By year
Vulnerabilities disclosed in 2026
CVEs published in 2026 with SEC.co analysis.
8541 published vulnerabilities · page 45 of 86
- CVE-2026-11215MEDIUM 6.5
A flaw in how Google Chrome handles domain names on Android devices allows attackers to trick users into visiting fake websites that appear legitimate. By crafting a specially formatted domain name, an attacker can make Chrome display a spoofed address bar, convincing users they're on a trusted site when they're actually on a malicious one. The vulnerability requires user interaction—the victim must visit a link or be socially engineered—but poses a direct threat to credential theft and phishing campaigns.
- CVE-2026-11217MEDIUM 6.5
CVE-2026-11217 is a medium-severity flaw in Google Chrome's Fenced Frames feature that could allow an attacker who has already compromised a renderer process to circumvent Chrome's site isolation security boundary. Site isolation is a core defense that prevents malicious websites from accessing data from other sites in your browser. A remote attacker would need to trick a user into visiting a specially crafted webpage while the renderer has already been compromised, creating a two-stage attack scenario. Google has rated this as low severity on the Chromium scale, though the CVSS score reflects the integrity impact of bypassing site isolation.
- CVE-2026-11220MEDIUM 6.5
A flaw in Google Chrome's navigation handling prior to version 149.0.7827.53 allows a remote attacker who has already compromised the renderer process to bypass the browser's site isolation protection using a specially crafted HTML page. Site isolation is a critical Chrome security boundary designed to prevent malicious websites from accessing data from other sites. This vulnerability requires the attacker to have already gained code execution in the renderer process, making it a secondary or chained attack rather than a direct entry point.
- CVE-2026-11222MEDIUM 6.5
Google Chrome versions before 149.0.7827.53 contain a flaw in how the browser's tab strip displays security information to users. An attacker can craft a malicious webpage that tricks the browser's security UI, making it appear as though the user is visiting a legitimate website when they are actually on a attacker-controlled domain. This is a user-interface spoofing vulnerability that relies on tricking the visual indicators users depend on to verify they're on the correct website.
- CVE-2026-11223MEDIUM 6.5
A vulnerability in Google Chrome allows an attacker who has already compromised the browser's renderer process to bypass the same-origin policy—a fundamental security boundary that prevents malicious websites from accessing data belonging to other sites. The attacker would craft a specially designed HTML page to exploit insufficient input validation in Chrome's network handling. This requires the renderer process to be compromised first, making it a secondary attack that compounds an existing breach rather than a standalone entry point.
- CVE-2026-11225MEDIUM 6.5
Google Chrome before version 149.0.7827.53 contains a flaw that allows attackers to perform domain spoofing—making a malicious website appear to come from a trusted domain. An attacker would need to trick a user into visiting a crafted link, but once clicked, the browser's address bar or other visual indicators could misrepresent the true origin of the site. This affects Chrome on Windows, macOS, and Linux.
- CVE-2026-11226MEDIUM 6.5
A vulnerability in Google Chrome's PreviewTab feature on Android allows attackers to bypass the browser's same-origin policy—a core security boundary that prevents websites from accessing data belonging to other websites. An attacker would need to craft a malicious HTML page and convince a user to perform specific touch gestures (like swiping or tapping) to trigger the bypass. While the underlying Chromium issue is rated Low severity, the CVSS score reflects the real-world impact: an attacker could alter or exfiltrate data from other websites the user is visiting, though not eavesdrop on encrypted traffic or crash the device.
- CVE-2026-11227MEDIUM 6.5
Google Chrome versions before 149.0.7827.53 contain a flaw in how it displays security information in tab hover cards—the small popup that appears when you hover over a browser tab. An attacker can craft a deceptive domain name that, when displayed in this hover card, makes it appear to be a legitimate website you trust. This is a domain spoofing attack: the user sees what looks like one domain but is actually visiting a different one. The vulnerability requires user interaction (hovering over the tab and being deceived) but could help an attacker trick users into thinking they're on a safe site when they're not.
- CVE-2026-11258MEDIUM 6.5
Google Chrome versions before 149.0.7827.53 contain a flaw in how the browser handles file system access permissions. An attacker can craft a malicious webpage that, when visited, tricks users into performing specific clicks or gestures that bypass the browser's normal access controls. This allows the attacker to gain unauthorized access to files on the user's computer that would normally be protected. The vulnerability requires user interaction and social engineering to exploit, but once triggered, could expose sensitive files.
- CVE-2026-11263MEDIUM 6.5
A flaw in Google Chrome's WebAuthentication implementation on Android before version 149.0.7827.53 could allow an attacker who has already compromised Chrome's rendering engine to steal sensitive data from websites across different origins. The attacker would need to trick a user into visiting a malicious webpage, but the underlying issue stems from insufficient enforcement of security policies that should prevent cross-origin data leakage. This is a moderate-severity issue because it requires a prior compromise of the renderer process, limiting the attack surface to scenarios where other vulnerabilities or system weaknesses have already been exploited.
- CVE-2026-11268MEDIUM 6.5
A vulnerability in Google Chrome's ANGLE graphics library on Windows allows an attacker to steal sensitive data from websites you visit. The flaw stems from uninitialized memory being used during graphics processing, which can leak information across security boundaries. An attacker would need to trick you into visiting a malicious webpage to exploit this—the vulnerability cannot be triggered remotely without user interaction. Chrome version 149.0.7827.53 and later patch this issue.
- CVE-2026-11270MEDIUM 6.5
Google Chrome on Android versions before 149.0.7827.53 contain a UI implementation flaw that allows attackers to trick users into visiting specially crafted web pages, potentially exposing sensitive data from other websites the user has visited or is logged into. The vulnerability requires user interaction (clicking a link or visiting a malicious page) but poses a meaningful confidentiality risk by circumventing the browser's cross-origin protections.
- CVE-2026-11271MEDIUM 6.5
Google Chrome versions before 149.0.7827.53 contain a flaw in password handling that could allow an attacker to trick users into revealing data from other websites. The vulnerability requires the attacker to craft a malicious webpage and convince the user to interact with it in a specific way—there is no automatic exploitation. The risk is confined to information disclosure; attackers cannot modify data or disrupt service. While the underlying Chromium project rates this as low severity, the CVSS score reflects the relatively low barrier to user interaction and the potential for cross-origin data leakage.
- CVE-2026-11275MEDIUM 6.5
A flaw in how Google Chrome on Android displays page information allows an attacker who has already compromised Chrome's rendering engine to bypass navigation security controls. An attacker would need to trick a user into viewing a specially crafted webpage after gaining control of the browser's internal processes. The vulnerability is rated Medium severity because while it requires significant pre-existing compromise, it enables attackers to circumvent protections that prevent unauthorized navigation to restricted pages.
- CVE-2026-11278MEDIUM 6.5
Google Chrome on Android contains a flaw in how it handles CustomTabs—a feature that allows apps to open web content in a customized browser interface. An attacker can craft a malicious HTML page that, when opened by a user, leaks data intended to be protected across different websites. This is a local attack requiring user interaction (clicking or opening the page), but the confidentiality impact is significant because sensitive information from one origin could be exposed to another.
- CVE-2026-11283MEDIUM 6.5
Google Chrome on macOS contains a flaw in how it validates input when processing Shortcuts—a macOS feature that allows automation of tasks across applications. An attacker can craft a malicious file that, when opened by a user, bypasses Chrome's navigation restrictions, potentially redirecting the user to unintended web destinations. This requires user interaction (opening the file) but does not require special system privileges or network complexity. The vulnerability was patched in Chrome version 149.0.7827.53.
- CVE-2026-11284MEDIUM 6.5
Google Chrome versions prior to 149.0.7827.53 contain a side-channel vulnerability in the Performance APIs that allows an attacker to extract sensitive data across website boundaries. An attacker can craft a malicious webpage that, when visited by a user, leaks information from other websites the user is viewing or has visited. This works because certain performance measurement features can infer timing details that reveal cross-origin data, even though browsers are designed to isolate websites from each other.
- CVE-2026-11287MEDIUM 6.5
A vulnerability in Google Chrome on Android allows an attacker who has already compromised the browser's renderer process to bypass navigation controls and direct users to unintended destinations using specially crafted web pages. The attacker must first gain control of the renderer process—a significant prerequisite—but once achieved, can manipulate where the browser navigates without proper restrictions. This affects Chrome versions prior to 149.0.7827.53.
- CVE-2026-11288MEDIUM 6.5
A vulnerability in Google Chrome's CSS handling allows an attacker to leak data from websites you visit to a different origin through a malicious webpage. The flaw stems from insufficient enforcement of browser security policies that normally prevent one website from accessing information from another. An attacker would need to trick you into visiting their crafted page while you're logged into or actively using other sites, but no special browser configuration or advanced user interaction is required beyond a standard click. This is a medium-severity issue affecting multiple operating systems through Chrome.
- CVE-2026-11289MEDIUM 6.5
A side-channel vulnerability in Google Chrome's Paint component allows attackers to leak sensitive cross-origin data through a specially crafted web page. An attacker would need to trick a user into visiting a malicious website, but once there, the vulnerability could expose information from other websites the user has open—a serious privacy breach. The issue affects Chrome versions before 149.0.7827.53 across Windows, macOS, and Linux.
- CVE-2026-11299MEDIUM 6.5
A flaw in how Google Chrome handles font data can lead to information disclosure when a user visits a malicious webpage. An attacker can craft a specially designed HTML page that exploits an integer overflow vulnerability in Chrome's font processing code, potentially allowing them to read sensitive data from the browser's memory. The vulnerability affects Chrome versions before 149.0.7827.53 and requires user interaction (visiting the malicious site) to trigger.
- CVE-2026-11322MEDIUM 6.5
Hermes WebUI versions before 0.51.221 have a path traversal flaw that lets authenticated users read files outside the intended workspace directory. By crafting symlinks that point to sensitive data, attackers can access SSH keys, cloud credentials, and application tokens that the server process can reach. The vulnerability requires an existing user account but poses a meaningful risk to credential and secret exposure.
- CVE-2026-11367MEDIUM 6.5
The PixMagix – WordPress Image Editor plugin contains a directory traversal vulnerability that allows authenticated users with author-level permissions to write malicious files anywhere on the server. When users upload or manipulate images through the plugin, an attacker can inject path traversal sequences (like '../../') into image parameters to escape the intended upload folder and place files in sensitive locations. This is particularly concerning because author-level access is granted by default after plugin activation, making exploitation straightforward for any author-role user on an affected WordPress site.
- CVE-2026-11442MEDIUM 6.5
Allegra contains a directory traversal vulnerability in its report export function that allows authenticated users to read files outside their intended access scope. An attacker with valid credentials can manipulate the file path parameter to traverse the directory structure and access sensitive information stored on the server, including files belonging to the application service account. This requires authentication but poses a meaningful information disclosure risk.
- CVE-2026-11611MEDIUM 6.5
A memory leak vulnerability exists in 389 Directory Server's Content Synchronization (sync) feature. When an authenticated user initiates a sync request but stops reading the server's responses without properly closing the connection, the server accumulates data in memory indefinitely, eventually consuming all available resources and crashing the service. The vulnerability also introduces race conditions that can trigger crashes during normal connection cleanup or server shutdown.
- CVE-2026-11653MEDIUM 6.5
Google Chrome versions before 149.0.7827.103 contain a flaw in how browser extensions are implemented that could allow an attacker to bypass site isolation—Chrome's core security mechanism that prevents websites from accessing each other's data. The attack requires two conditions: the attacker must first compromise Chrome's renderer process (the component that executes web pages), and then serve a specially crafted HTML page to the victim. While the technical barrier is high, successful exploitation would let malicious code access data across site boundaries, violating the security boundary that normally isolates sensitive information from different origins.
- CVE-2026-11658MEDIUM 6.5
A vulnerability in Google Chrome's extension validation system allows an attacker who has already compromised Chrome's renderer process to bypass site isolation—a critical security boundary that prevents malicious websites from accessing data across different sites. The flaw stems from insufficient checking of untrusted input in the Extensions subsystem. An attacker would need to trick a user into visiting a specially crafted HTML page while the renderer is already compromised, making this a secondary attack that compounds an existing breach rather than a standalone entry point.
- CVE-2026-11820MEDIUM 6.5
A vulnerability in Ansible's community.general collection allows API credentials for Vonage/Nexmo SMS services to leak into logs and monitoring systems. The nexmo module sends authentication credentials as part of URL query parameters in HTTP GET requests, where they end up in web server logs, proxy logs, HTTP headers, and network traffic captures. Even though Ansible marks these credentials with a 'no_log' flag to prevent them from appearing in Ansible output, the underlying HTTP calls still expose them. An attacker who gains access to any of these logging or monitoring points can retrieve the full API credentials and compromise the victim's Vonage/Nexmo account.
- CVE-2026-11852MEDIUM 6.5
Debusine, a tool used to build and maintain Debian-based Linux distributions, contains a permission-checking flaw in its artifact management system. When users or services create or delete relationships between artifacts (the packaged components that make up a distribution), the system fails to verify whether the requester has authorization to perform those actions. An attacker who can see an artifact can manipulate its relationships without proper permission checks, potentially corrupting the integrity of a distribution build or exposing sensitive artifacts to unauthorized access.
- CVE-2026-11853MEDIUM 6.5
Debusine, a tool for building and maintaining Debian-based Linux distributions, contains a vulnerability in how it parses Debian package manifest files (.dsc and .changes files). These manifests list the files that make up a software package. An attacker can craft malicious manifest files that trick Debusine's parser into creating symbolic links (shortcuts) pointing anywhere on the system. If exploited during the "mergeuploads" task, this could allow an attacker to overwrite files that the Debusine worker process has permission to access, potentially compromising the integrity of package builds or the system itself.
- CVE-2026-11884MEDIUM 6.5
A flaw in 389 Directory Server allows an attacker with administrative privileges—or someone controlling a replication server—to crash the service by creating directory object definitions with unusually long inheritance fields. The underlying issue is that the server calculates buffer space without accounting for the full size of these fields, leading to memory corruption when data is written. This is a remnant of an earlier incomplete patch attempt.
- CVE-2026-11906MEDIUM 6.5
IBM Db2 contains a vulnerability that allows authenticated users to crash the database by submitting specially crafted queries involving XMLTable-derived columns. An attacker with valid database credentials can trigger a denial of service condition, making the database unavailable to legitimate users. This requires authentication, so it is not exploitable by anonymous attackers, but it represents a risk from insider threats or compromised accounts.
- CVE-2026-11965MEDIUM 6.5
A flaw in the User Registration & Membership WordPress plugin before version 5.2.0 allows anyone to sign up for a paid membership subscription without actually paying for it. After self-registering through the plugin's open registration feature, attackers can activate any paid plan and immediately access restricted content—bypassing the payment requirement entirely.
- CVE-2026-11988MEDIUM 6.5
A flaw in the LearnPress WordPress LMS plugin (versions up to 4.3.9.1) allows authenticated users with basic subscriber access or higher to view course enrollment progress and completion data of instructor and administrator accounts. An attacker with a regular user account can directly request information about any teacher or admin's course activities without proper authorization. This does not affect access to other regular subscriber accounts, which remain protected. The vulnerability requires the attacker to already have login credentials.
- CVE-2026-11989MEDIUM 6.5
The Bit integrations plugin for WordPress, widely used for form integrations with WooCommerce and CRM systems, contains a Server-Side Request Forgery (SSRF) flaw that allows unauthenticated attackers to send web requests from your WordPress server to internal or external systems. An attacker can exploit this by submitting forms that trigger attachment uploads mapped to product images, galleries, or contact fields—common configurations for e-commerce and CRM integrations. This could expose sensitive internal services or allow tampering with data on systems the WordPress server can reach.
- CVE-2026-12024MEDIUM 6.5
A flaw in Google Chrome's Developer Tools (DevTools) allows attackers to bypass the same-origin policy—a fundamental browser security boundary that prevents one website from accessing another's data. An attacker crafting a malicious HTML page could trick a user into visiting it, potentially gaining unauthorized access to sensitive information from other sites the user is logged into. The vulnerability affects Chrome versions before 149.0.7827.115 across Windows, macOS, and Linux.
- CVE-2026-12026MEDIUM 6.5
A memory-reading vulnerability exists in Chrome's video processing component on ChromeOS. An attacker who successfully compromises the browser's renderer process can craft a malicious web page to read sensitive information stored in the browser's memory—such as passwords, authentication tokens, or other user data—and exfiltrate it. The vulnerability requires the attacker to already control the renderer process, which limits the attack surface but remains a serious concern when combined with other browser exploits.
- CVE-2026-12060MEDIUM 6.5
Heptabase, a note-taking and knowledge management application, contains a vulnerability that allows attackers to trick users into visiting malicious webpages within the app itself. Through social engineering—such as phishing links or deceptive invitations—an attacker can manipulate a victim into loading a webpage that requests access to the device's camera and microphone. Because the application exposes dangerous methods without proper safeguards, these permissions can be granted without requiring authentication, potentially giving attackers unauthorized access to recording capabilities.
- CVE-2026-12079MEDIUM 6.5
The Dokan Pro WordPress plugin contains a SQL injection vulnerability in how it processes the 'orderby' parameter. An authenticated user with basic Subscriber permissions can craft requests to inject SQL commands and potentially access sensitive database information. This requires an account on the WordPress site; the vulnerability does not affect unauthenticated visitors.
- CVE-2026-12085MEDIUM 6.5
IBM's UrbanCode Deploy and DevOps Deploy products contain a vulnerability that allows authenticated users to access sensitive configuration data and secrets through API responses. An attacker with valid credentials could extract this information and use it to mount further attacks on the system. The issue affects specific versions of both products and requires authentication, limiting immediate exposure but creating meaningful risk for organizations using these deployment tools.
- CVE-2026-12090MEDIUM 6.5
A SQL injection vulnerability exists in the Taskbuilder WordPress plugin (versions up to 5.0.8) that allows authenticated users with subscriber-level access to extract sensitive database information. The vulnerability is in the project filtering functionality and doesn't require additional verification tokens, meaning anyone with basic WordPress account access can exploit it without further prerequisites.
- CVE-2026-12105MEDIUM 6.5
Devolutions Server contains an access control weakness that allows authenticated users to view attachments they shouldn't have permission to access. The issue occurs when a folder is duplicated—the inherited permissions aren't properly restricted, giving users unintended access to sensitive files. An attacker would need valid login credentials to exploit this, but once authenticated, they could escalate their view into restricted attachment areas without additional authorization.
- CVE-2026-12110MEDIUM 6.5
A WordPress plugin called Taskbuilder, which provides project and task management features with a Kanban board, contains a SQL injection vulnerability in how it processes task search requests. The vulnerability allows authenticated users—even those with basic Subscriber account privileges—to inject malicious SQL commands to extract sensitive data from the website's database. This is particularly concerning because the vulnerable AJAX function that handles task searches doesn't verify user permissions or validate session tokens, making it accessible to any logged-in user regardless of their intended role.
- CVE-2026-12119MEDIUM 6.5
The Simple File List WordPress plugin contains a flaw that allows authenticated users with basic contributor privileges to perform unauthorized file operations on a server. An attacker can exploit this by creating a draft post, extracting a security token from its preview, and then using that token to delete files, move files, create folders, or download files—bypassing the plugin's intended access controls. This affects all versions up to 6.3.7.
- CVE-2026-12270MEDIUM 6.5
Everest Forms, a popular WordPress plugin, contains a flaw in how it protects certain administrative API endpoints used during initial setup. The plugin checks user permissions, but only when a specific HTTP header is present in requests—attackers can simply omit or change this header to bypass the check entirely. This allows unauthenticated visitors to view setup information, change plugin settings, and trigger emails sent to addresses of the attacker's choosing.
- CVE-2026-12302MEDIUM 6.5
A security bypass vulnerability exists in Firefox and Thunderbird's DOM security component that could allow an attacker to circumvent built-in protections. The vulnerability requires no user interaction and can be exploited over the network, though it is limited to information disclosure and integrity impacts without causing system unavailability. Mozilla has addressed this in recent versions of both browser products.
- CVE-2026-12309MEDIUM 6.5
A memory safety vulnerability has been identified and patched in Mozilla Firefox and Thunderbird. The flaw allows an attacker to crash the affected application or potentially leak sensitive information without requiring user interaction or special privileges. Mozilla has released fixes in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12 to address this issue.
- CVE-2026-12319MEDIUM 6.5
A denial-of-service vulnerability in Firefox and Thunderbird's audio and video playback component allows an unauthenticated attacker to crash the application by sending a malicious media file or crafting a specially designed media resource. The attacker needs only to trick a user into opening or viewing the content—no special privileges or complex interaction is required. While this does not expose data or allow unauthorized access, it can disrupt productivity and user experience.
- CVE-2026-12325MEDIUM 6.5
A denial-of-service vulnerability exists in Firefox and Thunderbird's image processing component. An attacker can craft a malicious image that, when viewed by a user, causes the application to crash or become unresponsive. The vulnerability requires user interaction—specifically, the user must open or view the malicious image—but no special privileges are needed. This is a localized impact issue affecting availability rather than data confidentiality or integrity.
- CVE-2026-12388MEDIUM 6.5
A vulnerability in Keycloak's identity provider mapper system allows administrators with limited permissions to escalate their access to full realm control. By creating a 'Hardcoded Role' mapper, a restricted admin can assign themselves high-level administrative roles like realm-admin, circumventing the permission boundaries that were supposed to limit their authority. This is a privilege escalation vulnerability that turns a controlled administrative account into an unrestricted one.
- CVE-2026-12428MEDIUM 6.5
The Blocks for ACF Fields plugin for WordPress has a flaw that lets authenticated users view sensitive ACF field data they shouldn't be able to see. Anyone with Author-level access or higher can read field values from private posts, drafts, or other posts belonging to different users by making requests to a specific REST API endpoint. The plugin only checks if a user can publish posts (a very broad permission) rather than verifying they actually own or have permission to view the specific content they're trying to access.
- CVE-2026-12450MEDIUM 6.5
A flaw in Google Chrome's media handling allows attackers to extract sensitive information from your browser's memory through a specially crafted webpage. An attacker could trick you into visiting a malicious site and potentially access data that shouldn't be exposed—passwords, tokens, or other secrets processed by the browser. This requires user interaction (clicking or visiting the page) but no special permissions, making it a realistic threat for targeted attacks.
- CVE-2026-12461MEDIUM 6.5
A memory reading flaw in Google Chrome's WebRTC component allows attackers to trick users into visiting a malicious webpage that extracts sensitive data from the browser's process memory. The vulnerability affects Windows users running Chrome versions prior to 149.0.7827.155. An attacker would need user interaction—specifically, the user must visit a crafted HTML page—but no special privileges or system access are required on the victim's end.
- CVE-2026-12568MEDIUM 6.5
CVE-2026-12568 is a path traversal vulnerability in the postman_download module that allows attackers to write arbitrary files to a user's system. The flaw stems from improper handling of workspace names retrieved from the Postman API. When a workspace name contains special characters designed to traverse directories (such as ../ sequences), the module fails to sanitize the input before using it to construct file paths. An attacker who controls a malicious Postman workspace can craft a name that causes files to be written outside the intended directory, potentially overwriting or injecting malicious content into the user's system.
- CVE-2026-12620MEDIUM 6.5
GridTime 3000 GNSS Time Server contains a credential exposure vulnerability where access tokens are inadvertently leaked through URL parameters on certain endpoints. An authenticated attacker can potentially capture or intercept these tokens, gaining unauthorized access to sensitive functionality. This affects versions 1.0r0.03 through 1.1r0.0 of the firmware.
- CVE-2026-12706MEDIUM 6.5
FFmpeg, a widely used multimedia framework, contains a use-after-free vulnerability in its RASC video decoder. When processing a specially crafted AVI file with malicious RASC video data, the decoder's move-table handling can inadvertently free memory that is still being read by the decode function. This causes the application to access invalid memory locations, typically resulting in a crash. An attacker needs only to trick a user into opening or playing a malicious video file—no special privileges or complex attack setup required.
- CVE-2026-12760MEDIUM 6.5
The Tapo C200 v3 camera contains a flaw in how it processes fragmented network traffic that allows an attacker on the same local network to disable the device temporarily. By sending specially crafted packets, an attacker can consume excessive resources on the camera, causing it to stop responding and interrupting video monitoring and recording. No authentication or user interaction is required—the attacker simply needs network adjacency to the device.
- CVE-2026-12993MEDIUM 6.5
Apicurio Registry contains a flaw in its XML parsing logic that allows authenticated users to cause service disruption. While the application blocks certain XML attack vectors like external entity references, it fails to disable internal entity expansion—specifically the 'billion-laughs' attack where deeply nested XML entities force the parser to consume massive amounts of CPU and memory. An attacker with permission to write artifacts can exploit this by uploading a specially crafted XML document. The Java XML parser has a built-in limit that provides partial protection, but it is not guaranteed to prevent all denial-of-service scenarios.
- CVE-2026-13010MEDIUM 6.5
The JoomSport plugin for WordPress contains a SQL injection vulnerability in its shortcode functionality that allows authenticated users with contributor-level permissions or higher to extract sensitive database information. An attacker with basic WordPress posting privileges can embed a malicious shortcode in a page or post that injects SQL commands to bypass normal database queries and access unauthorized data. The vulnerability affects all versions up to 5.7.9 and requires an attacker to already have legitimate WordPress access.
- CVE-2026-13011MEDIUM 6.5
The WP ERP (Enterprise Resource Planning) plugin for WordPress contains a SQL injection vulnerability in its employee list functionality. An attacker with HR Manager privileges or higher can manipulate a sorting parameter to inject malicious SQL commands, potentially extracting sensitive company data from the database. While the vulnerability requires authenticated access at a specific privilege level, the ability to exfiltrate data makes it a meaningful risk for organizations running this plugin.
- CVE-2026-13022MEDIUM 6.5
Google Chrome versions prior to 149.0.7827.197 contain a flaw in the Autofill feature that allows an attacker with control of the browser's renderer process to extract sensitive data across website boundaries using a specially crafted web page. This is a moderate-severity issue that requires both the renderer process to be compromised and user interaction to exploit.
- CVE-2026-13208MEDIUM 6.5
KubeVirt's virt-handler service has a flaw in how it validates incoming event messages from virt-launcher pods running on the same node. When a virt-launcher process sends updates about a virtual machine instance (VMI), the handler accepts the VMI identity directly from the message content without verifying that the sender is actually authorized to update that specific VMI. A compromised virt-launcher could exploit this to send fake lifecycle events for other VMIs on the same node, causing the handler to incorrectly update their state and disrupt normal operations.
- CVE-2026-13226MEDIUM 6.5
The Groundhogg WordPress plugin for CRM, newsletters, and marketing automation contains a SQL injection vulnerability in its contact table AJAX handler. An authenticated user—regardless of their role—can inject malicious SQL commands through the 'after' parameter to access sensitive database information. This vulnerability exists because the parameter isn't properly escaped, the SQL query lacks preparation defenses, and the security checks that should restrict access have been disabled. While exploitation requires an existing user account, the lack of role restrictions makes this a significant risk for organizations running the plugin.
- CVE-2026-13331MEDIUM 6.5
The Groundhogg CRM and marketing automation plugin for WordPress contains a SQL injection vulnerability in its search functionality. An authenticated user with marketer-level permissions or higher can craft malicious search queries to extract sensitive data from the WordPress database. The vulnerability exists because the search parameter is not properly escaped before being used in SQL queries. While an attacker needs valid WordPress credentials, the risk is significant because marketers and similar roles often have access to customer data, making unauthorized database extraction a realistic threat.
- CVE-2026-13333MEDIUM 6.5
A SQL injection vulnerability exists in the Groundhogg WordPress plugin (versions up to 4.5.5) that allows attackers with Sales Representative access or higher to extract sensitive data from the website's database. The vulnerability stems from improper handling of query parameters combined with a bypass mechanism—attackers can submit malformed filter requests that trigger an exception, causing the system to fall back to legacy code that doesn't properly sanitize user input. While authentication is required, the low privilege threshold and straightforward exploitation method make this a meaningful risk for organizations using this plugin.
- CVE-2026-13437MEDIUM 6.5
Devolutions PowerShell Universal version 2026.2.0 contains a vulnerability where authentication tokens (App Tokens) are exposed in plaintext within job API responses. An authenticated user with permission to read AI Agent jobs can capture these tokens and reuse them to gain unauthorized access to protected resources, potentially with higher privileges than their own account. This affects any organization using the vulnerable version where job APIs are accessible to users with lower privilege levels.
- CVE-2026-13454MEDIUM 6.5
A flaw in the MotoPress Appointment Booking WordPress plugin allows database extraction attacks. The vulnerability exists in how the plugin processes search parameters, failing to properly filter or prepare user input before passing it to database queries. Any WordPress user with the mpa_appointment_employee role can exploit this to read sensitive data from the database—customer contact information, appointment details, payment records, or other stored information. The flaw affects all versions up to 2.4.5.
- CVE-2026-13593MEDIUM 6.5
CSS::Minifier::XS is a Perl library that compresses CSS code by removing unnecessary characters like whitespace and comments. Versions before 0.14 contain a memory leak that occurs specifically when the minify function processes CSS files that consist entirely of removable content—essentially documents that should compress to nothing. This causes the application to consume memory that is never released, potentially degrading performance over time if such documents are processed repeatedly.
- CVE-2026-1365MEDIUM 6.5
A flaw in Sayax Energy Technologies Inc.'s OSOS product allows an authenticated user to bypass security controls by causing sensitive information to be exposed in outgoing data traffic. This means someone with valid login credentials could potentially access systems or data they should not be able to reach. The vulnerability affects OSOS versions through 09072026, and Sayax did not respond to early vendor notification attempts.
- CVE-2026-13790MEDIUM 6.5
A side-channel vulnerability in Google Chrome's Scroll feature allows attackers to extract sensitive cross-origin data by tricking users into visiting a malicious webpage. The flaw exploits timing or behavioral patterns in how the browser handles scroll operations, potentially exposing information from websites the user has visited or is logged into. Chrome versions prior to 150.0.7871.47 are vulnerable.
- CVE-2026-13793MEDIUM 6.5
Google Chrome versions before 150.0.7871.47 contain a flaw in how it enforces security policies for SVG (Scalable Vector Graphics) content. An attacker can craft a malicious web page that, when visited, leaks data from other websites the user has accessed or logged into. The attack requires user interaction—the victim must visit the attacker's page—but does not require special browser settings or privileges. This is a cross-origin data exposure vulnerability, meaning it breaks the browser's fundamental protection that prevents one website from accessing another's private information.
- CVE-2026-13795MEDIUM 6.5
A vulnerability in Google Chrome for iOS allows attackers to bypass browser navigation restrictions through a specially crafted webpage. An affected user would need to visit a malicious page, but once there, the attacker can force navigation to restricted destinations that the browser normally blocks. This affects Chrome on iOS up to version 149 and is resolved in version 150.0.7871.47 and later.
- CVE-2026-13809MEDIUM 6.5
A flaw in Google Chrome's Safe Browsing feature on iOS allows attackers who have already compromised Chrome's rendering process to steal sensitive data from other websites through a specially crafted web page. The vulnerability enables cross-origin information leakage—meaning an attacker could potentially access data that should be isolated between different websites. This requires the attacker to have already gained control of the renderer process, which limits the immediate threat scope but represents a serious escalation risk if other vulnerabilities are chained together.
- CVE-2026-13810MEDIUM 6.5
A flaw in how Google Chrome on Linux handles user input can allow attackers to steal sensitive information from the browser's memory. An attacker would craft a malicious webpage and trick a user into visiting it; the browser would then leak data that should have been protected. This affects Chrome versions prior to 150.0.7871.47 on Linux systems.
- CVE-2026-13816MEDIUM 6.5
A vulnerability in Google Chrome for Android allows attackers to steal private data from different websites through a crafted web page. The flaw exists in how Chrome handles file inputs without properly validating untrusted data. An attacker would need to trick a user into visiting a malicious page, but once that happens, sensitive cross-origin information—data meant to be isolated between websites—can be extracted. This affects Chrome versions prior to 150.0.7871.47 on Android devices.
- CVE-2026-13818MEDIUM 6.5
Google Chrome contained a flaw in its password management feature that could allow an attacker to trick users into navigating to unintended websites through a specially crafted web page. The vulnerability affects Chrome versions prior to 150.0.7871.47 and requires user interaction to exploit. While the attacker cannot steal passwords or crash the browser, the ability to redirect users to malicious sites poses a meaningful risk, particularly for phishing campaigns or drive-by downloads.
- CVE-2026-13820MEDIUM 6.5
A flaw in Skia, Google Chrome's graphics library, allows an attacker who has already compromised Chrome's renderer process to read memory outside intended boundaries. By serving a specially crafted webpage, the attacker can extract sensitive information that crosses origin boundaries—data they should not have access to. This requires the attacker to first gain control of the renderer process, which typically happens when a user visits a malicious or compromised website. The vulnerability affects Chrome on macOS prior to version 150.0.7871.47.
- CVE-2026-13822MEDIUM 6.5
Google Chrome on Android contains a flaw in how it handles extensions that allows attackers to bypass the same-origin policy—a critical browser security boundary. An attacker would need to trick a user into installing a malicious extension, after which the attacker could access or modify data from websites the user visits, potentially stealing credentials, session tokens, or sensitive information. This affects Chrome versions before 150.0.7871.47 on Android devices.
- CVE-2026-13826MEDIUM 6.5
A flaw in Chrome's autofill feature on Android could allow an attacker who has already compromised your browser's rendering process to steal sensitive data from other websites you visit. The attacker would need to trick you into visiting a specially crafted webpage, but once you do, they can extract information that should normally be hidden between different websites.
- CVE-2026-13828MEDIUM 6.5
A flaw in Google Chrome's Enterprise implementation allows attackers to extract sensitive data from browser memory by tricking users into visiting a specially crafted webpage. The vulnerability requires user interaction (clicking a link or viewing a page) but does not require any special privileges. While the underlying browser processes are not compromised or harmed, the attacker gains unauthorized access to information that may be confidential. This affects Chrome versions prior to 150.0.7871.47 across Windows, macOS, and Linux systems.
- CVE-2026-13833MEDIUM 6.5
A memory initialization flaw in Chrome's graphics engine (ANGLE) on macOS allows attackers to steal sensitive data from websites you visit. An attacker hosting a malicious webpage can craft it to trigger the vulnerability when you visit—no special user interaction beyond normal browsing is required beyond clicking a link. The leaked data remains confined to your current browser session, but the confidentiality risk is material.
- CVE-2026-13838MEDIUM 6.5
Google Chrome versions before 150.0.7871.47 contain a flaw in CSS rendering that could allow an attacker to craft a malicious web page bypassing Chrome's same-origin policy. This is a client-side vulnerability requiring user interaction—a victim must visit the attacker's page—but if successful, it could enable unauthorized access to data or functionality from other websites the user has visited.
- CVE-2026-13839MEDIUM 6.5
Google Chrome versions before 150.0.7871.47 contain a flaw in how CSS is processed that allows an attacker to bypass the browser's same-origin policy—a critical security boundary that prevents malicious websites from accessing data belonging to other sites. An attacker would need to trick a user into visiting a specially crafted webpage, but once there, the vulnerability could allow unauthorized access to sensitive information from other origins. This is a medium-severity issue that affects user privacy and data confidentiality.
- CVE-2026-13840MEDIUM 6.5
A flaw in how Google Chrome enforces security policies on the Canvas API allows attackers to extract sensitive information from different websites. An attacker could craft a malicious HTML page that, when visited by a user, reads data intended to be isolated between websites. The vulnerability affects Chrome versions before 150.0.7871.47 and requires user interaction to exploit.
- CVE-2026-13847MEDIUM 6.5
Google Chrome for iOS contains a flaw in how it validates user-supplied input when rendering web pages. An attacker can craft a malicious HTML page that, when viewed on an affected iOS device, leaks sensitive data from websites the user has visited or logged into—data that should be isolated between different web origins. The vulnerability affects Chrome versions prior to 150.0.7871.47 on iOS and requires user interaction (the user must visit the attacker's page), but once that happens, no additional steps are needed to compromise cross-origin data.
- CVE-2026-13858MEDIUM 6.5
Google Chrome versions before 150.0.7871.47 contain a memory safety flaw in the bundled FFmpeg video decoder. When processing a specially crafted video file, the decoder reads beyond allocated memory boundaries, potentially exposing sensitive data from the browser process's memory to an attacker. The vulnerability requires user interaction—an attacker must trick a user into opening a malicious video—but exploitation is otherwise straightforward.
- CVE-2026-13862MEDIUM 6.5
Google Chrome on iOS has a flaw in how it enforces security policies for Web Authentication features like passkeys and security keys. An attacker positioned on the same network as a victim could craft a malicious webpage that tricks the browser into leaking sensitive data from other websites the user has visited. The issue requires the attacker to be on a privileged network position and requires user interaction to click on a malicious link, but if successful can expose confidential information across website boundaries.
- CVE-2026-13866MEDIUM 6.5
A flaw in how Google Chrome on Android handles user input could allow an attacker to bypass the browser's site isolation security feature. If an attacker had already compromised Chrome's rendering engine through another vulnerability, they could use a specially crafted webpage to escape the sandbox that normally keeps different websites separated from each other. This is a secondary attack that depends on a prior breach of the renderer process.
- CVE-2026-13868MEDIUM 6.5
A flaw in Google Chrome's network implementation on Android allows an attacker who has already compromised the browser's rendering engine to bypass site isolation—a critical security boundary that prevents malicious websites from accessing data belonging to other sites. The vulnerability requires both a compromised renderer process and user interaction to trigger, and affects Chrome versions before 150.0.7871.47 on Android devices.
- CVE-2026-13871MEDIUM 6.5
A vulnerability in Google Chrome's GuestView feature allowed attackers who had already compromised the browser's renderer process to bypass the site isolation security boundary using a malicious HTML page. Site isolation is Chrome's primary defense against one renderer process reading data from another site; this flaw created a way around that protection. The vulnerability affects Chrome versions before 150.0.7871.47.
- CVE-2026-13873MEDIUM 6.5
A memory reading flaw in Google Chrome's Layout component allows attackers to trick users into visiting a malicious webpage that reads sensitive data from the browser process. The attacker gains no ability to modify data or crash the system, but can potentially expose information that should remain private. This affects Chrome versions before 150.0.7871.47 across Windows, macOS, and Linux systems.
- CVE-2026-13876MEDIUM 6.5
Google Chrome versions before 150.0.7871.47 contain a flaw in how the browser handles network traffic that allows an attacker positioned to intercept network communications to bypass the browser's Content Security Policy (CSP) protections. An attacker exploiting this would need to be in a position to monitor or modify traffic between a user and the websites they visit, such as on a shared or compromised network. The attacker cannot directly steal data or crash the browser, but can bypass CSP rules that normally prevent malicious scripts from running, potentially enabling further attacks if the attacker can inject their own content.
- CVE-2026-13879MEDIUM 6.5
Google Chrome contains a use-after-free memory vulnerability in its Bluetooth implementation that allows attackers on the same local network to extract sensitive data from the browser's memory by using a specially crafted Bluetooth device. This occurs before Chrome version 150.0.7871.47. The vulnerability is rated Medium severity and does not affect system stability or enable attackers to modify data, but it does create a risk of information disclosure from process memory.
- CVE-2026-13881MEDIUM 6.5
A flaw in how Google Chrome handles web app installations allows attackers to bypass the same-origin policy—a critical browser security boundary—by tricking users into visiting a malicious HTML page. The vulnerability affects Chrome versions before 150.0.7871.47 across Windows, macOS, and Linux. An attacker could craft a page that tricks Chrome into loading or interacting with resources from a different origin than the user expects, potentially enabling credential theft, session hijacking, or unauthorized data access.
- CVE-2026-13886MEDIUM 6.5
Google Chrome versions prior to 150.0.7871.47 contain a flaw in how Isolated Web Apps enforce content security policies. An attacker can craft a malicious HTML page that, when visited by a user, bypasses these protections—potentially allowing unauthorized modifications to web content or application behavior. The vulnerability requires user interaction (clicking a link or visiting a page) but does not require the victim to be logged in or have special privileges.
- CVE-2026-13887MEDIUM 6.5
This vulnerability affects Google Chrome on Android devices running versions before 150.0.7871.47. An attacker who has already compromised Chrome's renderer process—the component that interprets web pages—can craft a malicious HTML page to extract sensitive data from websites the user visits, even if those sites are on different domains. The attacker cannot modify or delete data, only read it. This is a medium-severity issue that requires the user to visit a malicious page after the renderer is already compromised.
- CVE-2026-13889MEDIUM 6.5
A vulnerability in Google Chrome on iOS allows attackers to steal sensitive information across different websites through a specially crafted web page. The flaw exists in Chrome's WebAuthentication system and can leak data without requiring any user interaction beyond visiting a malicious page. This affects Chrome versions before 150.0.7871.47 on iOS devices.
- CVE-2026-13892MEDIUM 6.5
A flaw in Google Chrome for iOS versions before 150.0.7871.47 allows attackers to steal data from websites you visit while using another site, but only if they can trick you into performing specific gestures on their crafted webpage. The vulnerability does not let attackers modify data or crash your browser—it's limited to unauthorized viewing of cross-origin information.
- CVE-2026-13893MEDIUM 6.5
Google Chrome versions before 150.0.7871.47 contain a weakness in the WebUI component where user input is not properly validated. An attacker could craft malicious network traffic to trick a user into visiting a specially prepared page, potentially exposing sensitive data from other websites the user has open. The vulnerability requires user interaction and does not allow attackers to modify data or crash the browser, but the confidentiality risk is significant.
- CVE-2026-13894MEDIUM 6.5
Google Chrome prior to version 150.0.7871.47 contains a policy enforcement gap that allows an attacker positioned on the same network to manipulate how the browser handles navigation. By serving a specially crafted HTML page, an attacker can circumvent restrictions designed to prevent users from accessing certain sites or resources. The vulnerability requires the attacker to be in a network position to intercept or serve malicious content, and the user must interact with the page (clicking a link or performing an action), but does not result in direct data theft or system access.