without user interaction.
- CVE-2026-13582HIGH 8.8
A buffer overflow vulnerability exists in Edimax EW-7478APC wireless access point firmware version 1.04. An authenticated attacker can send a specially crafted network request to the device's USB account management function, causing a memory overflow that leads to code execution with full device privileges. Public exploit code is available, and the vendor has not responded to responsible disclosure attempts, leaving affected devices at active risk.
- CVE-2026-13583HIGH 8.8
A buffer overflow vulnerability exists in Edimax EW-7478APC wireless access point (version 1.04) that allows authenticated attackers to crash the device or potentially execute arbitrary code. The flaw is in how the device processes user-supplied input when handling USB folder sharing requests. Because exploit code has already been released publicly and the vendor has not provided a patch despite early notification, the risk is elevated. Attackers who can log into the device can trigger this vulnerability remotely without user interaction.
- CVE-2026-13696HIGH 8.8
HAVELSAN Inc. Liman MYS contains an LDAP injection vulnerability that allows authenticated users to manipulate LDAP queries through improperly sanitized input. An attacker with valid credentials can craft malicious LDAP queries to bypass authentication controls, extract sensitive directory information, or modify directory objects. This is a logic flaw in how the application constructs LDAP search filters, leaving it vulnerable to query manipulation attacks similar to SQL injection but targeting directory services.
- CVE-2026-13706HIGH 8.8
A flaw in Wikimedia Foundation's UrlShortener component fails to properly validate user input, allowing authenticated users to cause significant harm. An attacker with login credentials can exploit this weakness to read sensitive data, alter information, or disrupt service availability. The vulnerability resides in the UrlShortenerUtils.php file and affects MediaWiki deployments.
- CVE-2026-13749HIGH 8.8
A vulnerability in Snowflake CLI versions before 3.19 allows attackers to run arbitrary code on a developer's machine during application bundling or deployment. An attacker can craft malicious project files that, when processed by the CLI, execute code with the privileges of the user running the tool. The attack requires the victim to run the bundling or deployment workflow against attacker-controlled content, making it effective in supply-chain or social-engineering scenarios where developers are tricked into processing untrusted project materials.
- CVE-2026-13777HIGH 8.8
Google Chrome on iOS contains a vulnerability that allows attackers to trigger heap memory corruption by tricking users into visiting a malicious webpage. The flaw stems from Chrome's iOSWeb component failing to properly validate user-supplied input before processing it. An attacker would need to craft a specially designed HTML page and convince a user to visit it; the user's device would then be at risk of compromise. Chrome versions before 150.0.7871.47 are vulnerable on iOS.
- CVE-2026-13783HIGH 8.8
A use-after-free memory vulnerability exists in Google Chrome's Views component that could allow an attacker to corrupt the heap memory of an affected system. The vulnerability requires a user to visit a malicious website and perform specific UI interactions, such as clicking or gesturing within the page. If exploited successfully, an attacker could read sensitive data, modify system behavior, or crash the application. This is a memory safety issue—a category of bugs that remains a persistent challenge in browser security.
- CVE-2026-13784HIGH 8.8
A use-after-free vulnerability exists in Google Chrome's Views component that could allow an attacker to corrupt browser memory. The flaw requires user interaction—specifically, the victim must perform certain UI gestures (like clicking, dragging, or other interface actions) while visiting a malicious webpage. If successfully exploited, this could lead to a complete compromise of the user's browser, potentially affecting data confidentiality, integrity, and availability. Chrome versions prior to 150.0.7871.47 are affected.
- CVE-2026-13786HIGH 8.8
A memory safety flaw in Google Chrome's Ozone subsystem allows attackers to execute arbitrary code on a victim's computer by hosting a malicious website. When a user visits the compromised site, the browser processes a specially crafted HTML page that triggers a use-after-free condition—essentially allowing code to operate on memory that has already been freed. This results in complete system compromise. The vulnerability requires user interaction (visiting a malicious page) but no special privileges, and affects Chrome versions prior to 150.0.7871.47.
- CVE-2026-13788HIGH 8.8
A use-after-free memory flaw in Google Chrome's fullscreen feature on Android allows attackers to run arbitrary code by tricking users into visiting a malicious webpage. This is a memory safety issue where the browser attempts to access memory that has already been freed, creating an opening for code execution. The flaw affects Android devices running Chrome versions prior to 150.0.7871.47.
- CVE-2026-13805HIGH 8.8
A use-after-free vulnerability exists in Google Chrome's graphics rendering engine (GFX) on macOS. An attacker can exploit this by hosting a malicious website; when a user visits the page, Chrome crashes in a way that allows the attacker to run arbitrary code with the privileges of the Chrome process. This affects Chrome versions prior to 150.0.7871.47 on Mac systems.
- CVE-2026-13811HIGH 8.8
Google Chrome versions before 150.0.7871.47 contain a use-after-free vulnerability in the Input Method Editor (IME) component that can be exploited when a user visits a malicious webpage. An attacker could leverage this flaw to execute arbitrary code within Chrome's sandbox environment, potentially leading to system compromise. The vulnerability requires user interaction (visiting a crafted page) but does not require elevated privileges to trigger.
- CVE-2026-13815HIGH 8.8
A use-after-free vulnerability exists in Google Chrome's Blink rendering engine that allows attackers to execute arbitrary code within the browser sandbox by tricking users into viewing a malicious webpage. No special privileges or complex user interaction beyond opening a link are required for exploitation.
- CVE-2026-13817HIGH 8.8
A flaw in Chrome's Glic component fails to properly validate user-supplied input before processing it. This weakness allows an attacker to craft a malicious HTML page that, when visited, could break out of Chrome's sandbox—the security boundary that isolates the browser from the underlying operating system. If successful, an attacker gains the ability to execute arbitrary code with the same privileges as the user running Chrome, potentially compromising the entire system.
- CVE-2026-13821HIGH 8.8
A use-after-free memory bug in Google Chrome's Canvas rendering engine allows attackers to run malicious code within the browser's sandbox by tricking users into visiting a specially crafted webpage. No special privileges are required—any user viewing a malicious site can be compromised. The vulnerability affects Chrome versions before 150.0.7871.47 across Windows, macOS, and Linux systems.
- CVE-2026-13825HIGH 8.8
Google Chrome contains a flaw where certain memory in the browser's graphics component (Dawn) is not properly initialized before use. An attacker who crafts a malicious HTML page can trigger this condition and potentially corrupt the heap memory that Chrome relies on, leading to crashes or, in the worst case, arbitrary code execution. The vulnerability requires user interaction—the victim must visit the malicious page—but once they do, the attack executes with no additional privileges needed.
- CVE-2026-13830HIGH 8.8
A use-after-free vulnerability in Google Chrome's Chromoting feature on Linux allows an attacker on the same network to remotely execute arbitrary code without user interaction. An attacker would need to send malicious network traffic to trigger the flaw, which resides in memory management of the Chromoting subsystem. This is a particularly dangerous class of vulnerability because it gives an attacker direct code execution capability on an affected system.
- CVE-2026-13835HIGH 8.8
Google Chrome versions prior to 150.0.7871.47 contain a flaw in how the browser processes XML within HTML pages. An attacker can craft a malicious web page that, when visited by a user, exploits this flaw to corrupt the browser's memory heap. This type of corruption can lead to complete compromise of the affected system—including theft of sensitive data, installation of malware, or loss of system control. The vulnerability requires user interaction (visiting a malicious site) but is otherwise straightforward to exploit.
- CVE-2026-13845HIGH 8.8
Google Chrome versions prior to 150.0.7871.47 contain a use-after-free vulnerability in the DOM (Document Object Model) that could allow an attacker to run arbitrary code within the browser's sandbox by tricking a user into visiting a specially crafted webpage. This is a memory safety issue where Chrome continues to reference DOM objects after they have been freed, creating a window for code execution. The vulnerability requires user interaction—specifically visiting a malicious site—but carries high risk once triggered.
- CVE-2026-13848HIGH 8.8
A use-after-free memory flaw in Google Chrome's form handling allows attackers to run malicious code within the browser's sandbox by tricking users into visiting a specially crafted website. The vulnerability affects Chrome versions prior to 150.0.7871.47 across Windows, macOS, and Linux. While the code executes in a sandbox—which limits what an attacker can directly access on the system—the sandbox itself isn't impenetrable, and successful exploitation could lead to full browser compromise or escalation of privileges.
- CVE-2026-13850HIGH 8.8
Google Chrome on iOS versions before 150.0.7871.47 contain a flaw that fails to properly validate user-supplied input when handling files. A local attacker could craft a malicious file that, when opened in Chrome on iOS, would execute arbitrary code within the browser's sandbox. While sandboxing limits the scope of potential damage, successful exploitation could allow an attacker to run malicious code on an affected device.