125 CVEs — updated 2026-08-04 · vulnfeed
| CVE / ID | Title | Severity | CVSS | EPSS | Source | Date |
|---|---|---|---|---|---|---|
| CVE-2026-13435 | IBM Langflow OSS 1.0.0 through 1.10.1 contains an improper input validation vulnerability in the PythonREPL sandbox impl | CRITICAL | 9.9 | 21%ile | NVD | 2026-07-30 |
| CVE-2026-17651 | Insufficient validation of untrusted input in Dawn in Google Chrome on Android prior to 151.0.7922.72 allowed a remote a | CRITICAL | 9.6 | 32%ile | NVD | 2026-07-30 |
| CVE-2026-17655 | Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to | CRITICAL | 9.6 | 34%ile | NVD | 2026-07-30 |
| CVE-2026-17671 | Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker wh | CRITICAL | 9.6 | 30%ile | NVD | 2026-07-30 |
| CVE-2026-17672 | Insufficient validation of untrusted input in Chromecast in Google Chrome prior to 151.0.7922.72 allowed a remote attack | CRITICAL | 9.6 | 30%ile | NVD | 2026-07-30 |
| CVE-2026-17681 | Insufficient validation of untrusted input in Web Authentication in Google Chrome on Android prior to 151.0.7922.72 allo | CRITICAL | 9.6 | 35%ile | NVD | 2026-07-30 |
| CVE-2026-17684 | Insufficient validation of untrusted input in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a re | CRITICAL | 9.6 | 30%ile | NVD | 2026-07-30 |
| CVE-2026-17713 | Insufficient validation of untrusted input in Accessibility in Google Chrome on Android prior to 151.0.7922.72 allowed a | CRITICAL | 9.6 | 30%ile | NVD | 2026-07-30 |
| CVE-2026-17738 | Insufficient validation of untrusted input in Payments in Google Chrome prior to 151.0.7922.72 allowed a remote attacker | CRITICAL | 9.6 | 20%ile | NVD | 2026-07-30 |
| CVE-2026-17749 | Insufficient validation of untrusted input in Extensions in Google Chrome prior to 151.0.7922.72 allowed an attacker who | CRITICAL | 9.6 | 12%ile | NVD | 2026-07-30 |
| CVE-2026-17768 | Insufficient validation of untrusted input in WebSockets in Google Chrome prior to 151.0.7922.72 allowed a remote attack | CRITICAL | 9.6 | 20%ile | NVD | 2026-07-30 |
| CVE-2026-17803 | Insufficient validation of untrusted input in Save to Drive in Google Chrome prior to 151.0.7922.72 allowed a remote att | CRITICAL | 9.6 | 21%ile | NVD | 2026-07-30 |
| CVE-2026-17834 | Insufficient validation of untrusted input in Passwords in Google Chrome prior to 151.0.7922.72 allowed a remote attacke | CRITICAL | 9.6 | 17%ile | NVD | 2026-07-30 |
| CVE-2026-17837 | Insufficient validation of untrusted input in DevTools in Google Chrome prior to 151.0.7922.72 allowed a remote attacker | CRITICAL | 9.6 | 17%ile | NVD | 2026-07-30 |
| CVE-2026-17847 | Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to | CRITICAL | 9.6 | 20%ile | NVD | 2026-07-30 |
| CVE-2026-17848 | Integer overflow in Codecs in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sa | CRITICAL | 9.6 | 17%ile | NVD | 2026-07-30 |
| CVE-2026-17940 | Insufficient validation of untrusted input in Picture-in-Picture in Google Chrome on Android prior to 151.0.7922.72 allo | CRITICAL | 9.6 | 17%ile | NVD | 2026-07-30 |
| CVE-2026-17987 | Insufficient validation of untrusted input in Notifications in Google Chrome prior to 151.0.7922.72 allowed a remote att | CRITICAL | 9.6 | 13%ile | NVD | 2026-07-30 |
| CVE-2026-17990 | Insufficient validation of untrusted input in WebAuthn in Google Chrome prior to 151.0.7922.72 allowed a remote attacker | CRITICAL | 9.6 | 13%ile | NVD | 2026-07-30 |
| CVE-2026-17991 | Insufficient validation of untrusted input in AI in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who h | CRITICAL | 9.6 | 16%ile | NVD | 2026-07-30 |
| CVE-2026-18002 | Insufficient validation of untrusted input in Google Lens in Google Chrome prior to 151.0.7922.72 allowed a remote attac | CRITICAL | 9.6 | 10%ile | NVD | 2026-07-30 |
| CVE-2026-67330 | @better-auth/scim (a better-auth plugin) versions >= 1.4.0-beta.27 through <= 1.6.21 and >= 1.7.0-beta.0 through <= 1.7. | CRITICAL | 9.4 | 28%ile | NVD | 2026-08-01 |
| CVE-2026-59650 | In Bouncy Castle for Java before 1.85, MTI/A0 DH agreement exponentiates unvalidated peer value. This issue also affects | CRITICAL | 9.3 | 18%ile | NVD | 2026-08-03 |
| CVE-2026-18801 | OpenMeter contains a stored, or second-order, SQL injection vulnerability in the handling of customer usage-attribution | CRITICAL | 9.3 | — | NVD | 2026-08-04 |
| CVE-2025-4318 | AWS Amplify Studio UI Component Properties Has an Input Validation Issue | CRITICAL | — | 57%ile | GitHub | 2026-07-30 |
| CVE-2026-17786 | Insufficient validation of untrusted input in DevTools in Google Chrome prior to 151.0.7922.72 allowed an attacker who c | HIGH | 8.8 | 12%ile | NVD | 2026-07-30 |
| CVE-2026-22622 | Improper input validation in one of the session management interface of Eaton's Tripp Lite series PADM firmware could al | HIGH | 8.8 | 23%ile | NVD | 2026-07-30 |
| CVE-2025-71399 | Better Auth relies on better-call, which uses the rou3 router library. In affected versions of rou3, paths are normalize | HIGH | 8.8 | 23%ile | NVD | 2026-08-02 |
| CVE-2026-67296 | FreeRDP before 3.29.0 contains a denial of service vulnerability in the RDPEI server channel handler that fails to valid | HIGH | 8.7 | 27%ile | NVD | 2026-08-01 |
| CVE-2026-22620 | Improper input validation in the authentication component of Eaton's Tripp Lite series PADM firmware could allow an unau | HIGH | 8.6 | 29%ile | NVD | 2026-07-30 |
| CVE-2026-67436 | Linuxfabrik monitoring-plugins provides Python monitoring plugins for Icinga, Nagios, and related monitoring systems. In | HIGH | 8.3 | 16%ile | NVD | 2026-07-29 |
| CVE-2026-17660 | Insufficient validation of untrusted input in Network in Google Chrome prior to 151.0.7922.72 allowed a remote attacker | HIGH | 8.3 | 31%ile | NVD | 2026-07-30 |
| CVE-2026-17663 | Insufficient validation of untrusted input in GPU in Google Chrome on Android prior to 151.0.7922.72 allowed a remote at | HIGH | 8.3 | 27%ile | NVD | 2026-07-30 |
| CVE-2026-22621 | Improper input validation in one of the session management interface of Eaton's Tripp Lite Series PADM firmware could al | HIGH | 8.3 | 45%ile | NVD | 2026-07-30 |
| CVE-2026-58183 | The Apache Traffic Server prefetch plugin can crash when processing attacker-influenced input. This issue affects Apach | HIGH | 8.2 | 41%ile | NVD | 2026-07-29 |
| CVE-2026-58186 | The Apache Traffic Server webp_transform plugin can decode unsafely and serve mislabeled, cacheable responses. This iss | HIGH | 8.2 | 43%ile | NVD | 2026-07-29 |
| CVE-2026-17686 | Insufficient validation of untrusted input in Passwords in Google Chrome prior to 151.0.7922.72 allowed a remote attacke | HIGH | 8.1 | 28%ile | NVD | 2026-07-30 |
| CVE-2026-17861 | Insufficient validation of untrusted input in Updater in Google Chrome prior to 151.0.7922.72 allowed a local attacker t | HIGH | 7.8 | 1%ile | NVD | 2026-07-30 |
| CVE-2025-39824 | HID: asus: fix UAF via HID_CLAIMED_INPUT validation | HIGH | 7.8 | 5%ile | Microsoft | 2025-09-09 |
| CVE-2026-33267 | Improper Input Validation vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 9.2.0 | HIGH | 7.7 | 16%ile | NVD | 2026-07-29 |
| CVE-2026-69192 | ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. Prior to 10.3.1, Address4 ac | HIGH | 7.7 | 22%ile | NVD | 2026-08-03 |
| CVE-2026-47219 | find-my-way is a framework-independent HTTP router that internally uses a Radix Tree and supports route parameters and w | HIGH | 7.5 | 38%ile | NVD | 2026-07-28 |
| CVE-2026-17698 | Insufficient validation of untrusted input in UI in Google Chrome on Android prior to 151.0.7922.72 allowed a local atta | HIGH | 7.5 | 22%ile | NVD | 2026-07-30 |
| CVE-2026-17774 | Insufficient validation of untrusted input in Variations in Google Chrome prior to 151.0.7922.72 allowed an attacker in | HIGH | 7.5 | 4%ile | NVD | 2026-07-30 |
| CVE-2026-17930 | Insufficient validation of untrusted input in Extensions in Google Chrome prior to 151.0.7922.72 allowed a remote attack | HIGH | 7.5 | 15%ile | NVD | 2026-07-30 |
| CVE-2026-53503 | Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, Thumbor's filters:convolution(<matrix>, | HIGH | 7.5 | 34%ile | NVD | 2026-07-31 |
| CVE-2026-21548 | In nr modem, there is a possible improper input validation. This could lead to remote denial of service with System exec | HIGH | 7.5 | 33%ile | NVD | 2026-08-03 |
| CVE-2026-21549 | In modem, there is a possible improper input validation. This could lead to remote denial of service with no additional | HIGH | 7.5 | 33%ile | NVD | 2026-08-03 |
| CVE-2026-21550 | In modem, there is a possible improper input validation. This could lead to remote denial of service with no additional | HIGH | 7.5 | 33%ile | NVD | 2026-08-03 |
| CVE-2026-21551 | In modem, there is a possible improper input validation. This could lead to remote denial of service with no additional | HIGH | 7.5 | 33%ile | NVD | 2026-08-03 |
| CVE-2026-21552 | In modem, there is a possible improper input validation. This could lead to remote denial of service with no additional | HIGH | 7.5 | 33%ile | NVD | 2026-08-03 |
| CVE-2026-21553 | In modem, there is a possible improper input validation. This could lead to remote denial of service with no additional | HIGH | 7.5 | 33%ile | NVD | 2026-08-03 |
| CVE-2026-21554 | In modem, there is a possible improper input validation. This could lead to remote denial of service with no additional | HIGH | 7.5 | 33%ile | NVD | 2026-08-03 |
| CVE-2026-21555 | In modem, there is a possible improper input validation. This could lead to remote denial of service with no additional | HIGH | 7.5 | 33%ile | NVD | 2026-08-03 |
| CVE-2026-69185 | Socket.IO enables bidirectional and low-latency communication for every platform. Prior to 4.2.7, 3.4.5, and 3.3.6, a sp | HIGH | 7.5 | 27%ile | NVD | 2026-08-03 |
| CVE-2026-37460 | Missing input validation in the rfapiRibBi2Ri() function (rfapi_rib.c) of FRRouting (FRR) stable/10.0 to stable/10.6 all | HIGH | 7.5 | 26%ile | Microsoft | 2026-06-09 |
| CVE-2026-67326 | GitPython before 3.1.50 fails to validate newline characters in the section parameter of config_writer(), allowing attac | HIGH | 7.3 | 9%ile | NVD | 2026-08-01 |
| CVE-2026-16843 | Some Hikvision Networking Products are vulnerable to authenticated command execution due to insufficient input validatio | HIGH | 7.2 | 56%ile | NVD | 2026-07-31 |
| CVE-2026-17741 | Insufficient validation of untrusted input in WebView in Google Chrome on Android prior to 151.0.7922.72 allowed a remot | HIGH | 7.1 | 11%ile | NVD | 2026-07-30 |
| CVE-2026-17867 | Insufficient validation of untrusted input in Dawn in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to | HIGH | 7.1 | 8%ile | NVD | 2026-07-30 |
| CVE-2026-17888 | Insufficient validation of untrusted input in WebUI in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to | HIGH | 7.1 | 5%ile | NVD | 2026-07-30 |
| CVE-2026-40272 | Improper Input Validation in the decode() function of the traceparser library could allow an attacker with a corrupted k | HIGH | 7.0 | 2%ile | NVD | 2026-07-29 |
| CVE-2026-59881 | AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.2, the WebSocket client ac | MEDIUM | 6.9 | 22%ile | NVD | 2026-07-30 |
| CVE-2026-53551 | free5GC is an open-source implementation of the 5G core network. Prior to 1.4.5, the free5GC AUSF (Authentication Server | MEDIUM | 6.9 | 35%ile | NVD | 2026-07-31 |
| CVE-2026-69198 | ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. From 10.1.1 until 10.2.2, ev | MEDIUM | 6.9 | 20%ile | NVD | 2026-08-03 |
| CVE-2026-65834 | Capsule is a multi-tenancy and policy-based framework for Kubernetes. Prior to 0.13.8, CapsuleConfiguration.Spec.NodeMet | MEDIUM | 6.8 | 19%ile | NVD | 2026-07-30 |
| CVE-2026-65891 | Joomla Extension - joomlacontenteditor.net - Creation of hidden files and unintended file overwrite via rename function | MEDIUM | 6.5 | 10%ile | NVD | 2026-07-29 |
| CVE-2026-17664 | Insufficient validation of untrusted input in Loader in Google Chrome prior to 151.0.7922.72 allowed a remote attacker w | MEDIUM | 6.5 | 29%ile | NVD | 2026-07-30 |
| CVE-2026-17679 | Insufficient validation of untrusted input in Print Preview in Google Chrome prior to 151.0.7922.72 allowed a remote att | MEDIUM | 6.5 | 28%ile | NVD | 2026-07-30 |
| CVE-2026-17690 | Insufficient validation of untrusted input in PDF in Google Chrome on Android prior to 151.0.7922.72 allowed a local att | MEDIUM | 6.5 | 19%ile | NVD | 2026-07-30 |
| CVE-2026-17789 | Insufficient validation of untrusted input in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a re | MEDIUM | 6.5 | 12%ile | NVD | 2026-07-30 |
| CVE-2026-17791 | Insufficient validation of untrusted input in Payments in Google Chrome prior to 151.0.7922.72 allowed a remote attacker | MEDIUM | 6.5 | 14%ile | NVD | 2026-07-30 |
| CVE-2026-17814 | Insufficient validation of untrusted input in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a re | MEDIUM | 6.5 | 19%ile | NVD | 2026-07-30 |
| CVE-2026-17831 | Insufficient validation of untrusted input in Passwords in Google Chrome prior to 151.0.7922.72 allowed a remote attacke | MEDIUM | 6.5 | 18%ile | NVD | 2026-07-30 |
| CVE-2026-17921 | Insufficient validation of untrusted input in Navigation in Google Chrome prior to 151.0.7922.72 allowed a remote attack | MEDIUM | 6.5 | 13%ile | NVD | 2026-07-30 |
| CVE-2026-17926 | Insufficient validation of untrusted input in DevTools in Google Chrome prior to 151.0.7922.72 allowed a remote attacker | MEDIUM | 6.5 | 13%ile | NVD | 2026-07-30 |
| CVE-2026-17929 | Insufficient validation of untrusted input in DevTools in Google Chrome prior to 151.0.7922.72 allowed a remote attacker | MEDIUM | 6.5 | 11%ile | NVD | 2026-07-30 |
| CVE-2026-17988 | Insufficient validation of untrusted input in Navigation in Google Chrome prior to 151.0.7922.72 allowed a remote attack | MEDIUM | 6.5 | 12%ile | NVD | 2026-07-30 |
| CVE-2026-18014 | Insufficient validation of untrusted input in DevTools in Google Chrome prior to 151.0.7922.72 allowed a remote attacker | MEDIUM | 6.5 | 6%ile | NVD | 2026-07-30 |
| CVE-2026-37458 | Missing input validation in the MP_REACH_NLRI component of FRRouting (FRR) stable/10.0 to stable/10.6 allows authenticat | MEDIUM | 6.5 | 16%ile | Microsoft | 2026-05-12 |
| CVE-2026-18245 | Improper control of code generation in Amazon @aws-amplify/codegen-ui-react before 2.20.6 might allow a remote authentic | MEDIUM | 6.4 | 41%ile | NVD | 2026-07-30 |
| CVE-2026-56722 | Dompdf is an HTML to PDF converter for PHP. In versions 3.15 and prior, aAn attacker who controls the HTML input can byp | MEDIUM | 6.3 | 43%ile | NVD | 2026-07-28 |
| CVE-2026-54663 | swagger-typescript-api generates API clients for Fetch or Axios from OpenAPI specifications. Prior to 13.12.2, src/resol | MEDIUM | 6.1 | 8%ile | NVD | 2026-07-29 |
| CVE-2026-20469 | In trusted_mem, there is a possible escalation of privilege due to improper input validation. This could lead to local e | MEDIUM | 6.0 | 2%ile | NVD | 2026-08-03 |
| CVE-2026-17736 | Insufficient validation of untrusted input in WebView in Google Chrome on Android prior to 151.0.7922.72 allowed a remot | MEDIUM | 5.8 | 9%ile | NVD | 2026-07-30 |
| CVE-2026-17806 | Insufficient validation of untrusted input in Extensions in Google Chrome prior to 151.0.7922.72 allowed a remote attack | MEDIUM | 5.8 | 6%ile | NVD | 2026-07-30 |
| CVE-2026-17809 | Insufficient validation of untrusted input in Extensions in Google Chrome prior to 151.0.7922.72 allowed a remote attack | MEDIUM | 5.8 | 6%ile | NVD | 2026-07-30 |
| CVE-2026-17890 | Insufficient validation of untrusted input in DevTools in Google Chrome prior to 151.0.7922.72 allowed a remote attacker | MEDIUM | 5.8 | 6%ile | NVD | 2026-07-30 |
| CVE-2026-17893 | Insufficient validation of untrusted input in Updater in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote at | MEDIUM | 5.8 | 6%ile | NVD | 2026-07-30 |
| CVE-2026-17906 | Insufficient validation of untrusted input in Bluetooth in Google Chrome prior to 151.0.7922.72 allowed a remote attacke | MEDIUM | 5.8 | 6%ile | NVD | 2026-07-30 |
| CVE-2026-17908 | Insufficient validation of untrusted input in Printing in Google Chrome on Windows prior to 151.0.7922.72 allowed a remo | MEDIUM | 5.8 | 6%ile | NVD | 2026-07-30 |
| CVE-2026-11835 | Time-of-check time-of-use (TOCTOU) vulnerability combined with missing input validation in Caliptra Core ROM (UpdateRese | MEDIUM | 5.6 | 0%ile | NVD | 2026-08-04 |
| CVE-2026-18772 | Improper input validation vulnerability in Samsung Open Source rlottie allows Oversized Serialized Data Payloads. | MEDIUM | 5.5 | 3%ile | NVD | 2026-08-04 |
| CVE-2026-17761 | Insufficient validation of untrusted input in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a re | MEDIUM | 5.4 | 7%ile | NVD | 2026-07-30 |
| CVE-2026-17799 | Insufficient validation of untrusted input in Safe Browsing in Google Chrome prior to 151.0.7922.72 allowed a remote att | MEDIUM | 5.4 | 10%ile | NVD | 2026-07-30 |
| CVE-2026-18174 | @fastify/forwarded resolves client addresses from the X-Forwarded-For header. In versions before 3.0.2, when the header | MEDIUM | 5.3 | 9%ile | NVD | 2026-07-29 |
| CVE-2026-17909 | Insufficient validation of untrusted input in Isolated Web Apps in Google Chrome prior to 151.0.7922.72 allowed a remote | MEDIUM | 5.3 | 12%ile | NVD | 2026-07-30 |
| CVE-2026-54909 | pion/stun is a Go implementation of STUN. Prior to 3.1.3, XORMappedAddress.GetFromAs can panic while parsing a malformed | MEDIUM | 5.3 | 30%ile | NVD | 2026-07-31 |
| CVE-2026-17700 | Insufficient validation of untrusted input in Actor in Google Chrome prior to 151.0.7922.72 allowed a remote attacker wh | MEDIUM | 4.3 | 21%ile | NVD | 2026-07-30 |
| CVE-2026-17706 | Insufficient validation of untrusted input in Media in Google Chrome on Windows prior to 151.0.7922.72 allowed a remote | MEDIUM | 4.3 | 22%ile | NVD | 2026-07-30 |
| CVE-2026-17767 | Insufficient validation of untrusted input in WebView in Google Chrome on Android prior to 151.0.7922.72 allowed a remot | MEDIUM | 4.3 | 12%ile | NVD | 2026-07-30 |
| CVE-2026-17769 | Insufficient validation of untrusted input in Cast in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to | MEDIUM | 4.3 | 12%ile | NVD | 2026-07-30 |
| CVE-2026-17773 | Insufficient validation of untrusted input in Cast in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to | MEDIUM | 4.3 | 12%ile | NVD | 2026-07-30 |
| CVE-2026-17794 | Insufficient validation of untrusted input in Mobile in Google Chrome on Android prior to 151.0.7922.72 allowed a remote | MEDIUM | 4.3 | 14%ile | NVD | 2026-07-30 |
| CVE-2026-17795 | Inappropriate implementation in GetUserMedia in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had c | MEDIUM | 4.3 | 12%ile | NVD | 2026-07-30 |
| CVE-2026-17844 | Insufficient validation of untrusted input in Cast in Google Chrome prior to 151.0.7922.72 allowed an attacker on the lo | MEDIUM | 4.3 | 2%ile | NVD | 2026-07-30 |
| CVE-2026-17870 | Insufficient validation of untrusted input in Cast in Google Chrome prior to 151.0.7922.72 allowed an attacker on the lo | MEDIUM | 4.3 | 2%ile | NVD | 2026-07-30 |
| CVE-2026-17901 | Insufficient validation of untrusted input in Sharing in Google Chrome on Android prior to 151.0.7922.72 allowed a remot | MEDIUM | 4.3 | 8%ile | NVD | 2026-07-30 |
| CVE-2026-17934 | Insufficient validation of untrusted input in DevTools in Google Chrome prior to 151.0.7922.72 allowed a remote attacker | MEDIUM | 4.3 | 15%ile | NVD | 2026-07-30 |
| CVE-2026-17937 | Insufficient validation of untrusted input in DevTools in Google Chrome prior to 151.0.7922.72 allowed a remote attacker | MEDIUM | 4.3 | 10%ile | NVD | 2026-07-30 |
| CVE-2026-17939 | Insufficient validation of untrusted input in Passwords in Google Chrome prior to 151.0.7922.72 allowed a remote attacke | MEDIUM | 4.3 | 7%ile | NVD | 2026-07-30 |
| CVE-2026-17955 | Insufficient validation of untrusted input in Payments in Google Chrome prior to 151.0.7922.72 allowed a remote attacker | MEDIUM | 4.3 | 9%ile | NVD | 2026-07-30 |
| CVE-2026-17970 | Insufficient validation of untrusted input in Passwords in Google Chrome prior to 151.0.7922.72 allowed an attacker in a | MEDIUM | 4.3 | 4%ile | NVD | 2026-07-30 |
| CVE-2026-17982 | Insufficient validation of untrusted input in Cast in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to | MEDIUM | 4.3 | 9%ile | NVD | 2026-07-30 |
| CVE-2026-18009 | Insufficient validation of untrusted input in Passwords in Google Chrome prior to 151.0.7922.72 allowed a remote attacke | MEDIUM | 4.3 | 4%ile | NVD | 2026-07-30 |
| CVE-2025-62347 | HCL iControl was affected by Improper Input Validation vulnerability. It is vulnerable to unexpected system behavior and | MEDIUM | 4.3 | 8%ile | NVD | 2026-07-31 |
| CVE-2026-17747 | Insufficient validation of untrusted input in Payments in Google Chrome on Android prior to 151.0.7922.72 allowed a remo | MEDIUM | 4.2 | 12%ile | NVD | 2026-07-30 |
| CVE-2026-18211 | A flaw was found in the secure-client-uris client policy executor within Keycloak core services. This component is respo | MEDIUM | 4.2 | 9%ile | NVD | 2026-07-31 |
| CVE-2026-18206 | A flaw was found in the keycloak-services component of Keycloak, which provides identity and access management services. | LOW | 3.7 | 12%ile | NVD | 2026-07-31 |
| CVE-2026-18217 | A flaw was found in the SAML protocol implementation of Keycloak, an open-source identity and access management solution | LOW | 3.4 | 9%ile | NVD | 2026-07-31 |
| CVE-2026-17766 | Insufficient validation of untrusted input in Clipboard in Google Chrome on Android prior to 151.0.7922.72 allowed a loc | LOW | 3.3 | 2%ile | NVD | 2026-07-30 |
| CVE-2026-17860 | Insufficient validation of untrusted input in Mobile in Google Chrome on Android prior to 151.0.7922.72 allowed a local | LOW | 3.3 | 1%ile | NVD | 2026-07-30 |
| CVE-2026-55554 | Dompdf is an HTML to PDF converter for PHP. In versions 3.15 and prior, the validateLocalUri() method enforces chroot bo | LOW | 2.3 | 20%ile | NVD | 2026-07-28 |
| CVE-2026-17735 | Insufficient validation of untrusted input in BFCache in Google Chrome prior to 151.0.7922.72 allowed a remote attacker | UNKNOWN | — | 11%ile | NVD | 2026-07-30 |
| CVE-2026-12003 | CPython >3.11 Insecure Input Validation resulting in privilege escalation | UNKNOWN | — | 4%ile | Microsoft | 2026-06-09 |