Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
2.9 LOW
CVE-2026-16517 — Libarchive: libarchive: signed integer overflow in archive_write_zip_header

A signed integer overflow vulnerability was found in libarchive's ZIP writer. In the archive_write_zip_header function in archive_write_set_format_zip.c, when ZIP encryption is enabled and the entry …

Jul 21, 2026 Jul 22, 2026
Jul 21, 2026
Jul 22, 2026
5.0 MEDIUM
CVE-2026-16486 — SourceCodester Class and Exam Timetabling System BSIS.php cross site scripting

A vulnerability was found in SourceCodester Class and Exam Timetabling System 1.0. This affects an unknown part of the file /BSIS.php. Performing a manipulation of the argument day results in cross s…

class_and_exam_timetabling_system | Remote | Cross-Site Scripting
Jul 21, 2026 Jul 22, 2026
Jul 21, 2026
Jul 22, 2026
5.0 MEDIUM
CVE-2026-16485 — SourceCodester Class and Exam Timetabling System class.php cross site scripting

A vulnerability has been found in SourceCodester Class and Exam Timetabling System 1.0. Affected by this issue is some unknown functionality of the file /class.php. Such manipulation of the argument …

class_and_exam_timetabling_system | Remote | Cross-Site Scripting
Jul 21, 2026 Jul 22, 2026
Jul 21, 2026
Jul 22, 2026
9.6 CRITICAL
CVE-2026-16424 — Google Chrome GPU Use-After-Free Sandbox Escape

Use after free in GPU in Google Chrome on Android prior to 150.0.7871.182 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML…

android chrome chrome edge_chromium | Remote | Memory Corruption
Jul 21, 2026 Jul 24, 2026
Jul 21, 2026
Jul 24, 2026
8.8 HIGH
CVE-2026-16423 — Google Chrome UI Use-After-Free

Use after free in UI in Google Chrome prior to 150.0.7871.182 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTM…

chrome chrome edge_chromium | Remote | Memory Corruption
Jul 21, 2026 Jul 24, 2026
Jul 21, 2026
Jul 24, 2026
7.5 HIGH
CVE-2026-16422 — Google Chrome Certificate Validation Domain Spoofing Vulnerability

Insufficient validation of untrusted input in Certificate in Google Chrome on Linux prior to 150.0.7871.182 allowed an attacker in a privileged network position to perform domain spoofing via malicio…

linux_kernel chrome chrome edge_chromium | Remote | Information Disclosure
Jul 21, 2026 Jul 24, 2026
Jul 21, 2026
Jul 24, 2026
8.8 HIGH
CVE-2026-16421 — Google Chrome WebAudio Remote Code Execution Vulnerability

Inappropriate implementation in WebAudio in Google Chrome prior to 150.0.7871.182 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security seve…

chrome chrome edge_chromium | Remote | Memory Corruption
Jul 21, 2026 Jul 24, 2026
Jul 21, 2026
Jul 24, 2026
8.8 HIGH
CVE-2026-16420 — Google Chrome WebAudio Type Confusion Vulnerability

Type Confusion in WebAudio in Google Chrome prior to 150.0.7871.182 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

chrome chrome edge_chromium | Remote | Memory Corruption
Jul 21, 2026 Jul 24, 2026
Jul 21, 2026
Jul 24, 2026
9.6 CRITICAL
CVE-2026-16419 — Google Chromium ANGLE Out-of-Bounds Memory Access

Out of bounds read and write in ANGLE in Google Chrome on Android prior to 150.0.7871.182 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security…

android chrome chrome edge_chromium | Remote | Memory Corruption
Jul 21, 2026 Jul 24, 2026
Jul 21, 2026
Jul 24, 2026
8.8 HIGH
CVE-2026-16418 — Google Chrome V8 Stack Buffer Overflow

Stack buffer overflow in V8 in Google Chrome prior to 150.0.7871.182 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

chrome chrome edge_chromium | Remote | Memory Corruption
Jul 21, 2026 Jul 24, 2026
Jul 21, 2026
Jul 24, 2026
3.1 LOW
CVE-2026-16417 — Google Chrome Skia Uninitialized Use Vulnerability

Uninitialized Use in Skia in Google Chrome prior to 150.0.7871.182 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium secu…

chrome chrome edge_chromium | Remote | Information Disclosure
Jul 21, 2026 Jul 24, 2026
Jul 21, 2026
Jul 24, 2026
8.3 HIGH
CVE-2026-16416 — Google Chrome Chromecast Integer Overflow

Integer overflow in Chromecast in Google Chrome prior to 150.0.7871.182 allowed a local attacker to potentially perform a sandbox escape via malicious network traffic. (Chromium security severity: Hi…

chrome chrome edge_chromium | Memory Corruption
Jul 21, 2026 Jul 24, 2026
Jul 21, 2026
Jul 24, 2026
5.4 MEDIUM
CVE-2026-16415 — Google Chrome Extensions Omnibox Spoofing Vulnerability

Insufficient validation of untrusted input in Extensions in Google Chrome prior to 150.0.7871.182 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. (Ch…

chrome chrome edge_chromium | Remote | Information Disclosure
Jul 21, 2026 Jul 24, 2026
Jul 21, 2026
Jul 24, 2026
8.3 HIGH
CVE-2026-16414 — Google Chrome Chromecast Sandbox Escape

Insufficient validation of untrusted input in Chromecast in Google Chrome prior to 150.0.7871.182 allowed a local attacker to potentially perform a sandbox escape via malicious network traffic. (Chro…

chrome chrome edge_chromium | Information Disclosure
Jul 21, 2026 Jul 24, 2026
Jul 21, 2026
Jul 24, 2026
8.3 HIGH
CVE-2026-16413 — Google Chrome ANGLE Out-of-Bounds Write Sandbox Escape

Out of bounds write in ANGLE in Google Chrome prior to 150.0.7871.182 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML pag…

chrome chrome edge_chromium | Remote | Memory Corruption
Jul 21, 2026 Jul 24, 2026
Jul 21, 2026
Jul 24, 2026
8.6 HIGH
CVE-2026-8989 — Open Recovery Mode

Autel Maxi Charger Single firmware through V1.03.51 permits unrestricted access to the NXP i.MX6 recovery mode through exposed hardware recovery pins. An attacker with physical access can boot attack…

| Authentication
Jul 21, 2026 Jul 22, 2026
Jul 21, 2026
Jul 22, 2026
8.6 HIGH
CVE-2026-8988 — Access to Bootloader

Autel Maxi Charger Single firmware through V1.03.51 exposes an accessible UART interface that permits interruption of the boot process and access to the U-Boot bootloader. An attacker with physical a…

| Misconfiguration
Jul 21, 2026 Jul 22, 2026
Jul 21, 2026
Jul 22, 2026
9.4 CRITICAL
CVE-2026-8987 — Authenticated Heap Overflow

Autel Maxi Charger Single firmware through V1.03.51 contains a heap-based buffer overflow in the set_ap_param command handled by the /localcfg endpoint. An authenticated attacker can supply oversized…

Remote | Memory Corruption
Jul 21, 2026 Jul 22, 2026
Jul 21, 2026
Jul 22, 2026
9.5 CRITICAL
CVE-2026-8986 — Command Injection via Malicious OCPP Server

Autel Maxi Charger Single firmware through V1.03.51 is vulnerable to OS command injection when processing OCPP GetDiagnostics requests. A malicious or compromised OCPP server can supply a crafted dia…

Remote | Injection
Jul 21, 2026 Jul 22, 2026
Jul 21, 2026
Jul 22, 2026
10.0 CRITICAL
CVE-2026-8985 — Unauthenticated Command Injection

Autel Maxi Charger Single firmware through V1.03.51 is vulnerable to OS command injection in the /test endpoint exposed on TCP port 9002. An unauthenticated attacker can supply crafted input in the u…

Remote | Injection
Jul 21, 2026 Jul 22, 2026
Jul 21, 2026
Jul 22, 2026
Showing 20 of 8954 Results