CVE Search

IDDescriptionSeverityUpdated
CVE-2014-7906Use-after-free vulnerability in the Pepper plugins in Google Chrome before 39.0.2171.65 allows remote attackers to cause a denial of service or possibly have unspecified other impact via crafted Flash content that triggers an attempted PepperMediaDeviceManager access outside of the object's lifetime.
high
CVE-2016-1669The Zone::New function in zone.cc in Google V8 before 5.0.71.47, as used in Google Chrome before 50.0.2661.102, does not properly determine when to expand certain memory allocations, which allows remote attackers to cause a denial of service (buffer overflow) or possibly have unspecified other impact via crafted JavaScript code.
high
CVE-2012-2042Adobe Illustrator before CS6 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2012-0780, CVE-2012-2023, CVE-2012-2024, CVE-2012-2025, and CVE-2012-2026.
critical
CVE-2026-1284An Out-Of-Bounds Write vulnerability affecting the EPRT file reading procedure in SOLIDWORKS eDrawings from Release SOLIDWORKS Desktop 2025 through Release SOLIDWORKS Desktop 2026 could allow an attacker to execute arbitrary code while opening a specially crafted EPRT file.
high
CVE-2026-22722A malicious actor with authenticated user privileges on a Windows based Workstation host may be able to cause a null pointer dereference error. To Remediate CVE-2026-22722, apply the patches listed in the "Fixed version" column of the 'Response Matrix'
medium
CVE-2026-33451CVE-2026-33451 is an arbitrary read/write vulnerability in the Secure Access Windows client prior to 14.50. Attackers with local control of the Windows client can send malformed data to an API and elevate their level of privilege to system.
high
CVE-2026-77639Tor before 0.4.9.9 was prone to a compression bomb bypass where an attacker could concatenate many gzip or zlib sub-streams, each just under the per-stream detection threshold, to avoid the compression bomb check entirely. This is TROVE-2026-022.
medium
CVE-2026-81578An improper access control vulnerability exists in the web management interface of PaperCut MF and PaperCut NG. Under specific conditions, unauthenticated remote requests targeting administrative functions can trigger backend actions prior to the completion of access validation checks. This allows an unauthenticated remote attacker to modify certain system configurations.
high
Vulnerability of Interest
CVE-2015-6783The FindStartOffsetOfFileInZipFile function in crazy_linker_zip.cpp in crazy_linker (aka Crazy Linker) in Android 5.x and 6.x, as used in Google Chrome before 47.0.2526.73, improperly searches for an EOCD record, which allows attackers to bypass a signature-validation requirement via a crafted ZIP archive.
medium
CVE-2026-40875mailcow: dockerized is an open source groupware/email suite based on docker. In versions prior to 2026-03b, the user dashboard's "Seen successful connections" (login history) renders the client IP from login logs without HTML escaping. Because the server trusts the X-Real-IP header as the source IP for logging, an attacker can inject HTML/JS into this field. This Self-XSS can be exploited by a Login CSRF to force the victim into the attacker's account, and then read emails in a previous browser tab. Version 2026-03b fixes the vulnerability.
high
CVE-2026-33399Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.7.0, the SSRF fix applied in version 4.6.2 for CVE-2026-30839 and CVE-2026-30840 is incomplete. The validate_webhook_url_for_ssrf() protection was added to the test* notification endpoints but not to the corresponding save* endpoints. An authenticated user can save an internal/private IP address as a notification URL, and when the cron job sendnotifications.php executes, the request is sent to the internal IP without any SSRF validation. This issue has been patched in version 4.7.0.
high
CVE-2021-38669Microsoft Edge (Chromium-based) Tampering Vulnerability
high
CVE-2022-23264Microsoft Edge (Chromium-based) Spoofing Vulnerability
medium
CVE-2023-29334Microsoft Edge (Chromium-based) Spoofing Vulnerability
medium
CVE-2024-21383Microsoft Edge (Chromium-based) Spoofing Vulnerability
low
CVE-2023-36727Microsoft Edge (Chromium-based) Spoofing Vulnerability
medium
CVE-2024-38083Microsoft Edge (Chromium-based) Spoofing Vulnerability
medium
CVE-2024-38221Microsoft Edge (Chromium-based) Spoofing Vulnerability
medium
CVE-2025-65046Microsoft Edge (Chromium-based) Spoofing Vulnerability
low
CVE-2026-45489Microsoft Edge (Chromium-based) Spoofing Vulnerability
medium
CVE-2026-37709Insecure Permissions vulnerability in grokability snipe-it v.8.4.0 and before and fixed after 2026-03-10 commit 676a9958 allows a remote attacker to execute arbitrary code via the app/Http/Controllers/Api/UploadedFilesController.php component
critical
CVE-2026-2476Mattermost Plugins versions <=2.0.3.0 fail to properly mask sensitive configuration values which allows an attacker with access to support packets to obtain original plugin settings via exported configuration data. Mattermost Advisory ID: MMSA-2026-00606
medium
CVE-2026-7474HashiCorp Nomad and Nomad Enterprise prior to 2.0.1 are vulnerable to code execution on the client host through a path traversal attack. This vulnerability (CVE-2026-7474) is fixed in Nomad 2.0.1, 1.11.5 and 1.10.11.
high
CVE-2026-56131libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_ResumeParser from within handlers in cases of a policy violation. Thus, a use-after-free can occur (similar to the CVE-2026-50219 situation).
medium
CVE-2021-30607Chromium: CVE-2021-30607 Use after free in Permissions
high
CVE-2021-30614Chromium: CVE-2021-30614 Heap buffer overflow in TabStrip
high
CVE-2023-38158Microsoft Edge (Chromium-based) Information Disclosure Vulnerability
low
CVE-2024-38222Microsoft Edge (Chromium-based) Information Disclosure Vulnerability
medium
CVE-2012-2025Adobe Illustrator before CS6 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2012-0780, CVE-2012-2023, CVE-2012-2024, and CVE-2012-2026.
critical
CVE-2021-33741Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
high
CVE-2021-36930Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
high
CVE-2022-21929Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
low
CVE-2022-30127Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
high
CVE-2022-26908Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
high
CVE-2022-24475Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
high
CVE-2022-29144Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
high
CVE-2023-21796Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
high
CVE-2023-21795Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
high
CVE-2023-23374Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
high
CVE-2023-29354Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability
medium
CVE-2023-38187Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
medium
CVE-2023-38157Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability
medium
CVE-2023-36741Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
high
CVE-2023-36014Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
high
CVE-2023-36024Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
high
CVE-2023-36008Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
medium
CVE-2024-26163Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability
medium
CVE-2024-26246Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability
low
CVE-2024-43566Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
critical
CVE-2024-43579Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
high