2026 · High
High-severity vulnerabilities disclosed in 2026
High-rated CVEs published in 2026, with SEC.co remediation and prioritization guidance.
4140 published vulnerabilities · page 26 of 42
- CVE-2025-60474HIGH 7.5
A buffer overflow vulnerability in GPAC Project's MP4Box media processing tool can crash the application when given a specially crafted input file. While attackers cannot steal data or modify files through this flaw, they can disrupt services that rely on MP4Box for media processing. The vulnerability affects versions before 26.02.0 and requires no authentication or user interaction beyond supplying the malicious file.
- CVE-2025-61018HIGH 7.5
Openlink Virtuoso Open Source version 7.2.11 contains a vulnerability in its SQL processing component (sqlo_place_dt_set) that allows remote attackers to disrupt database service by submitting specially crafted SQL statements. No authentication is required to exploit this weakness, making it accessible to unauthenticated network users. The attack causes a denial of service condition, rendering the database unavailable to legitimate users.
- CVE-2025-61019HIGH 7.5
Openlink Virtuoso Open Source version 7.2.11 contains a vulnerability in its SQL query optimization component that allows remote attackers to crash the database server by sending specially crafted SQL statements. No authentication is required, and the attack can be executed over the network. This is a pure availability issue—attackers cannot steal data or modify the database, but they can disrupt service for all legitimate users.
- CVE-2025-61020HIGH 7.5
A vulnerability exists in Openlink Virtuoso Open Source (version 7.2.11) that allows attackers to crash the database service by sending specially crafted SQL queries. An attacker with network access can exploit this without authentication, causing the application to become unavailable. This is a denial-of-service issue affecting the component responsible for handling JOIN statements in SQL parsing.
- CVE-2025-61021HIGH 7.5
OpenLink Virtuoso Open Source versions up to 7.2.11 contain a vulnerability in the SQL query optimizer (specifically the sqlo_natural_join_cond component) that allows remote attackers to crash the database server by submitting carefully crafted SQL statements. No authentication is required to exploit this issue, and successful attacks result in service unavailability rather than data theft or corruption.
- CVE-2025-61022HIGH 7.5
Openlink Virtuoso Open Source v7.2.11 contains a vulnerability in its SQL query optimizer that allows remote attackers to crash the database server by submitting specially crafted SQL statements. No authentication is required to trigger this issue, and the attacker gains no access to data—the sole impact is service unavailability. This is a network-accessible denial-of-service flaw affecting the core database query processing logic.
- CVE-2025-61023HIGH 7.5
Openlink Virtuoso Open Source version 7.2.11 contains a flaw in its SQL comparison component that allows remote attackers to crash the database server by sending specially crafted SQL queries. No authentication is required, and the attack can be executed over the network. The vulnerability does not compromise data confidentiality or integrity—it purely denies service availability.
- CVE-2025-61024HIGH 7.5
Openlink Virtuoso Open Source version 7.2.11 contains a flaw in how it processes certain SQL loop constructs that allows an attacker to craft malicious SQL statements and crash the database service, making it unavailable to legitimate users. No authentication is required to exploit this vulnerability, and it can be triggered over the network.
- CVE-2025-61025HIGH 7.5
OpenLink Virtuoso Open Source version 7.2.11 contains a vulnerability in its SQL query parsing component (sslr_qst_get) that allows remote attackers to crash the database server without authentication. By sending specially crafted SQL statements over the network, an attacker can trigger a denial of service condition, making the database unavailable to legitimate users. No special privileges or user interaction are required to exploit this flaw.
- CVE-2025-61027HIGH 7.5
OpenLink Virtuoso Open Source version 7.2.11 contains a vulnerability in its t_set_push component that allows remote attackers to crash the database server by sending specially crafted SQL statements. No authentication is required to exploit this issue, making it accessible to any network-connected user. The attack results in denial of service, preventing legitimate users from accessing the database until the server is restarted.
- CVE-2025-61028HIGH 7.5
OpenLink Virtuoso Open Source version 7.2.11 contains a vulnerability in its time_t_to_dt component that allows remote attackers to crash the database server by sending specially crafted SQL statements. No authentication is required to trigger the issue, and successful exploitation results in a denial of service condition affecting database availability.
- CVE-2025-61029HIGH 7.5
CVE-2025-61029 is a denial-of-service vulnerability in OpenLink Virtuoso Open Source version 7.2.11. An attacker can craft malicious SQL statements that crash or hang the database server, making it unavailable to legitimate users. The attack requires no authentication and can be executed over the network, making it a practical threat to exposed instances.
- CVE-2025-63579HIGH 7.5
A vulnerability in Kyocera's multifunction printers and their Command Center RX management system allows attackers to bypass encryption protections and extract sensitive data without requiring authentication. An attacker with network access can export all contacts stored in the device's address book, decrypt previously encrypted communications, and obtain stored passwords and credentials. This represents a direct path to credential theft and reconnaissance against organizations relying on these devices for document management.
- CVE-2025-66389HIGH 7.5
GitHub Copilot version 1.372.0 contains a security flaw that allows the AI assistant to access files outside the workspace folder without explicit user permission. An attacker could potentially exploit this through indirect prompt injection—feeding malicious instructions into Copilot through compromised or attacker-controlled text—to read sensitive files on the user's system and exfiltrate their contents. The vulnerability stems from improper validation of file-handler URI parameters passed to the fetch_webpage function.
- CVE-2025-68063HIGH 7.5
A local file inclusion vulnerability exists in the Splash WordPress theme (versions 4.4.3 and earlier) used for sports club websites. An authenticated contributor-level user can craft requests to read sensitive files from the server, potentially exposing configuration data, database credentials, or other protected content. This requires an attacker to have valid contributor access to the WordPress site, limiting exposure to internal threats or compromised user accounts.
- CVE-2025-69131HIGH 7.5
A critical flaw in the WordPress & WooCommerce Scraper Plugin (versions 1.0.7 and earlier) allows attackers to download arbitrary files from affected servers without authentication. An attacker can exploit this remotely by making a specially crafted request, potentially exposing sensitive data such as configuration files, database backups, or other confidential information stored on the web server.
- CVE-2025-69134HIGH 7.5
A vulnerability in the OpenAI Chatbot for WordPress – Helper plugin (versions 1.1.4 and earlier) allows attackers to delete content from WordPress sites without needing to log in or provide any credentials. An attacker can remotely trigger deletion of arbitrary site content by sending specially crafted requests, potentially causing significant disruption to website availability and integrity.
- CVE-2025-70099HIGH 7.5
A vulnerability in the lwext4 library (version 1.0.0) can crash applications that process specially crafted EXT4 filesystem images. The flaw occurs when the code attempts to read file information from a corrupted directory entry without first verifying the entry pointer exists. An attacker could provide a malicious filesystem image to trigger this crash, disrupting service availability. This is a denial-of-service issue with no data theft or system compromise risk.
- CVE-2025-70796HIGH 7.5
WTI (Wireless Technology, Inc.) version 3.5.0 released May 24, 2024 contains a path traversal flaw in its web management interface that does not require authentication to exploit. An attacker can send crafted HTTP requests with directory traversal sequences (such as '../' patterns) to read files outside the intended web root, potentially exposing sensitive system files, configuration data, credentials, and other confidential information. The vulnerability is remotely exploitable over the network with no special access or user interaction required.
- CVE-2025-71319HIGH 7.5
The image-size npm package through version 2.0.2 contains a vulnerability that allows attackers to crash Node.js applications by sending specially crafted image files. When the package processes JXL or HEIF format images containing a box with a zero-valued size field, it enters an infinite loop that permanently blocks the application's event loop, causing a complete denial of service. No authentication or user interaction is required to exploit this issue—an attacker simply needs to send a malicious image to a vulnerable application.
- CVE-2025-71324HIGH 7.5
Flowise, an open-source platform for building conversational AI applications, contains a flaw that allows unauthenticated attackers to read files from the server hosting it. The vulnerability exists in file-download endpoints that accept a chatId parameter without properly validating or restricting where files can be retrieved from. An attacker can manipulate this parameter to escape the intended storage directory and access sensitive files elsewhere on the system—most critically, the application's SQLite database, which contains user credentials, conversation histories, and other sensitive data. No user interaction or authentication is required to exploit this.
- CVE-2025-71329HIGH 7.5
The image-size Node.js library versions up to 2.0.2 contain a vulnerability that allows an attacker to crash applications by sending a specially crafted image file. The attacker exploits how the library processes certain image formats (JXL and HEIF) by creating a box structure with a size field set to zero. This causes the parser to enter an infinite loop, freezing the application's event loop indefinitely. The attack requires no authentication and can be triggered remotely by any user who can send an image to an affected application.
- CVE-2025-71330HIGH 7.5
The image-size Node.js library through version 2.0.2 contains a denial-of-service flaw that allows attackers to freeze an application's event loop indefinitely. By sending a maliciously crafted ICNS image file with specific properties—valid header signature but a zero-length entry field—an attacker can cause the parser to spin in an endless loop, rendering the application unresponsive. No authentication is required, and the attack succeeds over the network against any system processing untrusted ICNS image data.
- CVE-2025-8873HIGH 7.5
A flaw in Arista EOS can be triggered by a specially crafted network packet when IPsec is enabled, causing the system to stop forwarding all IPsec-protected traffic. While the control plane may attempt to recover and restart IPsec processing, traffic flow may not resume afterward. Non-IPsec traffic and IPsec sessions not local to the affected device remain unaffected. An Arista customer first reported this issue.
- CVE-2026-0156HIGH 7.5
CVE-2026-0156 is a memory safety flaw in Android's RTP (Real-time Transport Protocol) session handling that allows an attacker to crash or disrupt media streaming without authentication. The vulnerability exists in the collision-detection code that processes incoming RTP packets; a missing validation check can cause the system to attempt operations on a null pointer, triggering a denial-of-service condition. An attacker on the network can exploit this remotely by sending specially crafted RTP traffic.
- CVE-2026-0270HIGH 7.5
Palo Alto Networks Cortex XSOAR running on Linux contains a flaw that lets an attacker on the same network write files to the server if they can intercept and modify network traffic in transit. The vulnerability requires the attacker to be positioned to perform a man-in-the-middle attack, but once they are, they can exploit the path traversal weakness to place arbitrary files on the host system. This is a significant risk in environments where XSOAR is exposed to untrusted network segments or where network security controls may be incomplete.
- CVE-2026-0287HIGH 7.5
Palo Alto Networks PAN-OS firewalls contain multiple denial of service vulnerabilities that allow unauthenticated attackers on the network to crash the firewall by sending specially crafted traffic through dataplane interfaces. Repeating this attack forces the firewall into maintenance mode, effectively taking it offline. Panorama management systems are not affected. This is a network-accessible vulnerability requiring no authentication, making it a significant availability risk for organizations relying on these firewalls for critical security functions.
- CVE-2026-0288HIGH 7.5
Palo Alto Networks PAN-OS contains multiple buffer overflow flaws in the User-ID Terminal Server Agent (TSA) component that can be exploited over the network without authentication. An attacker can send malformed network traffic to trigger a denial of service or potentially run arbitrary code on affected firewalls. However, the risk is substantially reduced if you follow Palo Alto's deployment guidance and restrict TSA connectivity to trusted internal IP addresses only. Panorama appliances are not affected.
- CVE-2026-0828HIGH 7.5
Safetica's endpoint protection client contains a flaw in its kernel-level driver that allows unprivileged users to forcibly terminate system processes that should be protected. An attacker without elevated privileges can exploit this through direct driver communication (IOCTL calls) to shut down critical Windows processes, potentially disabling security features or system functionality. This vulnerability affects specific versions of Safetica's x64 endpoint client.
- CVE-2026-10003HIGH 7.5
A use-after-free vulnerability in Chrome's Views component allows attackers to execute arbitrary code on affected systems. The flaw requires user interaction—specifically, the victim must perform particular UI gestures after being convinced to visit a malicious webpage. Once triggered, the vulnerability grants the attacker the same privileges as the user running the browser, potentially leading to complete system compromise.
- CVE-2026-10005HIGH 7.5
Google Chrome on macOS contains a use-after-free vulnerability in its WebAppInstalls component that can be exploited to execute arbitrary code. An attacker would need to convince a user to perform specific gestures within a crafted HTML page to trigger the flaw. This affects Chrome versions prior to 148.0.7778.216.
- CVE-2026-10006HIGH 7.5
A race condition in Google Chrome's WebAudio component allows attackers to execute arbitrary code within the browser sandbox by serving a specially crafted HTML page to a user. The vulnerability requires user interaction (clicking or navigating to the malicious page) but does not require special privileges. Successfully exploiting this issue could allow an attacker to run code with the permissions of the Chrome process, potentially leading to data theft, malware installation, or further system compromise.
- CVE-2026-10009HIGH 7.5
A mathematical error in Chrome's graphics rendering engine (Skia) could allow attackers to break out of the browser sandbox and run malicious code if they've already compromised the browser's rendering process. The vulnerability affects Chrome versions before 148.0.7778.216 and requires user interaction, such as visiting a malicious webpage, to trigger the exploit.
- CVE-2026-10022HIGH 7.5
A type confusion flaw in Google Chrome's V8 JavaScript engine (CVE-2026-10022) allows attackers to execute arbitrary code within the browser sandbox if they can trick a user into installing a malicious Chrome extension. The vulnerability affects Chrome versions before 148.0.7778.216 and impacts Windows, macOS, and Linux systems. While the underlying Chromium severity is rated Medium by Google, the CVSS v3.1 score of 7.5 reflects the practical risk: an attacker gaining code execution inside the Chrome sandbox can read sensitive data, modify browser state, or escalate privileges. The attack requires social engineering to distribute the malicious extension, which limits opportunistic exploitation but remains a credible threat in targeted campaigns.
- CVE-2026-10044HIGH 7.5
Usagi-org's ai-goofish-monitor application contains a critical flaw that allows anyone on the network to read files from an affected Windows server without authentication. By crafting a specially-formed request to the GET /api/prompts/{filename} endpoint, an attacker can bypass the application's path-checking logic and access sensitive files stored on the system—such as configuration files, credentials, or other sensitive data accessible to the application process. The vulnerability exploits a weakness in how the application validates file paths, specifically by allowing absolute Windows paths and backslash characters that the incomplete validation routine fails to detect.
- CVE-2026-10056HIGH 7.5
Network Optix Nx Witness VMS contains a cross-origin resource sharing (CORS) misconfiguration in its REST API that allows an unauthenticated attacker to steal a logged-in user's session token and hijack their administrator account. The vulnerability exists only in the default Standard security mode on Linux and Windows systems running versions prior to 6.1.2. An attacker would craft a malicious web page and trick a victim into visiting it while authenticated to the VMS; the browser would then leak the session credentials to the attacker. The High security mode configuration is not affected by this flaw.
- CVE-2026-10069HIGH 7.5
A denial-of-service vulnerability exists in Shibby Tomato 1.28's miniupnpd service that allows unauthenticated attackers to exhaust system resources remotely. The flaw resides in an unspecified function within the UPnP daemon and can be triggered without special privileges or user interaction. While Shibby Tomato is no longer maintained (superseded by FreshTomato), organizations still running this legacy firmware remain at risk.
- CVE-2026-10073HIGH 7.5
DreamMaker, a product by Interinfo, contains a flaw that allows attackers to read arbitrary files from the system without authentication. An attacker can exploit a relative path traversal weakness to access sensitive system files they shouldn't be able to reach. This is a network-accessible vulnerability, meaning an attacker doesn't need physical access or prior system credentials to attempt exploitation.
- CVE-2026-10083HIGH 7.5
The APCu Manager WordPress plugin versions before 4.5.0 contain a stored cross-site scripting (XSS) vulnerability in the admin dashboard. An attacker can inject malicious JavaScript into cache keys that persist in the object cache. When an administrator visits the plugin's admin page, the unescaped cache keys execute JavaScript in their browser session, potentially compromising the administrator's account or WordPress installation.
- CVE-2026-10097HIGH 7.5
wolfSSL's optimized implementation of ML-KEM-1024, a post-quantum key encapsulation mechanism, contains a critical flaw in how it validates ciphertexts during decryption. The vulnerability stems from an incomplete cryptographic check: the library compares only 1536 of the required 1568 ciphertext bytes when verifying that a ciphertext was correctly re-encrypted. This allows an attacker to craft malicious ciphertexts that pass validation when they should be rejected. An attacker with access to a decapsulation oracle can exploit this as a side-channel-like oracle to recover the long-term private key—without needing to exploit timing behavior or other indirect measurements. A proof of concept demonstrated recovery of a full private key using roughly 350 carefully chosen ciphertexts, with approximately 98% success rate.
- CVE-2026-10108HIGH 7.5
xiaomusic version 0.5.7 contains an unauthenticated vulnerability that allows attackers to download files from anywhere on the server, not just the music directory. The flaw exists in how the application validates file paths when serving content. An attacker can craft special requests that bypass this validation to read sensitive files—such as configuration files, private keys, or application source code—without needing any credentials. The vulnerability affects any exposed xiaomusic instance running the affected version.
- CVE-2026-10142HIGH 7.5
kafka-python versions before 2.3.2 contain a denial-of-service flaw that allows attackers to crash or freeze Kafka client applications. By sending a malformed network message with an oversized frame length, an attacker positioned as a rogue broker or intercepting traffic can force the client to either allocate massive amounts of memory (potentially gigabytes) or encounter an error that leaves the connection broken. When this happens, consumer applications stop responding to heartbeat signals and become unresponsive until manually restarted.
- CVE-2026-10143HIGH 7.5
kafka-python versions before 2.3.2 contain a denial-of-service flaw in their SCRAM authentication mechanism. When connecting to a Kafka broker, the client accepts an iteration count from the broker without validation and passes it directly to a cryptographic hashing function. A malicious broker or attacker positioned between client and broker can send an extremely large iteration count, causing the client's event loop to freeze during authentication. This blocks all Kafka operations—producers cannot send messages, consumers cannot poll, admin commands fail, and heartbeats stop. Frozen clients are evicted from consumer groups and enter a cycle of reconnection failures, effectively denying service to applications relying on Kafka.
- CVE-2026-10512HIGH 7.5
A cryptographic error in WolfSSL's X25519 implementation can produce incorrect encryption keys. The vulnerability stems from incomplete mathematical reduction in the elliptic curve algorithm's final step, potentially leaving computed values in an invalid state. This could result in Diffie-Hellman key exchanges that don't match expectations, though the impact depends on how applications use the affected library and whether they validate results.
- CVE-2026-10621HIGH 7.5
Collibra Agent contains a path traversal vulnerability in its restore handler that allows attackers to write arbitrary files to a system by uploading a malicious ZIP archive. The vulnerability stems from insufficient validation of file paths during ZIP extraction, enabling an attacker to escape the intended extraction directory and place files anywhere on the system. No authentication is required to exploit this flaw.
- CVE-2026-10696HIGH 7.5
Devolutions UniGetUI, a package manager frontend, contains a flaw in how it matches installed applications to available updates. An attacker who contributes a malicious package to the WinGet community catalog can craft a package with a name that partially matches an existing installed application. When a user attempts to apply updates, UniGetUI may incorrectly associate the legitimate application with the attacker's malicious package and execute the attacker's installer instead. This affects version 2026.2.0 and earlier.
- CVE-2026-10699HIGH 7.5
Progress MOVEit Transfer's Custom Reports modules contain a memory leak vulnerability that can be exploited to exhaust system resources and cause the application to become unavailable. An attacker on the network can trigger this condition without authentication, leading to a denial of service. The issue affects specific versions released in 2025 and early 2026.
- CVE-2026-10701HIGH 7.5
Firefox's text rendering engine contains a flaw in how it validates memory boundaries when processing text data. An attacker on the network can exploit this without requiring user interaction or special permissions, allowing them to read sensitive information from the browser's memory. The vulnerability affects Firefox versions prior to 151.0.3.
- CVE-2026-10706HIGH 7.5
Adalo's no-code app builder (versions 1 and 2) contains a vulnerability that allows attackers to extract complete user records and track user behavior across multiple applications by exploiting database identifier (dbId) enumeration. The platform lacks fundamental privacy protections such as data minimization principles and privacy-by-design safeguards, enabling unauthorized access to sensitive user information.
- CVE-2026-10708HIGH 7.5
A vulnerability in Adalo applications allows attackers to extract sensitive user data—including email addresses, unique identifiers, and custom profile fields—from any Adalo-built app without needing to know app-specific credentials. The attack exploits three compounding design issues: the app accepts requests from any origin (wildcard CORS), authentication tokens remain valid for twenty days without the ability to revoke them, and a simple leaderboard query can expose multiple user records in a single request. An attacker needs only network access and can harvest data at scale.
- CVE-2026-10725HIGH 7.5
Protocol::HTTP2, a Perl library for handling HTTP/2 communication, contains a vulnerability that allows an attacker to consume excessive server memory by sending a specially crafted HTTP/2 request with many headers. The library fails to enforce advertised limits on header sizes, permitting small network payloads to expand dramatically once processed, disrupting server availability. This affects versions before 1.13.
- CVE-2026-10735HIGH 7.5
Three WordPress plugins—Shapedsmart-post-show-pro, Real Testimonials Pro, and Product Slider for WooCommerce Pro—were compromised at their update source and distributed with malicious code. When site owners installed or updated to affected versions, the backdoor code ran on their sites, enabling attackers to steal login credentials and other sensitive information, then gain complete administrative control. This is a supply-chain attack: the threat came not from a code flaw, but from the vendor's update infrastructure being breached.
- CVE-2026-10737HIGH 7.5
The SP Project & Document Manager plugin for WordPress has a serious authorization flaw that allows anyone on the internet to download files from project folders without logging in. The vulnerability stems from a flawed permission check that uses logic errors to bypass all security gates. An attacker only needs to know or guess a file ID to request access through a standard WordPress admin interface, potentially exposing confidential project documents, contracts, customer data, or other sensitive files stored within the plugin.
- CVE-2026-10796HIGH 7.5
nvm (Node Version Manager) versions through 0.40.4 contain a command injection vulnerability in how they process version strings retrieved from configured Node.js mirrors. When you run commands like `nvm install`, the tool fetches available versions from a mirror's index and builds download URLs and shell commands using the version string without proper sanitization. An attacker controlling the mirror, intercepting unencrypted mirror traffic, or providing malicious mirror content can inject arbitrary commands that execute with the privileges of the user running nvm. The official default mirror (nodejs.org over HTTPS) is not affected, but users relying on alternative mirrors or unencrypted connections face significant risk.
- CVE-2026-10816HIGH 7.5
NetScaler ADC and NetScaler Gateway appliances with management interfaces exposed to the network are vulnerable to unauthenticated attackers reading arbitrary files from the system. An attacker with network access to the management IP address (NSIP, Cluster Management IP, or SNIP configured for management) can exploit a path traversal or similar flaw to extract sensitive files without providing credentials. This is a significant confidentiality risk because management interfaces typically house configuration data, certificates, and other sensitive information.
- CVE-2026-10817HIGH 7.5
NetScaler ADC and NetScaler Gateway are vulnerable to a memory disclosure attack when TCP TimeStamp functionality is enabled on TCP profiles associated with load balancing, content switching, VPN virtual servers, or services. An attacker on the network can trigger insufficient input validation to read sensitive data from memory without requiring authentication or user interaction. The vulnerability exposes confidential information but does not allow system disruption or modification.
- CVE-2026-10823HIGH 7.5
The YMC Filter WordPress plugin contains a flaw that allows anyone on the internet to read private and draft posts from a WordPress site without logging in. The vulnerability exists in a REST API endpoint that lacks proper permission checks and doesn't validate input parameters. An attacker can exploit this by making a simple API request to extract sensitive content that should remain hidden from the public.
- CVE-2026-10846HIGH 7.5
NLnet Labs ldns, a DNS library used by many applications for DNS resolution, contains a critical validation flaw in its UDP stub resolver implementation. When applications use ldns to resolve DNS queries over UDP, the library fails to properly verify that responses match their requests—it doesn't check the source address, port, query ID, or even the question being asked. This oversight enables attackers on the network to inject malicious DNS responses without being on the direct path between the client and the legitimate DNS server, a technique known as off-path poisoning. The drill diagnostic tool bundled with ldns is directly affected.
- CVE-2026-10899HIGH 7.5
A use-after-free vulnerability exists in Google Chrome's Ozone display system on Linux that could allow an attacker to corrupt the browser's memory. If a user is tricked into performing specific UI interactions on a malicious webpage, the attacker could potentially execute code or crash the browser. This flaw affects Chrome versions prior to 149.0.7827.53 on Linux systems.
- CVE-2026-10900HIGH 7.5
A use-after-free flaw in Google Chrome's password management feature on macOS allows attackers to corrupt memory and potentially execute code if they trick a user into performing specific interactions with a malicious webpage. The vulnerability requires user interaction and affects Chrome versions before 149.0.7827.53. While rated HIGH by CVSS, the attack surface is narrowed by the need for deliberate user gestures and the complexity of reliable exploitation.
- CVE-2026-10901HIGH 7.5
A use-after-free memory flaw exists in Google Chrome's password manager on macOS. An attacker can trigger the vulnerability by convincing a user to interact with a specially crafted webpage in specific ways—for example, through unusual clicking patterns or drag-and-drop actions in the password UI. Successful exploitation allows remote code execution with the privileges of the Chrome process. This is a memory safety issue where the browser continues to reference password manager data after it has been freed, creating an opportunity for malicious code injection.
- CVE-2026-10906HIGH 7.5
Google Chrome contains a use-after-free vulnerability in its WebAuthentication implementation that can lead to heap memory corruption. An attacker must craft a malicious HTML page and convince a user to interact with it in a specific way—such as clicking or gesturing within the web interface—to trigger the flaw. Successfully exploiting this could allow the attacker to execute arbitrary code or crash the browser. The vulnerability affects Chrome versions before 149.0.7827.53.
- CVE-2026-10946HIGH 7.5
Google Chrome versions before 149.0.7827.53 contain a heap buffer overflow vulnerability in its media processing component. An attacker can exploit this by hosting a specially crafted HTML page and convincing a user to interact with it in specific ways—such as clicking, dragging, or performing other UI gestures. If successful, the attacker gains the ability to run arbitrary code, but crucially, that code executes within Chrome's sandbox, limiting lateral damage to the user's system. The vulnerability requires active user involvement, which raises the bar for exploitation but remains a meaningful risk given how often users interact with web content.
- CVE-2026-10969HIGH 7.5
A flaw in Google Chrome's extension validation system allows attackers to escalate privileges if they've already compromised Chrome's rendering engine. An attacker would need to trick a user into viewing a specially crafted webpage while the renderer process is already under their control, leading to unauthorized system-level access. This is a High-severity issue affecting Chrome versions before 149.0.7827.53.
- CVE-2026-11058HIGH 7.5
Google Chrome on Windows contains an integer overflow vulnerability in its CredentialProvider component that could allow an attacker who has already compromised the browser's rendering engine to escalate their privileges to the operating system level. The attacker would need to serve a specially crafted webpage to trigger the flaw. While the Chromium project rates this as Medium severity, the CVSS assessment reflects HIGH risk due to the potential for complete system compromise once the renderer is already under attacker control.
- CVE-2026-11149HIGH 7.5
Google Chrome versions before 149.0.7827.53 contain a flaw in how Extensions are validated, allowing an attacker who has already compromised Chrome's rendering engine to bypass security boundaries and gain elevated privileges on the user's system. The attacker would need to trick a user into visiting a specially crafted webpage while the renderer process is already under attacker control. This vulnerability bridges a gap between renderer compromise and full system-level access, making it a serious escalation path in multi-stage attacks.
- CVE-2026-11151HIGH 7.5
Google Chrome's Password Manager component fails to properly validate user-supplied input before processing it. This gap allows an attacker who has already compromised Chrome's renderer process—the sandboxed part of the browser that runs web content—to escape the sandbox and gain deeper access to the system. The attacker would need to craft a malicious HTML page and convince a user to visit it, but once the renderer is compromised, the insufficient input validation becomes the bridge to break out of Chrome's security boundaries.
- CVE-2026-11154HIGH 7.5
A use-after-free flaw in Google Chrome's Dawn graphics component allows an attacker who has already compromised the renderer process to break out of Chrome's sandbox and potentially gain system-level access. The vulnerability requires the attacker to trick a user into opening a malicious webpage and demands prior compromise of the renderer process, making it a two-stage attack. Patching to Chrome 149.0.7827.53 or later closes this gap.
- CVE-2026-11239HIGH 7.5
Google Chrome versions before 149.0.7827.53 contain a flaw in how the browser handles extensions that could allow an attacker to escalate privileges if they've already compromised the renderer process—the sandboxed component responsible for running web pages and extensions. An attacker would need to trick a user into visiting a malicious webpage after the renderer is already compromised, but successful exploitation could grant them elevated system access.
- CVE-2026-11242HIGH 7.5
Google Chrome versions prior to 149.0.7827.53 contain a vulnerability in how the browser handles untrusted input within plugins. An attacker who has already compromised Chrome's renderer process can craft a malicious HTML page to steal sensitive data from websites the user has visited, potentially exposing information that should remain isolated between different web domains. This requires the renderer to be compromised first, making it a secondary attack in a chain, but the confidentiality risk is significant.
- CVE-2026-11255HIGH 7.5
A flaw in Google Chrome's Storage Access API fails to properly check user input, creating a security gap. If an attacker first compromises Chrome's renderer process—the part that runs web content—they could exploit this gap to steal data from websites you've visited, even across security boundaries that normally block such access. The issue affects Chrome versions before 149.0.7827.53, as well as the underlying operating systems on macOS, Linux, and Windows where Chrome runs.
- CVE-2026-11265HIGH 7.5
Google Chrome versions before 149.0.7827.53 contain a flaw in the Autofill feature that can allow attackers to steal sensitive data from other websites. An attacker can craft a malicious webpage that, when visited by a user, extracts information that should have been protected by browser isolation mechanisms. The vulnerability requires no user interaction beyond visiting the page and affects confidentiality but not system integrity or availability.
- CVE-2026-11296HIGH 7.5
Google Chrome versions before 149.0.7827.53 contain a flaw in how the ImageCapture feature handles certain operations, allowing an attacker who has already compromised the browser's rendering engine to gain elevated privileges on the system. The attacker would need to trick the user into visiting a malicious webpage while the renderer process is already under their control. This is a privilege escalation vulnerability rather than a remote code execution vulnerability, meaning the initial compromise must have already occurred.
- CVE-2026-11310HIGH 7.5
wolfSSL contains a certificate validation flaw that allows attackers to present fraudulent certificate chains that bypass trust verification. This happens only when applications use wolfSSL's OpenSSL compatibility layer to manually verify certificates (rather than relying on wolfSSL's native TLS verification). An attacker can craft a certificate chain with a self-signed or untrusted intermediate certificate that the vulnerable code mistakenly accepts as valid, potentially enabling impersonation attacks across S/MIME, code signing, JWT validation, and other PKI-dependent protocols.
- CVE-2026-11352HIGH 7.5
curl and libcurl clients can be remotely stalled indefinitely by a malicious HTTP/3 server through a flaw in how the library handles empty network packets. An attacker controlling an HTTP/3 server can flood a connecting client with zero-length UDP datagrams, causing the client to hang or become unresponsive. This affects any application using curl or libcurl for HTTP/3 connections without proper timeout mechanisms.
- CVE-2026-11404HIGH 7.5
Cesanta Mongoose, a popular embedded web server library, has a vulnerability in its built-in TLS implementation that allows an attacker to crash services remotely. When a client initiates a TLS connection, the server reads a length value from the client's handshake message but fails to verify it's reasonable before using it to read data from memory. An attacker can send a malformed TLS handshake with an inflated length value, causing the server to read beyond its buffer boundaries and crash. Any application using Mongoose's TLS server for HTTPS, MQTTS (MQTT over TLS), or WSS (WebSocket over TLS) services is at risk.
- CVE-2026-11568HIGH 7.5
The Product Configurator for WooCommerce plugin contains a critical authorization flaw that exposes sensitive product information to anyone on the internet. Through an unprotected AJAX endpoint, attackers can retrieve detailed data—including titles, prices, weights, stock levels, and configuration options—for products that store owners intentionally marked as private or draft. This bypasses WordPress's native access controls, essentially making hidden product catalogs visible to unauthorized parties. The vulnerability requires no special access, authentication, or user interaction; an attacker only needs to know or guess a product ID.
- CVE-2026-11571HIGH 7.5
The Everest Forms WordPress plugin fails to securely delete temporary CSV files created when sending email notifications from forms. These files remain accessible in the website's public uploads directory with predictable names, allowing anyone on the internet to guess and download them—potentially exposing sensitive form submission data from other users without needing any login credentials.
- CVE-2026-11576HIGH 7.5
A recent security patch for eclipse-threadx NetX Duo's HTTP server introduced a new vulnerability. When handling file upload requests, the code uses a single cleanup routine that always tries to close a file—even if the file was never opened in the first place. If an error occurs before the file is successfully opened, the cleanup code attempts to close an uninitialized file handle, causing the application to crash, leak memory, or potentially corrupt data. This is a regression: the patch meant to fix one vulnerability inadvertently created another.
- CVE-2026-11586HIGH 7.5
A denial-of-service vulnerability exists in curl's WebSocket implementation. By default, curl automatically responds to WebSocket PING frames sent by servers, but it does not enforce a limit on how much memory can be used to store unacknowledged frames. An attacker controlling a malicious WebSocket server can send rapid PING messages faster than curl can process them, causing memory to accumulate without bound until the client system runs out of memory and becomes unresponsive.
- CVE-2026-11625HIGH 7.5
Bytes::Random::Secure, a Perl library for generating cryptographic random numbers, has a critical flaw in how it handles forked processes. When the library is initialized before a process fork or when using its functional interface, the internal random number generator state is duplicated across child processes. This means all forked processes produce identical sequences of random numbers, making secrets generated in multi-process applications predictable and essentially worthless for security purposes.
- CVE-2026-11632HIGH 7.5
A use-after-free flaw in Google Chrome's TabStrip component allows attackers to run arbitrary code on a victim's computer. The vulnerability requires an attacker to craft a malicious webpage and convince a user to perform specific interactions (like clicking or dragging tabs) to trigger the bug. Successful exploitation could give an attacker complete control over the affected system, including access to sensitive data, installation of malware, or lateral movement to other systems on the network.
- CVE-2026-11636HIGH 7.5
A use-after-free vulnerability exists in Google Chrome's Autofill feature on Windows systems. An attacker can craft a malicious HTML page that, when combined with specific user interactions, may trigger memory corruption leading to code execution. The vulnerability requires user interaction—specifically certain UI gestures—to be exploited, but once triggered, the impact is severe. Chrome versions prior to 149.0.7827.103 are affected.
- CVE-2026-11639HIGH 7.5
A use-after-free memory safety flaw exists in Google Chrome's compositing engine on macOS. If you visit a malicious webpage, an attacker could exploit this vulnerability to run arbitrary code on your system with the privileges of the Chrome process. The vulnerability was patched in Chrome 149.0.7827.103 and later versions.
- CVE-2026-11641HIGH 7.5
A memory safety flaw in Google Chrome's Bluetooth implementation on Windows allows attackers to crash the browser or run malicious code if they can trick a user into specific interactions with a specially crafted webpage. The vulnerability requires user action and doesn't grant automatic exploitation, but once triggered, it could give an attacker full control over the affected browser process and any data within it.
- CVE-2026-11644HIGH 7.5
A use-after-free vulnerability exists in Google Chrome's Views component on Linux systems. An attacker could exploit this by tricking a user into installing a malicious Chrome extension, which could then execute arbitrary code with the privileges of the Chrome process. This represents a critical-severity issue from Chromium's perspective, though the CVSS score reflects the requirement for user interaction (extension installation) as a limiting factor.
- CVE-2026-11667HIGH 7.5
Google Chrome versions prior to 149.0.7827.103 contain an out-of-bounds read vulnerability in WebRTC processing that could allow an attacker with prior access to the GPU process to corrupt heap memory and potentially execute code. The attack requires user interaction (clicking a malicious link or visiting a crafted webpage) but could lead to serious data theft or system compromise.
- CVE-2026-11690HIGH 7.5
A memory safety vulnerability in Google Chrome's media handling on macOS allows an attacker who has already compromised the browser's renderer process to read and write memory outside intended boundaries. By hosting a malicious HTML page, the attacker can exploit this flaw to execute arbitrary code even within Chrome's sandbox environment. The vulnerability affects Chrome versions prior to 149.0.7827.103 on macOS.
- CVE-2026-11694HIGH 7.5
A use-after-free flaw in Google Chrome's ServiceWorker implementation could allow an attacker who has already compromised the renderer process to run malicious code within the sandbox. The vulnerability requires user interaction (visiting a specially crafted webpage) but poses a direct path to code execution for an attacker with partial system access.
- CVE-2026-11702HIGH 7.5
Perl's Bytes::Random::Secure::Tiny library has a flaw where random number generation fails to properly reset when code is forked into multiple processes. If an application initializes the random number generator before spawning child processes, all of those processes will generate identical sequences of random numbers. This means any cryptographic secrets or tokens created across multiple processes become predictable, defeating the security purpose of randomization. The vulnerability affects versions 1.011 and earlier.
- CVE-2026-11703HIGH 7.5
A flaw in WolfSSL allows an attacker to reuse a cached TLS session in a different virtual-hosting context than the one where it was originally authenticated. When a client reconnects using a saved session, the library failed to verify that the server name (SNI) and protocol settings (ALPN) matched the original connection. If authentication requirements differ across virtual hosts, an attacker could bypass those checks by resuming a session meant for one host in the security context of another. The fix ensures all session resumptions now validate SNI and ALPN bindings, falling back to a full handshake if they don't match.
- CVE-2026-11799HIGH 7.5
A cross-site scripting (XSS) vulnerability affecting Mozilla Focus and Klar for iOS allows attackers to execute arbitrary JavaScript code in the context of visited websites without requiring user interaction. Unlike traditional XSS flaws that target web applications, this Unsafe JavaScript Execution in WebKit (UXSS) vulnerability exploits how the iOS browser engines handle navigation and script execution, potentially exposing sensitive user data or enabling phishing attacks within the browser itself.
- CVE-2026-11823HIGH 7.5
BookingPress Appointment Booking Pro, a popular WordPress plugin for managing service bookings, contains a SQL Injection vulnerability in versions up to 5.7.1. The vulnerability exists in the code that handles staff member assignments to appointment slots. When processing user input, the plugin strips escape characters but then inserts the data directly into database queries without using proper parameterization. An attacker without authentication can craft malicious input to inject additional SQL commands, allowing them to read sensitive information from the WordPress database. This is a significant risk for any site using the plugin to manage bookings, as customer data, business information, and potentially credentials could be exposed.
- CVE-2026-11877HIGH 7.5
CVE-2026-11877 is a high-severity vulnerability in OpenText Access Manager that allows an unauthenticated attacker to modify system configuration via API calls. An attacker on the network can send specially crafted API requests to alter Access Manager settings without providing credentials, potentially compromising authentication, authorization, or system behavior. This vulnerability affects Access Manager versions before 5.1.3.
- CVE-2026-11911HIGH 7.5
The Simple File List WordPress plugin contains a critical flaw that allows anyone on the internet to delete files from a website's server without logging in. Because the vulnerable code lacks proper validation of file paths, an attacker can target sensitive files like wp-config.php—the configuration file that contains database credentials and security keys. Deleting such files can crash the website or create an opening for the attacker to take over the server entirely. The vulnerability exists in all versions up to and including 6.3.7.
- CVE-2026-11912HIGH 7.5
The Simple File List WordPress plugin contains a critical flaw that allows unauthenticated attackers to delete or modify files on vulnerable servers. The vulnerability exists in all versions up to 6.3.7 and stems from a flawed authorization mechanism. Specifically, the code checks whether a request appears to come from an admin before evaluating the actual permission setting that controls file management features. This means attackers can bypass the intended security control even on installations where the administrator has explicitly disabled the file management feature.
- CVE-2026-11946HIGH 7.5
open62541, an OPC UA implementation, contains a flaw in its GetEndpoints Discovery Service that allows any network attacker to crash the server by consuming its memory. The vulnerability exists because the service doesn't validate how large a string an attacker claims to send—an attacker can declare they're sending up to 4 GB of data and never finish sending it, causing the server to hold onto that reserved memory indefinitely. This happens before any secure connection is established, meaning it bypasses encryption and doesn't require a valid user account.
- CVE-2026-11999HIGH 7.5
A flaw in wolfSSL's OpenSSL compatibility layer allows attackers to bypass certificate trust validation in certain configurations. When an application uses wolfSSL's X509_verify_cert() function with untrusted intermediate certificates and the certificate chain exceeds 100 levels deep, the library incorrectly accepts the chain without verifying it reaches a trusted root certificate. This only affects applications built with OpenSSL compatibility mode enabled that manually perform certificate verification; standard TLS connections are not vulnerable.
- CVE-2026-12064HIGH 7.5
curl has a vulnerability where using a schemeless URL with the `--proto-default` flag set to sftp or scp causes the command-line tool to incorrectly handle SSH security verification. The tool layer fails to initialize critical host verification options, allowing curl to connect to SSH servers without validating their authenticity. This happens because of a mismatch between how the tool interprets the URL and how the underlying libcurl library processes it, resulting in a silent bypass of security checks that should normally occur.
- CVE-2026-12077HIGH 7.5
The Dokan Pro WordPress plugin contains a SQL injection flaw in versions up to 5.0.4 that allows unauthenticated attackers to inject malicious SQL commands through latitude and longitude parameters. Because the plugin fails to properly escape and prepare these user-supplied inputs, attackers can craft requests that extract sensitive database information without requiring authentication. This is a high-severity network-based vulnerability with no user interaction needed to trigger the attack.