| CVE-2014-7906 | Use-after-free vulnerability in the Pepper plugins in Google Chrome before 39.0.2171.65 allows remote attackers to cause a denial of service or possibly have unspecified other impact via crafted Flash content that triggers an attempted PepperMediaDeviceManager access outside of the object's lifetime. | high | |
| CVE-2016-1669 | The Zone::New function in zone.cc in Google V8 before 5.0.71.47, as used in Google Chrome before 50.0.2661.102, does not properly determine when to expand certain memory allocations, which allows remote attackers to cause a denial of service (buffer overflow) or possibly have unspecified other impact via crafted JavaScript code. | high | |
| CVE-2012-2042 | Adobe Illustrator before CS6 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2012-0780, CVE-2012-2023, CVE-2012-2024, CVE-2012-2025, and CVE-2012-2026. | critical | |
| CVE-2026-1284 | An Out-Of-Bounds Write vulnerability affecting the EPRT file reading procedure in SOLIDWORKS eDrawings from Release SOLIDWORKS Desktop 2025 through Release SOLIDWORKS Desktop 2026 could allow an attacker to execute arbitrary code while opening a specially crafted EPRT file. | high | |
| CVE-2026-22722 | A malicious actor with authenticated user privileges on a Windows based Workstation host may be able to cause a null pointer dereference error. To Remediate CVE-2026-22722, apply the patches listed in the "Fixed version" column of the 'Response Matrix' | medium | |
| CVE-2026-33451 | CVE-2026-33451 is an arbitrary read/write vulnerability in the Secure Access Windows client prior to 14.50. Attackers with local control of the Windows client can send malformed data to an API and elevate their level of privilege to system. | high | |
| CVE-2026-77639 | Tor before 0.4.9.9 was prone to a compression bomb bypass where an attacker could concatenate many gzip or zlib sub-streams, each just under the per-stream detection threshold, to avoid the compression bomb check entirely. This is TROVE-2026-022. | medium | |
| CVE-2026-81578 | An improper access control vulnerability exists in the web management interface of PaperCut MF and PaperCut NG. Under specific conditions, unauthenticated remote requests targeting administrative functions can trigger backend actions prior to the completion of access validation checks. This allows an unauthenticated remote attacker to modify certain system configurations. | highVulnerability of Interest | |
| CVE-2015-6783 | The FindStartOffsetOfFileInZipFile function in crazy_linker_zip.cpp in crazy_linker (aka Crazy Linker) in Android 5.x and 6.x, as used in Google Chrome before 47.0.2526.73, improperly searches for an EOCD record, which allows attackers to bypass a signature-validation requirement via a crafted ZIP archive. | medium | |
| CVE-2026-40875 | mailcow: dockerized is an open source groupware/email suite based on docker. In versions prior to 2026-03b, the user dashboard's "Seen successful connections" (login history) renders the client IP from login logs without HTML escaping. Because the server trusts the X-Real-IP header as the source IP for logging, an attacker can inject HTML/JS into this field. This Self-XSS can be exploited by a Login CSRF to force the victim into the attacker's account, and then read emails in a previous browser tab. Version 2026-03b fixes the vulnerability. | high | |
| CVE-2026-33399 | Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.7.0, the SSRF fix applied in version 4.6.2 for CVE-2026-30839 and CVE-2026-30840 is incomplete. The validate_webhook_url_for_ssrf() protection was added to the test* notification endpoints but not to the corresponding save* endpoints. An authenticated user can save an internal/private IP address as a notification URL, and when the cron job sendnotifications.php executes, the request is sent to the internal IP without any SSRF validation. This issue has been patched in version 4.7.0. | high | |
| CVE-2021-38669 | Microsoft Edge (Chromium-based) Tampering Vulnerability | high | |
| CVE-2022-23264 | Microsoft Edge (Chromium-based) Spoofing Vulnerability | medium | |
| CVE-2023-29334 | Microsoft Edge (Chromium-based) Spoofing Vulnerability | medium | |
| CVE-2024-21383 | Microsoft Edge (Chromium-based) Spoofing Vulnerability | low | |
| CVE-2023-36727 | Microsoft Edge (Chromium-based) Spoofing Vulnerability | medium | |
| CVE-2024-38083 | Microsoft Edge (Chromium-based) Spoofing Vulnerability | medium | |
| CVE-2024-38221 | Microsoft Edge (Chromium-based) Spoofing Vulnerability | medium | |
| CVE-2025-65046 | Microsoft Edge (Chromium-based) Spoofing Vulnerability | low | |
| CVE-2026-45489 | Microsoft Edge (Chromium-based) Spoofing Vulnerability | medium | |
| CVE-2026-37709 | Insecure Permissions vulnerability in grokability snipe-it v.8.4.0 and before and fixed after 2026-03-10 commit 676a9958 allows a remote attacker to execute arbitrary code via the app/Http/Controllers/Api/UploadedFilesController.php component | critical | |
| CVE-2026-2476 | Mattermost Plugins versions <=2.0.3.0 fail to properly mask sensitive configuration values which allows an attacker with access to support packets to obtain original plugin settings via exported configuration data. Mattermost Advisory ID: MMSA-2026-00606 | medium | |
| CVE-2026-7474 | HashiCorp Nomad and Nomad Enterprise prior to 2.0.1 are vulnerable to code execution on the client host through a path traversal attack. This vulnerability (CVE-2026-7474) is fixed in Nomad 2.0.1, 1.11.5 and 1.10.11. | high | |
| CVE-2026-56131 | libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_ResumeParser from within handlers in cases of a policy violation. Thus, a use-after-free can occur (similar to the CVE-2026-50219 situation). | medium | |
| CVE-2021-30607 | Chromium: CVE-2021-30607 Use after free in Permissions | high | |
| CVE-2021-30614 | Chromium: CVE-2021-30614 Heap buffer overflow in TabStrip | high | |
| CVE-2023-38158 | Microsoft Edge (Chromium-based) Information Disclosure Vulnerability | low | |
| CVE-2024-38222 | Microsoft Edge (Chromium-based) Information Disclosure Vulnerability | medium | |
| CVE-2012-2025 | Adobe Illustrator before CS6 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2012-0780, CVE-2012-2023, CVE-2012-2024, and CVE-2012-2026. | critical | |
| CVE-2021-33741 | Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | high | |
| CVE-2021-36930 | Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | high | |
| CVE-2022-21929 | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | low | |
| CVE-2022-30127 | Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | high | |
| CVE-2022-26908 | Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | high | |
| CVE-2022-24475 | Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | high | |
| CVE-2022-29144 | Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | high | |
| CVE-2023-21796 | Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | high | |
| CVE-2023-21795 | Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | high | |
| CVE-2023-23374 | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | high | |
| CVE-2023-29354 | Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability | medium | |
| CVE-2023-38187 | Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | medium | |
| CVE-2023-38157 | Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability | medium | |
| CVE-2023-36741 | Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | high | |
| CVE-2023-36014 | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | high | |
| CVE-2023-36024 | Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | high | |
| CVE-2023-36008 | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | medium | |
| CVE-2024-26163 | Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability | medium | |
| CVE-2024-26246 | Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability | low | |
| CVE-2024-43566 | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | critical | |
| CVE-2024-43579 | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | high | |