The NVD is the U.S. government repository of standards based vulnerability management data represented using the Security Content Automation Protocol (SCAP). This data enables automation of vulnerability management, security measurement, and compliance. The NVD includes databases of security checklist references, security-related software flaws, product names, and impact metrics.
For information on how to cite the NVD, including the database's Digital Object Identifier (DOI), please consult NIST's Public Data Repository.
Legal Disclaimer:
Here is where you can read the NVD legal disclaimer.
-
CVE-2026-17650 - Use after free in Compositing in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
Published: July 29, 2026; 9:16:26 PM -0400 -
CVE-2026-17652 - Use after free in Views in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
Published: July 29, 2026; 9:16:27 PM -0400 -
CVE-2026-17653 - Use after free in Skia in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
Published: July 29, 2026; 9:16:27 PM -0400 -
CVE-2026-17654 - Race in Updater in Google Chrome on Mac prior to 151.0.7922.72 allowed a local attacker to perform OS-level privilege escalation via a malicious file. (Chromium security severity: Critical)
Published: July 29, 2026; 9:16:27 PM -0400 -
CVE-2026-17655 - Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
Published: July 29, 2026; 9:16:27 PM -0400 -
CVE-2026-17656 - Use after free in Ozone in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
Published: July 29, 2026; 9:16:27 PM -0400 -
CVE-2026-17657 - Use after free in Navigation in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
Published: July 29, 2026; 9:16:27 PM -0400 -
CVE-2026-17658 - Use after free in V8 in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
Published: July 29, 2026; 9:16:27 PM -0400 -
CVE-2026-17659 - Inappropriate implementation in SiteIsolation in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: High)
Published: July 29, 2026; 9:16:27 PM -0400 -
CVE-2026-17660 - Insufficient validation of untrusted input in Network in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security se... read CVE-2026-17660
Published: July 29, 2026; 9:16:27 PM -0400 -
CVE-2024-13461 - The Autoship Cloud for WooCommerce Subscription Products plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'autoship-create-scheduled-order-action' shortcode in all versions up to, and including, 2.8.0 due to insuf... read CVE-2024-13461
Published: February 21, 2025; 5:15:10 AM -0500V3.1: 5.4 MEDIUM
-
CVE-2026-17346 - The fix for CVE-2026-12044 in pgAdmin 4 9.16 hardened qtLiteral and switched sixteen COMMENT ON / pgstattuple / pgstatindex templates to it, but missed several sinks that had been placed in test_sql_string_literal_lint.py's ALLOWLIST on the incorr... read CVE-2026-17346
Published: July 31, 2026; 12:16:58 PM -0400 -
CVE-2026-11536 - IBM WebSphere Application Server 9.0, and 8.5 is affected by a remote code execution vulnerability in the SOAP/JMX connector.
Published: July 30, 2026; 4:16:52 PM -0400 -
CVE-2026-10695 - IBM Db2 12.1.0 through 12.1.4 federated server is vulnerable to a denial of service when running non fenced federated queries.
Published: July 30, 2026; 3:17:01 PM -0400V3.1: 5.5 MEDIUM
-
CVE-2026-62927 - In Eclipse Milo versions 1.0.0 through 1.1.4, the Call service dispatches the original mixed batch to address-space handlers after calculating authorization, allowing an anonymous or otherwise low-privileged client to execute a denied method by ba... read CVE-2026-62927
Published: August 04, 2026; 9:18:55 AM -0400V3.1: 7.5 HIGH
-
CVE-2026-10535 - IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to buffer overflow in setgid helper db2flacc.
Published: July 30, 2026; 3:17:01 PM -0400V3.1: 7.8 HIGH
-
CVE-2026-65891 - Joomla Extension - joomlacontenteditor.net - Creation of hidden files and unintended file overwrite via rename function in Joomla Content Editor (JCE) < 2.20.2 - Improper input validation in the file rename functionality allowed an authenticated u... read CVE-2026-65891
Published: July 29, 2026; 9:19:10 AM -0400 -
CVE-2026-58080 - In Eclipse Milo versions 1.0.0 through 1.1.4, `OpcUaServerConfig.copy()` fails to preserve a configured `RoleMapper`. On servers that rely on role permissions and construct the running configuration through `copy()`, sessions receive no role IDs a... read CVE-2026-58080
Published: August 04, 2026; 9:18:55 AM -0400V3.1: 8.2 HIGH
-
CVE-2026-24033 - Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 10.0.0 through 10.1.3, from 9.0.0 through 9.2.14. Users are recommended to up... read CVE-2026-24033
Published: July 29, 2026; 4:16:30 AM -0400V3.1: 5.3 MEDIUM
-
CVE-2026-22068 - Regular Expression without Anchors vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 10.0.X through 10.1.3, from 9.0.X through 9.2.14. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fixes... read CVE-2026-22068
Published: July 29, 2026; 4:16:30 AM -0400V3.1: 5.3 MEDIUM