CVE Search

IDDescriptionSeverityUpdated
CVE-2026-78947Incomplete cleanup in Chromium in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to bypass web origin policy via a crafted Chrome extension. (Chromium security severity: Low)
medium
CVE-2016-1679The ToV8Value function in content/child/v8_value_converter_impl.cc in the V8 bindings in Google Chrome before 51.0.2704.63 does not properly restrict use of getters and setters, which allows remote attackers to cause a denial of service (use-after-free) or possibly have unspecified other impact via crafted JavaScript code.
high
CVE-2026-20988Improper verification of intent by broadcast receiver in Settings prior to SMR Mar-2026 Release 1 allows local attacker to launch arbitrary activity with Settings privilege. User interaction is required for triggering this vulnerability.
medium
CVE-2026-23561[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] XAPI can configure different users with different roles, using Role Based Access Control. For more details, see: https://docs.xenserver.com/en-us/xencenter/current-release/rbac-overview.html#rbac-roles The pool-admin role is fully privileged. Notably, users with this role can also SSH into the host as root. The other administrator roles are pool-operator, vm-power-admin and vm-admin, each of which are authorised to configure and manage various aspects of the system. Some settings are inadequately restricted, and can be set by a lower privilege of administrator than expected. * CVE-2026-23559: A vm-admin can set VBD.other_config:backend-local and turn arbitrary files in dom0 into VDIs (virtual disks) and give said disks to a VM they control. This is an arbitrary read and/or modify of files in dom0. * CVE-2026-23560: A vm-admin can set VM.other-config:is_system_domain and mark a VM as a system domain. System domains are ignored and left running during certain other host/pool operations, and may be hidden from view in tooling. * CVE-2026-23561: A vm-admin can set VM.other_config:storage_driver_domain and mark a VM as the storage domain for a particular host storage connection (PBD). Shutting down the VM can cause the PBD to be erroneously marked as unplugged when it is not. * CVE-2026-23562: Configuration of PCI passthrough is normally restricted to the pool-admin role. However one API was missing this check, allowing a vm-admin access to unintended host hardware. * CVE-2026-42486: A vm-admin can set the VM.platform:hvm_serial parameter, which should be restricted to the pool-admin role, as it can allow arbitrary dom0 file write.
critical
CVE-2024-11803Fuji Electric Tellus Lite V-Simulator 5 V8 File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Fuji Electric Tellus Lite. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of V8 files in the V-Simulator 5 component. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated data structure. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-24771.
high
CVE-2026-42799Out-of-bounds read vulnerability in ASR Kestrel (nr_fw modules) allows Overflow Buffers. This vulnerability is associated with program files Code/Nr/nr_fw/RA/src/NrPwrCtrl.C. This issue affects Kestrel: before 2026/02/10.
critical
CVE-2026-40949CVE-2026-40949 is a buffer overflow vulnerability in the Secure Access Windows client prior to 14.50. Attackers with local control of the Windows client can use it to trigger a denial of service.
medium
CVE-2026-55399CVE-2026-55399 is a resource exhaustion vulnerability in the Secure Access publisher prior to 14.55. Attackers with valid credentials to the Secure Access tunnel can create a non-persistent DoS against the publisher.
medium
CVE-2021-30619Chromium: CVE-2021-30619 UI Spoofing in Autofill
medium
CVE-2021-26436Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
high
CVE-2021-43221Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
medium
CVE-2022-21930Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
medium
CVE-2022-21954Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
medium
CVE-2022-21970Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
high
CVE-2022-26894Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
high
CVE-2022-26900Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
high
CVE-2022-26891Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
high
CVE-2022-44708Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
high
CVE-2022-33638Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
high
CVE-2023-21719Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability
medium
CVE-2023-36887Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
high
CVE-2023-28284Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability
medium
CVE-2024-26247Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability
medium
CVE-2023-36027Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
medium
CVE-2024-38219Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
critical
CVE-2025-21408Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
high
CVE-2025-21401Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability
medium
CVE-2022-29146Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
high
CVE-2022-38012Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
high
CVE-2023-36735Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
critical
CVE-2024-29987Microsoft Edge (Chromium-based) Information Disclosure Vulnerability
medium
CVE-2023-36409Microsoft Edge (Chromium-based) Information Disclosure Vulnerability
medium
CVE-2016-1653The LoadBuffer implementation in Google V8, as used in Google Chrome before 50.0.2661.75, mishandles data types, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via crafted JavaScript code that triggers an out-of-bounds write operation, related to compiler/pipeline.cc and compiler/simplified-lowering.cc.
high
CVE-2015-1207Double-free vulnerability in libavformat/mov.c in FFMPEG in Google Chrome 41.0.2251.0 allows remote attackers to cause a denial of service (memory corruption and crash) via a crafted .m4a file.
medium
CVE-2024-11799Fuji Electric Tellus Lite V-Simulator 5 V8 File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Fuji Electric Tellus Lite. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of V8 files in the V-Simulator 5 component. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-24664.
high
CVE-2016-9159A vulnerability has been identified in SIMATIC S7-300 CPU family (All versions), SIMATIC S7-300 CPU family (incl. related ET200 CPUs and SIPLUS variants) (All versions), SIMATIC S7-400 PN/DP V6 and below CPU family (incl. SIPLUS variants) (All versions), SIMATIC S7-400 PN/DP V7 CPU family (incl. SIPLUS variants) (All versions), SIMATIC S7-400 V6 and earlier CPU family (All versions), SIMATIC S7-400 V7 CPU family (All versions), SIMATIC S7-410 V8 CPU family (All versions), SIMATIC S7-410 V8 CPU family (incl. SIPLUS variants) (All versions). An attacker with network access to port 102/tcp (ISO-TSAP) or via Profibus could obtain credentials from the PLC if protection-level 2 is configured on the affected devices.
medium
CVE-2014-1706crosh in Google Chrome OS before 33.0.1750.152 allows attackers to inject commands via unspecified vectors.
critical
CVE-2026-33399Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.7.0, the SSRF fix applied in version 4.6.2 for CVE-2026-30839 and CVE-2026-30840 is incomplete. The validate_webhook_url_for_ssrf() protection was added to the test* notification endpoints but not to the corresponding save* endpoints. An authenticated user can save an internal/private IP address as a notification URL, and when the cron job sendnotifications.php executes, the request is sent to the internal IP without any SSRF validation. This issue has been patched in version 4.7.0.
high
CVE-2026-40875mailcow: dockerized is an open source groupware/email suite based on docker. In versions prior to 2026-03b, the user dashboard's "Seen successful connections" (login history) renders the client IP from login logs without HTML escaping. Because the server trusts the X-Real-IP header as the source IP for logging, an attacker can inject HTML/JS into this field. This Self-XSS can be exploited by a Login CSRF to force the victim into the attacker's account, and then read emails in a previous browser tab. Version 2026-03b fixes the vulnerability.
high
CVE-2021-30616Chromium: CVE-2021-30616 Use after free in Media
high
CVE-2021-30620Chromium: CVE-2021-30620 Insufficient policy enforcement in Blink
high
CVE-2022-41115Microsoft Edge (Chromium-based) Update Elevation of Privilege Vulnerability
medium
CVE-2024-29986Microsoft Edge for Android (Chromium-based) Information Disclosure Vulnerability
medium
CVE-2025-21399Microsoft Edge (Chromium-based) Update Elevation of Privilege Vulnerability
high
CVE-2026-37709Insecure Permissions vulnerability in grokability snipe-it v.8.4.0 and before and fixed after 2026-03-10 commit 676a9958 allows a remote attacker to execute arbitrary code via the app/Http/Controllers/Api/UploadedFilesController.php component
critical
CVE-2026-7474HashiCorp Nomad and Nomad Enterprise prior to 2.0.1 are vulnerable to code execution on the client host through a path traversal attack. This vulnerability (CVE-2026-7474) is fixed in Nomad 2.0.1, 1.11.5 and 1.10.11.
high
CVE-2026-2476Mattermost Plugins versions <=2.0.3.0 fail to properly mask sensitive configuration values which allows an attacker with access to support packets to obtain original plugin settings via exported configuration data. Mattermost Advisory ID: MMSA-2026-00606
medium
CVE-2026-56131libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_ResumeParser from within handlers in cases of a policy violation. Thus, a use-after-free can occur (similar to the CVE-2026-50219 situation).
medium
CVE-2026-6342Mattermost Plugins versions <=11.5 11.1.5 10.13.11 11.3.4.0 fail to appropriately check for valid namespaces which allows plugin users to create subscriptions to groups that were not whitelisted via creating groups that share the same prefix as a whitelisted group. Mattermost Advisory ID: MMSA-2026-00601
medium
CVE-2026-42600MinIO is a high-performance object storage system. From RELEASE.2022-07-24T01-54-52Z to before RELEASE.2026-04-14T21-32-45Z, A path traversal vulnerability in MinIO's ReadMultiple internode storage-REST endpoint allows a caller holding the cluster root JWT to read files from outside the configured drive roots, bounded only by the MinIO process UID. The attacker sends POST minio/storage/{drivePath}/v63/rmpl with a msgpack-encoded body carrying ../ sequences in the Bucket field. The server opens the resulting path via os.OpenFile with O_RDONLY|O_NOATIME and returns its contents in the msgpack response stream. This vulnerability is fixed in RELEASE.2026-04-14T21-32-45Z.
medium