CVE Feed

    Dashboard / CVE

    4.3
    Medium

    CVE-2026-17693

    Last Modified: 3 Aug 2026

    Insufficient policy enforcement in FileSystem in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)

    Published: 30 Jul 2026
    9.6
    Critical

    CVE-2026-17692

    Last Modified: 31 Jul 2026

    Use after free in DataTransfer in Google Chrome on Windows prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

    Published: 30 Jul 2026
    9.6
    Critical

    CVE-2026-17691

    Last Modified: 30 Jul 2026

    Out of bounds write in ANGLE in Google Chrome on Windows prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

    Published: 30 Jul 2026
    4.3
    Medium

    CVE-2026-17689

    Last Modified: 30 Jul 2026

    Uninitialized Use in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)

    Published: 30 Jul 2026
    6.5
    Medium

    CVE-2026-17690

    Last Modified: 30 Jul 2026

    Insufficient validation of untrusted input in PDF in Google Chrome on Android prior to 151.0.7922.72 allowed a local attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)

    Published: 30 Jul 2026
    9.6
    Critical

    CVE-2026-17688

    Last Modified: 31 Jul 2026

    Use after free in Input in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

    Published: 30 Jul 2026
    9.6
    Critical

    CVE-2026-17687

    Last Modified: 31 Jul 2026

    Type Confusion in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

    Published: 30 Jul 2026
    8.1
    High

    CVE-2026-17686

    Last Modified: 30 Jul 2026

    Insufficient validation of untrusted input in Passwords in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: High)

    Published: 30 Jul 2026
    8.8
    High

    CVE-2026-17685

    Last Modified: 31 Jul 2026

    Use after free in Autofill in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

    Published: 30 Jul 2026
    9.6
    Critical

    CVE-2026-17684

    Last Modified: 4 Aug 2026

    Insufficient validation of untrusted input in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

    Published: 30 Jul 2026
    6.5
    Medium

    CVE-2026-17683

    Last Modified: 31 Jul 2026

    Inappropriate implementation in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High)

    Published: 30 Jul 2026
    9.6
    Critical

    CVE-2026-17681

    Last Modified: 31 Jul 2026

    Insufficient validation of untrusted input in Web Authentication in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

    Published: 30 Jul 2026
    9.6
    Critical

    CVE-2026-17680

    Last Modified: 31 Jul 2026

    Heap buffer overflow in Color in Google Chrome on ChromeOS prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

    Published: 30 Jul 2026
    9.6
    Critical

    CVE-2026-17682

    Last Modified: 30 Jul 2026

    Integer overflow in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

    Published: 30 Jul 2026
    6.5
    Medium

    CVE-2026-17679

    Last Modified: 30 Jul 2026

    Insufficient validation of untrusted input in Print Preview in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)

    Published: 30 Jul 2026
    8.8
    High

    CVE-2026-17678

    Last Modified: 30 Jul 2026

    Out of bounds read in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

    Published: 30 Jul 2026
    9.6
    Critical

    CVE-2026-17676

    Last Modified: 31 Jul 2026

    Inappropriate implementation in ANGLE in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

    Published: 30 Jul 2026
    8.8
    High

    CVE-2026-17677

    Last Modified: 30 Jul 2026

    Inappropriate implementation in ANGLE in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

    Published: 30 Jul 2026
    9.6
    Critical

    CVE-2026-17675

    Last Modified: 31 Jul 2026

    Out of bounds write in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

    Published: 30 Jul 2026
    6.5
    Medium

    CVE-2026-17674

    Last Modified: 5 Aug 2026

    Inappropriate implementation in HTML in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to bypass content security policy via a crafted HTML page. (Chromium security severity: High)

    Published: 30 Jul 2026
    9.6
    Critical

    CVE-2026-17672

    Last Modified: 30 Jul 2026

    Insufficient validation of untrusted input in Chromecast in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

    Published: 30 Jul 2026
    9.6
    Critical

    CVE-2026-17673

    Last Modified: 30 Jul 2026

    Integer overflow in QUIC in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

    Published: 30 Jul 2026
    9.6
    Critical

    CVE-2026-17670

    Last Modified: 31 Jul 2026

    Use after free in Views in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

    Published: 30 Jul 2026
    9.6
    Critical

    CVE-2026-17669

    Last Modified: 4 Aug 2026

    Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

    Published: 30 Jul 2026
    9.6
    Critical

    CVE-2026-17671

    Last Modified: 30 Jul 2026

    Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

    Published: 30 Jul 2026
    6.5
    Medium

    CVE-2026-17668

    Last Modified: 31 Jul 2026

    Uninitialized Use in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)

    Published: 30 Jul 2026
    6.5
    Medium

    CVE-2026-17667

    Last Modified: 31 Jul 2026

    Uninitialized Use in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)

    Published: 30 Jul 2026
    9.1
    Critical

    CVE-2026-17666

    Last Modified: 30 Jul 2026

    Cryptographic Flaw in Enterprise in Google Chrome prior to 151.0.7922.72 allowed an attacker in a privileged network position to bypass discretionary access control via malicious network traffic. (Chromium security severity: High)

    Published: 30 Jul 2026
    8.8
    High

    CVE-2026-17665

    Last Modified: 31 Jul 2026

    Use after free in V8 in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

    Published: 30 Jul 2026
    4.3
    Medium

    CVE-2026-17662

    Last Modified: 30 Jul 2026

    Insufficient policy enforcement in Prefetch in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)

    Published: 30 Jul 2026
    6.5
    Medium

    CVE-2026-17664

    Last Modified: 31 Jul 2026

    Insufficient validation of untrusted input in Loader in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)

    Published: 30 Jul 2026
    8.3
    High

    CVE-2026-17663

    Last Modified: 31 Jul 2026

    Insufficient validation of untrusted input in GPU in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

    Published: 30 Jul 2026
    8.8
    High

    CVE-2026-17661

    Last Modified: 31 Jul 2026

    Use after free in Loader in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

    Published: 30 Jul 2026
    8.3
    High

    CVE-2026-17660

    Last Modified: 31 Jul 2026

    Insufficient validation of untrusted input in Network in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

    Published: 30 Jul 2026
    4.2
    Medium

    CVE-2026-17659

    Last Modified: 30 Jul 2026

    Inappropriate implementation in SiteIsolation in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: High)

    Published: 30 Jul 2026
    8.8
    High

    CVE-2026-17658

    Last Modified: 31 Jul 2026

    Use after free in V8 in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

    Published: 30 Jul 2026
    8.3
    High

    CVE-2026-17657

    Last Modified: 31 Jul 2026

    Use after free in Navigation in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

    Published: 30 Jul 2026
    9.6
    Critical

    CVE-2026-17656

    Last Modified: 31 Jul 2026

    Use after free in Ozone in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)

    Published: 30 Jul 2026
    9.6
    Critical

    CVE-2026-17655

    Last Modified: 31 Jul 2026

    Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)

    Published: 30 Jul 2026
    7.8
    High

    CVE-2026-17654

    Last Modified: 31 Jul 2026

    Race in Updater in Google Chrome on Mac prior to 151.0.7922.72 allowed a local attacker to perform OS-level privilege escalation via a malicious file. (Chromium security severity: Critical)

    Published: 30 Jul 2026
    8.3
    High

    CVE-2026-17653

    Last Modified: 31 Jul 2026

    Use after free in Skia in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)

    Published: 30 Jul 2026
    9.6
    Critical

    CVE-2026-17652

    Last Modified: 31 Jul 2026

    Use after free in Views in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)

    Published: 30 Jul 2026
    9.6
    Critical

    CVE-2026-17651

    Last Modified: 31 Jul 2026

    Insufficient validation of untrusted input in Dawn in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)

    Published: 30 Jul 2026
    8.3
    High

    CVE-2026-17650

    Last Modified: 31 Jul 2026

    Use after free in Compositing in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)

    Published: 30 Jul 2026
    6.9
    Medium

    CVE-2026-59952

    Last Modified: 30 Jul 2026

    Valibot helps validate data using a schema. Versions prior to 1.4.2 can throw a TypeError inside its flatten() helper when validation issues contain attacker-controlled object keys such as toString, valueOf, or hasOwnProperty. The issue is reachable through normal record() validation. record() intentionally filters __proto__, prototype, and constructor, but it still accepts other own keys that collide with inherited Object.prototype properties. If the record key schema or value schema rejects such an entry, Valibot creates an issue path containing that key. Passing the resulting issues to Valibot's documented flatten() helper causes flatErrors.nested[dotPath] to resolve to the inherited method instead of an own error array, and the helper calls .push(...) on that function. This is not a global prototype pollution issue. The impact is availability/error handling: applications that validate user-controlled objects with record() and flatten validation errors for API responses can crash the request path with a TypeError instead of returning structured validation errors. This issue has been fixed in version 1.4.2.

    Published: 30 Jul 2026
    5.1
    Medium

    CVE-2026-62946

    Last Modified: 30 Jul 2026

    ImageMagick is free and open-source software used for editing and manipulating digital images. In versions prior to both 6.9.13-52 and 7.1.2-27, processing an extremely large JNX file on 32-bit platforms can cause an integer overflow, leading to a heap buffer over-write. This issue has been fixed in versions 6.9.13-52 and 7.1.2-27.

    Published: 30 Jul 2026
    5
    Medium

    CVE-2026-62363

    Last Modified: 30 Jul 2026

    ImageMagick is free and open-source software used for editing and manipulating digital images. In versions prior to 7.1.2-27, a heap buffer over-write can occur in the fx operation by passing a crafted argument. This issue has been fixed in version 7.1.2-27.

    Published: 30 Jul 2026
    7.8
    High

    CVE-2026-63622

    Last Modified: 9 Sept 2026

    A flaw was found in libvirt. A local attacker, specifically a process running as the confined `swtpm` user, could exploit a symlink-following vulnerability in the `virFileChownFiles()` function. By planting a symbolic link within the `swtpm` state directory, the attacker could trick the root-level libvirt daemon into changing the ownership of an arbitrary file to the `swtpm` user. This allows for privilege escalation from the `swtpm` sandbox to root-level file ownership control.

    Published: 30 Jul 2026
    7.8
    High

    CVE-2026-16524

    Last Modified: 18 Aug 2026

    A command injection flaw in PCP's linux_sockets PMDA allows malicious shell metacharacters via the network.persocket.filter metric. This failed validation lets attackers execute arbitrary commands as the PMDA user when metrics refresh.

    Published: 30 Jul 2026
    7.6
    High

    CVE-2026-18378

    Last Modified: 17 Aug 2026

    A flaw was found in koku-metrics-operator. The operator's CostManagementMetricsConfig custom resource allows user able to edit the CR to specify an arbitrary upload URL. When authentication.type is set to token (the default), the cluster-global Red Hat Cloud pull-secret bearer token is attached to HTTP requests sent to this user-controlled URL, allowing the attacker to obtain the token.

    Published: 30 Jul 2026