2026 · HIGH + CRITICAL · CVE Project mirror
Recent CVEs
Search 2026 HIGH and CRITICAL vulnerabilities ingested from the CVE Project V5 mirror. Refreshed every 5 minutes.
2,151 critical7,899 highLast ingest 2m ago@d61c1f3
100 most recent · with fix
CVE
Title / Vendor
Fix
CVSS
Severity
- CVE-2026-485572026-05-29Spatie Laravel Media Library < 11.23.0 File Upload Restriction Bypass via FileAdder.phpspatie / laravel-medialibrary11.23.01 patch8.7v4.0HIGH
- CVE-2026-493742026-05-29In JetBrains TeamCity before 2026JetBrains / TeamCity2026.17.6v3.1HIGH
- CVE-2026-493732026-05-29In JetBrains TeamCity before 2026JetBrains / TeamCity2026.17.1v3.1HIGH
- CVE-2026-493722026-05-29In JetBrains TeamCity before 2026JetBrains / TeamCity2026.1, 2025.11.57.5v3.1HIGH
- CVE-2026-493712026-05-29In JetBrains TeamCity before 2026JetBrains / TeamCity2026.1.17.1v3.1HIGH
- CVE-2026-493682026-05-29In JetBrains YouTrack before 2026JetBrains / YouTrack2026.1.131628.7v3.1HIGH
- CVE-2026-493672026-05-29In JetBrains IntelliJ IDEA before 2026JetBrains / IntelliJ IDEA2026.1.18.0v3.1HIGH
- CVE-2026-493662026-05-29In JetBrains IntelliJ IDEA before 2026JetBrains / IntelliJ IDEA2026.1.17.8v3.1HIGH
- CVE-2026-429292026-05-29MacGregor Voyage Data Recorder (VDR) G4e Use of Hard-coded CredentialsDanelec / MacGregor Voyage Data Recorder (VDR) G4e5.2508.7v4.0HIGH
- CVE-2026-429412026-05-29MacGregor Voyage Data Recorder (VDR) G4e Use of Default CredentialsDanelec / MacGregor Voyage Data Recorder (VDR) G4e5.2508.7v4.0HIGH
- CVE-2026-57682026-05-29Fourth Frontier Frontier X Mobile Application, Frontier X2 Missing Authentication for Critical FunctionFourth Frontier / Frontier X Android application · Fourth Frontier / Frontier X IOS application · Fourth Frontier / Frontier X215.0.0+1 more8.8v3.1HIGH
- CVE-2026-449622026-05-29Plesk contains an XPath injection vulnerability in the APS Application Catalog search functionality, where user-supplied input is interpolated into XPath queries without proper sanitizationWebPros / Plesk18.0.75.1+1 more10.0v3.1CRITICAL
- CVE-2026-356742026-05-29OpenClaw < 2026.5.18 - Scope Bypass via Inherited chat.send RouteOpenClaw / OpenClaw2026.5.188.7v4.0HIGH
- CVE-2026-356302026-05-29OpenClaw < 2026.5.18 - QQBot Missing Approver Identity Enforcement in Native Approval ButtonsOpenClaw / OpenClaw2026.5.187.5v4.0HIGH
- CVE-2026-329052026-05-29OpenClaw < 2026.5.4 - Unauthorized Device-Pairing Bootstrap Code Issuance via Chat CommandOpenClaw / OpenClaw2026.5.48.7v4.0HIGH
- CVE-2026-95082026-05-29Incorrect Permission Assignment for Critical Resource vulnerability in Suprema's BioStarSuprema / BioStar 2 (server)v2.9.121 patch10.0v4.0CRITICAL
- CVE-2026-83262026-05-29Remote Spark SparkView Path Traversal in RDP Drive Redirection leading to RCERemote Spark (https://www.remotespark.com/) / SparkViewbuild 112710.0v4.0CRITICAL
- CVE-2026-98092026-05-29A stored Cross-Site Scripting (XSS) vulnerability exists in the Projects component of Mautic 7Mautic7.1.27.6v3.1HIGH
- CVE-2026-98082026-05-29An authorization bypass vulnerability exists in the Mautic 7 API v2 endpoints (utilizing API Platform)Mautic7.1.27.1v3.1HIGH
- CVE-2026-95592026-05-29A path traversal vulnerability exists in the campaign import feature of Mautic 7Mautic7.1.29.9v3.1CRITICAL
- CVE-2026-95582026-05-29A Server-Side Template Injection (SSTI) vulnerability exists in Mautic's theme engineMautic4.4.20+3 more9.9v3.1CRITICAL
- CVE-2026-100562026-05-29CORS misconfiguration in Nx Witness VMS allows session token exfiltration via cross-origin requestNetwork Optix / Nx Witness VMS6.1.27.5v3.1HIGH
- CVE-2026-47762026-05-29An SQL injection vulnerability exists in Mautic's API contact filtering mechanismMautic4.4.20+3 more7.1v3.1HIGH
- CVE-2026-53432026-05-28SAML SSO - Service Provider - Critical - Authentication bypass - SA-CONTRIB-2026-031Drupal / SAML SSO - Service Provider3.1.47.4v3.1HIGH
- CVE-2026-100222026-05-28Type Confusion in V8 in Google Chrome prior to 148Google / Chrome148.0.7778.2168.8v3.1HIGH
- CVE-2026-100212026-05-28Insufficient validation of untrusted input in USB in Google Chrome prior to 148Google / Chrome148.0.7778.2168.8v3.1HIGH
- CVE-2026-100202026-05-28Insufficient validation of untrusted input in Skia in Google Chrome on Android prior to 148Google / Chrome148.0.7778.2168.3v3.1HIGH
- CVE-2026-100172026-05-28Out of bounds read in Headless in Google Chrome prior to 148Google / Chrome148.0.7778.2168.3v3.1HIGH
- CVE-2026-100162026-05-28Use after free in DOM in Google Chrome prior to 148Google / Chrome148.0.7778.2168.8v3.1HIGH
- CVE-2026-100152026-05-28Integer overflow in WTF in Google Chrome prior to 148Google / Chrome148.0.7778.2168.8v3.1HIGH
- CVE-2026-100142026-05-28Use after free in WebMIDI in Google Chrome on Android prior to 148Google / Chrome148.0.7778.2168.3v3.1HIGH
- CVE-2026-100132026-05-28Use after free in WebCodecs in Google Chrome prior to 148Google / Chrome148.0.7778.2168.8v3.1HIGH
- CVE-2026-100122026-05-28Use after free in Skia in Google Chrome prior to 148Google / Chrome148.0.7778.2168.3v3.1HIGH
- CVE-2026-100092026-05-28Integer overflow in Skia in Google Chrome prior to 148Google / Chrome148.0.7778.2167.5v3.1HIGH
- CVE-2026-100072026-05-28Use after free in SVG in Google Chrome prior to 148Google / Chrome148.0.7778.2168.8v3.1HIGH
- CVE-2026-100062026-05-28Race in WebAudio in Google Chrome prior to 148Google / Chrome148.0.7778.2167.5v3.1HIGH
- CVE-2026-100052026-05-28Use after free in WebAppInstalls in Google Chrome on Mac prior to 148Google / Chrome148.0.7778.2167.5v3.1HIGH
- CVE-2026-100032026-05-28Use after free in Views in Google Chrome prior to 148Google / Chrome148.0.7778.2167.5v3.1HIGH
- CVE-2026-100022026-05-28Use after free in PDFium in Google Chrome prior to 148Google / Chrome148.0.7778.2168.8v3.1HIGH
- CVE-2026-100012026-05-28Use after free in PerformanceManager in Google Chrome prior to 148Google / Chrome148.0.7778.2168.3v3.1HIGH
- CVE-2026-100002026-05-28Use after free in Passwords in Google Chrome on Windows prior to 148Google / Chrome148.0.7778.2168.3v3.1HIGH
- CVE-2026-99992026-05-28Inappropriate implementation in ANGLE in Google Chrome on Mac prior to 148Google / Chrome148.0.7778.2168.8v3.1HIGH
- CVE-2026-99982026-05-28Integer overflow in Skia in Google Chrome prior to 148Google / Chrome148.0.7778.2168.3v3.1HIGH
- CVE-2026-99972026-05-28Use after free in Input in Google Chrome prior to 148Google / Chrome148.0.7778.2168.3v3.1HIGH
- CVE-2026-99952026-05-28Use after free in WebXR in Google Chrome prior to 148Google / Chrome148.0.7778.2168.8v3.1HIGH
- CVE-2026-99942026-05-28Use after free in Core in Google Chrome on Windows prior to 148Google / Chrome148.0.7778.2168.3v3.1HIGH
- CVE-2026-99932026-05-28Use after free in Views in Google Chrome prior to 148Google / Chrome148.0.7778.2168.3v3.1HIGH
- CVE-2026-99922026-05-28Use after free in Network in Google Chrome prior to 148Google / Chrome148.0.7778.2168.8v3.1HIGH
- CVE-2026-99902026-05-28Use after free in WebAppInstalls in Google Chrome on Mac prior to 148Google / Chrome148.0.7778.2167.5v3.1HIGH
- CVE-2026-99882026-05-28Use after free in WebRTC in Google Chrome on Linux prior to 148Google / Chrome148.0.7778.2168.3v3.1HIGH
- CVE-2026-99872026-05-28Insufficient validation of untrusted input in WebAppInstalls in Google Chrome on Android prior to 148Google / Chrome148.0.7778.2167.8v3.1HIGH
- CVE-2026-99842026-05-28Use after free in UI in Google Chrome on Windows prior to 148Google / Chrome148.0.7778.2168.8v3.1HIGH
- CVE-2026-99832026-05-28Type Confusion in Skia in Google Chrome prior to 148Google / Chrome148.0.7778.2168.8v3.1HIGH
- CVE-2026-99822026-05-28Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 148Google / Chrome148.0.7778.2168.3v3.1HIGH
- CVE-2026-99782026-05-28Use after free in Glic in Google Chrome prior to 148Google / Chrome148.0.7778.2168.8v3.1HIGH
- CVE-2026-99772026-05-28Insufficient validation of untrusted input in WebShare in Google Chrome on Android prior to 148Google / Chrome148.0.7778.2168.3v3.1HIGH
- CVE-2026-99762026-05-28Inappropriate implementation in USB in Google Chrome prior to 148Google / Chrome148.0.7778.2168.8v3.1HIGH
- CVE-2026-99752026-05-28Out of bounds read and write in ANGLE in Google Chrome prior to 148Google / Chrome148.0.7778.2168.3v3.1HIGH
- CVE-2026-99742026-05-28Out of bounds write in GPU in Google Chrome prior to 148Google / Chrome148.0.7778.2168.3v3.1HIGH
- CVE-2026-99732026-05-28Out of bounds write in V8 in Google Chrome prior to 148Google / Chrome148.0.7778.2168.8v3.1HIGH
- CVE-2026-99722026-05-28Uninitialized Use in Gamepad in Google Chrome on Mac prior to 148Google / Chrome148.0.7778.2168.3v3.1HIGH
- CVE-2026-99702026-05-28Use after free in WebGL in Google Chrome prior to 148Google / Chrome148.0.7778.2168.3v3.1HIGH
- CVE-2026-99692026-05-28Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 148Google / Chrome148.0.7778.2168.8v3.1HIGH
- CVE-2026-99682026-05-28Integer overflow in V8 in Google Chrome prior to 148Google / Chrome148.0.7778.2168.8v3.1HIGH
- CVE-2026-99672026-05-28Out of bounds write in GPU in Google Chrome prior to 148Google / Chrome148.0.7778.2169.6v3.1CRITICAL
- CVE-2026-99662026-05-28Integer overflow in XML in Google Chrome on Windows prior to 148Google / Chrome148.0.7778.2168.3v3.1HIGH
- CVE-2026-99652026-05-28Out of bounds write in ANGLE in Google Chrome prior to 148Google / Chrome148.0.7778.2168.8v3.1HIGH
- CVE-2026-99642026-05-28Use after free in Bluetooth in Google Chrome on Mac prior to 148Google / Chrome148.0.7778.2168.1v3.1HIGH
- CVE-2026-99632026-05-28Uninitialized Use in iOS in Google Chrome on iOS prior to 148Google / Chrome148.0.7778.2167.5v3.1HIGH
- CVE-2026-99622026-05-28Use after free in WebRTC in Google Chrome prior to 148Google / Chrome148.0.7778.2168.8v3.1HIGH
- CVE-2026-99612026-05-28Use after free in SurfaceCapture in Google Chrome prior to 148Google / Chrome148.0.7778.2168.8v3.1HIGH
- CVE-2026-99602026-05-28Integer overflow in PDFium in Google Chrome prior to 148Google / Chrome148.0.7778.2167.5v3.1HIGH
- CVE-2026-99582026-05-28Use after free in PDFium in Google Chrome prior to 148Google / Chrome148.0.7778.2168.8v3.1HIGH
- CVE-2026-99572026-05-28Use after free in PDF in Google Chrome prior to 148Google / Chrome148.0.7778.2168.8v3.1HIGH
- CVE-2026-99562026-05-28Use after free in iOS in Google Chrome on iOS prior to 148Google / Chrome148.0.7778.2167.5v3.1HIGH
- CVE-2026-99542026-05-28Use after free in TabStrip in Google Chrome prior to 148Google / Chrome148.0.7778.2167.5v3.1HIGH
- CVE-2026-99522026-05-28Use after free in WebAudio in Google Chrome prior to 148Google / Chrome148.0.7778.2168.8v3.1HIGH
- CVE-2026-99512026-05-28Use after free in UI in Google Chrome prior to 148Google / Chrome148.0.7778.2168.3v3.1HIGH
- CVE-2026-99492026-05-28Use after free in Core in Google Chrome on Windows prior to 148Google / Chrome148.0.7778.2168.3v3.1HIGH
- CVE-2026-99482026-05-28Use after free in Views in Google Chrome on Mac prior to 148Google / Chrome148.0.7778.2168.3v3.1HIGH
- CVE-2026-99472026-05-28Use after free in XML in Google Chrome prior to 148Google / Chrome148.0.7778.2168.8v3.1HIGH
- CVE-2026-99462026-05-28Use after free in ANGLE in Google Chrome prior to 148Google / Chrome148.0.7778.2168.3v3.1HIGH
- CVE-2026-99452026-05-28Use after free in Media in Google Chrome on Windows prior to 148Google / Chrome148.0.7778.2168.8v3.1HIGH
- CVE-2026-99412026-05-28Use after free in ANGLE in Google Chrome prior to 148Google / Chrome148.0.7778.2168.8v3.1HIGH
- CVE-2026-99402026-05-28Heap buffer overflow in ANGLE in Google Chrome prior to 148Google / Chrome148.0.7778.2168.8v3.1HIGH
- CVE-2026-99392026-05-28Heap buffer overflow in WebCodecs in Google Chrome prior to 148Google / Chrome148.0.7778.2168.8v3.1HIGH
- CVE-2026-99382026-05-28Inappropriate implementation in V8 in Google Chrome prior to 148Google / Chrome148.0.7778.2168.8v3.1HIGH
- CVE-2026-99372026-05-28Use after free in UI in Google Chrome on Windows prior to 148Google / Chrome148.0.7778.2168.3v3.1HIGH
- CVE-2026-99362026-05-28Use after free in GFX in Google Chrome on Mac prior to 148Google / Chrome148.0.7778.2168.3v3.1HIGH
- CVE-2026-99342026-05-28Use after free in Aura in Google Chrome prior to 148Google / Chrome148.0.7778.2167.5v3.1HIGH
- CVE-2026-99332026-05-28Use after free in Input in Google Chrome prior to 148Google / Chrome148.0.7778.2167.5v3.1HIGH
- CVE-2026-99322026-05-28Use after free in ANGLE in Google Chrome on Windows prior to 148Google / Chrome148.0.7778.2168.3v3.1HIGH
- CVE-2026-99312026-05-28Use after free in GPU in Google Chrome prior to 148Google / Chrome148.0.7778.2168.3v3.1HIGH
- CVE-2026-99282026-05-28Out of bounds read in ANGLE in Google Chrome on Windows prior to 148Google / Chrome148.0.7778.2168.8v3.1HIGH
- CVE-2026-99272026-05-28Use after free in ANGLE in Google Chrome prior to 148Google / Chrome148.0.7778.2168.8v3.1HIGH
- CVE-2026-99262026-05-28Heap buffer overflow in ANGLE in Google Chrome prior to 148Google / Chrome148.0.7778.2168.3v3.1HIGH
- CVE-2026-99252026-05-28Use after free in ANGLE in Google Chrome prior to 148Google / Chrome148.0.7778.2168.3v3.1HIGH
- CVE-2026-99242026-05-28Heap buffer overflow in ANGLE in Google Chrome on Windows prior to 148Google / Chrome148.0.7778.2168.3v3.1HIGH
- CVE-2026-99232026-05-28Use after free in Skia in Google Chrome prior to 148Google / Chrome148.0.7778.2168.8v3.1HIGH
- CVE-2026-99222026-05-28Use after free in GPU in Google Chrome on Mac prior to 148Google / Chrome148.0.7778.2167.5v3.1HIGH