Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.5 HIGH
CVE-2026-3924 — Google Chrome WindowDialog Use-After-Free Vulnerability

use after free in WindowDialog in Google Chrome prior to 146.0.7680.71 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML pa…

Remote | Memory Corruption
Mar 11, 2026 Mar 12, 2026
Mar 11, 2026
Mar 12, 2026
8.8 HIGH
CVE-2026-3923 — Google Chrome WebMIDI Use-After-Free Vulnerability

Use after free in WebMIDI in Google Chrome prior to 146.0.7680.71 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

Remote | Memory Corruption
Mar 11, 2026 Mar 12, 2026
Mar 11, 2026
Mar 12, 2026
8.8 HIGH
CVE-2026-3922 — Google Chrome MediaStream Use After Free Vulnerability

Use after free in MediaStream in Google Chrome prior to 146.0.7680.71 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

Remote | Memory Corruption
Mar 11, 2026 Mar 12, 2026
Mar 11, 2026
Mar 12, 2026
8.8 HIGH
CVE-2026-3921 — Google Chrome TextEncoding Use-After-Free Heap Corruption Vulnerability

Use after free in TextEncoding in Google Chrome prior to 146.0.7680.71 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

Remote | Memory Corruption
Mar 11, 2026 Mar 12, 2026
Mar 11, 2026
Mar 12, 2026
8.8 HIGH
CVE-2026-3920 — Google Chrome WebML Heap Corruption

Out of bounds memory access in WebML in Google Chrome prior to 146.0.7680.71 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Hig…

Remote | Memory Corruption
Mar 11, 2026 Mar 12, 2026
Mar 11, 2026
Mar 12, 2026
8.8 HIGH
CVE-2026-3919 — "Google Chrome Extensions Use After Free Heap Corruption Vulnerability"

Use after free in Extensions in Google Chrome prior to 146.0.7680.71 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTM…

Remote | Memory Corruption
Mar 11, 2026 Mar 12, 2026
Mar 11, 2026
Mar 12, 2026
8.8 HIGH
CVE-2026-3918 — Google Chrome WebMCP Use-After-Free Vulnerability

Use after free in WebMCP in Google Chrome prior to 146.0.7680.71 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

Remote | Memory Corruption
Mar 11, 2026 Mar 12, 2026
Mar 11, 2026
Mar 12, 2026
8.8 HIGH
CVE-2026-3917 — Google Chrome Use After Free Heap Corruption

Use after free in Agents in Google Chrome prior to 146.0.7680.71 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

Remote | Memory Corruption
Mar 11, 2026 Mar 12, 2026
Mar 11, 2026
Mar 12, 2026
9.6 CRITICAL
CVE-2026-3916 — Google Chrome Web Speech Out-of-Bounds Read Vulnerability

Out of bounds read in Web Speech in Google Chrome prior to 146.0.7680.71 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

Remote | Memory Corruption
Mar 11, 2026 Mar 12, 2026
Mar 11, 2026
Mar 12, 2026
8.8 HIGH
CVE-2026-3915 — Google Chrome WebML Heap Buffer Overflow

Heap buffer overflow in WebML in Google Chrome prior to 146.0.7680.71 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: High)

Remote | Memory Corruption
Mar 11, 2026 Mar 12, 2026
Mar 11, 2026
Mar 12, 2026
8.8 HIGH
CVE-2026-3914 — Google Chrome WebML Integer Overflow Heap Corruption

Integer overflow in WebML in Google Chrome prior to 146.0.7680.71 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

Remote | Memory Corruption
Mar 11, 2026 Mar 12, 2026
Mar 11, 2026
Mar 12, 2026
8.8 HIGH
CVE-2026-3913 — Google Chrome Heap Buffer Overflow Vulnerability

Heap buffer overflow in WebML in Google Chrome prior to 146.0.7680.71 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)

Remote | Memory Corruption
Mar 11, 2026 Mar 12, 2026
Mar 11, 2026
Mar 12, 2026
9.8 CRITICAL
CVE-2026-32136 — AdGuard Home: HTTP/2 Cleartext (h2c) Upgrade Authentication Bypass

AdGuard Home is a network-wide software for blocking ads and tracking. Prior to 0.107.73, an unauthenticated remote attacker can bypass all authentication in AdGuardHome by sending an HTTP/1.1 reques…

Remote | Authentication
Mar 11, 2026 Mar 12, 2026
Mar 11, 2026
Mar 12, 2026
7.8 HIGH
CVE-2026-32133 — 2FAuth has Blind SSRF in image parameter allows internal network access and more

2FAuth is a web app to manage Two-Factor Authentication (2FA) accounts and generate their security codes. Prior to 6.1.0, a blind SSRF vulnerability exists in 2FAuth that allows authenticated users t…

Remote | Server-Side Request Forgery
Mar 11, 2026 Mar 12, 2026
Mar 11, 2026
Mar 12, 2026
7.4 HIGH
CVE-2026-32132 — ZITADEL: Reactivation of Expired Passkey Registration Codes

ZITADEL is an open source identity management platform. Prior to 3.4.8 and 4.12.2, a potential vulnerability exists in Zitadel's passkey registration endpoints. This endpoint allows registering a new…

Remote | Authentication
Mar 11, 2026 Mar 12, 2026
Mar 11, 2026
Mar 12, 2026
7.7 HIGH
CVE-2026-32131 — ZITADEL Cross-Tenant Information Disclosure in Management API

ZITADEL is an open source identity management platform. Prior to 3.4.8 and 4.12.2, a vulnerability in Zitadel's Management API has been reported, which allowed authenticated users holding a valid low…

Remote | Authorization
Mar 11, 2026 Mar 12, 2026
Mar 11, 2026
Mar 12, 2026
7.5 HIGH
CVE-2026-32130 — ZITADEL SCIM Authentication Bypass via URL Encoding

ZITADEL is an open source identity management platform. From 2.68.0 to before 3.4.8 and 4.12.2, Zitadel provides a System for Cross-domain Identity Management (SCIM) API to provision users from exter…

Remote | Authorization
Mar 11, 2026 Mar 12, 2026
Mar 11, 2026
Mar 12, 2026
6.3 MEDIUM
CVE-2026-32128 — FastGPT Python Sandbox Bypass of File-Write Restriction

FastGPT is an AI Agent building platform. In 4.14.7 and earlier, FastGPT's Python Sandbox (fastgpt-sandbox) includes guardrails intended to prevent file writes (static detection + seccomp). These gua…

Remote | Misconfiguration
Mar 11, 2026 Mar 12, 2026
Mar 11, 2026
Mar 12, 2026
7.6 HIGH
CVE-2026-32117 — grafanacubism-panel : Stored XSS via javascript: URL in panel zoom link (Editor → Viewer)

The grafanacubism-panel plugin allows use of cubism.js in Grafana. In 0.1.2 and earlier, the panel's zoom-link handler passes a dashboard-editor-supplied URL directly to window.location.assign() / wi…

Remote | Cross-Site Scripting
Mar 11, 2026 Mar 12, 2026
Mar 11, 2026
Mar 12, 2026
9.9 CRITICAL
CVE-2026-27591 — Winter: Privilege escalation by authenticated backend users

Winter is a free, open-source content management system (CMS) based on the Laravel PHP framework. Prior to 1.0.477, 1.1.12, and 1.2.12, Winter CMS allowed authenticated backend users to escalate thei…

Remote | Authorization
Mar 11, 2026 Mar 12, 2026
Mar 11, 2026
Mar 12, 2026
Showing 20 of 5429 Results