U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.

NVD Dashboard

CVEs Received and Processed

CVEs Received and Processed

Please Wait

CVE Status Count

Please Wait

CVSS Score Spread

Please Wait

CVSS V3 Score Distribution

Severity Number of Vulns

CVSS V2 Score Distribution

Severity Number of Vulns


For information on how to the cite the NVD, including the database's Digital Object Identifier (DOI), please consult NIST's Public Data Repository.

Last 20 Scored Vulnerability IDs & Summaries CVSS Severity
  • CVE-2026-76034 - Buffer overflow in WebGL in Google Chrome prior to 151.0.7922.169 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)
    Published: August 18, 2026; 5:18:27 PM -0400

  • CVE-2026-76036 - Buffer overflow in Dawn in Google Chrome on on Android prior to 151.0.7922.169 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)
    Published: August 18, 2026; 5:18:27 PM -0400

  • CVE-2026-76037 - Link following in CredentialProvider in Google Chrome on on Windows prior to 151.0.7922.169 allowed a local attacker to potentially execute arbitrary code outside the sandbox via a local program. (Chromium security severity: High)
    Published: August 18, 2026; 5:18:27 PM -0400

  • CVE-2026-76038 - Type confusion in V8 in Google Chrome prior to 151.0.7922.169 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
    Published: August 18, 2026; 5:18:27 PM -0400

  • CVE-2026-76047 - Type confusion in V8 in Google Chrome prior to 151.0.7922.169 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
    Published: August 18, 2026; 5:18:28 PM -0400

  • CVE-2026-76033 - Inappropriate implementation in CORS in Google Chrome prior to 151.0.7922.169 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: High)
    Published: August 18, 2026; 5:18:27 PM -0400

  • CVE-2026-47865 - VMware Avi Load Balancer contains an authentication bypass vulnerability. A malicious user with network access may be able to access the Avi Control plane by bypassing the authentication mechanism. Affected versions: 31.1.1 through 31.2.2 (fixed ... read CVE-2026-47865
    Published: July 18, 2026; 5:17:08 AM -0400

  • CVE-2026-47866 - VMware Avi Load Balancer contains an authorization bypass vulnerability. A malicious actor on the network can access a limited subset of the Avi Control Plane without proper authorization. Affected versions: 32.1.1 (fixed in 32.1.2) 31.1.1 throug... read CVE-2026-47866
    Published: July 18, 2026; 5:17:08 AM -0400

  • CVE-2026-47867 - VMware Avi Load Balancer contains a remote code execution vulnerability. A malicious user with network access may be able to access the Avi Control plane and execute code remotely. Affected versions: 32.1.1 (fixed in 32.1.2) 31.1.1 through 31.2.2... read CVE-2026-47867
    Published: July 18, 2026; 5:17:08 AM -0400

    V3.1: 8.8 HIGH

  • CVE-2026-47868 - VMware Avi Load Balancer contains a local privilege escalation vulnerability. A malicious user with local access may be able to escalate their privileges to run code as root. Affected versions: 32.1.1 (fixed in 32.1.2) 31.1.1 through 31.2.2 (fixe... read CVE-2026-47868
    Published: July 18, 2026; 5:17:08 AM -0400

  • CVE-2026-47869 - VMware Avi Load Balancer contains a remote code execution vulnerability. A malicious authenticated user with network access may be able to inject and execute code. Affected versions: 32.1.1 (fixed in 32.1.2) 31.1.1 through 31.2.2 (fixed in 31.2.2... read CVE-2026-47869
    Published: July 18, 2026; 5:17:08 AM -0400

    V3.1: 8.8 HIGH

  • CVE-2026-47870 - VMware Avi Load Balancer contains a privilege escalation vulnerability. A malicious authenticated user with network access may be able to execute remote code. Affected versions: 32.1.1 (fixed in 32.1.2) 31.1.1 through 31.2.2 (fixed in 31.2.2-2p3)... read CVE-2026-47870
    Published: July 18, 2026; 5:17:08 AM -0400

    V3.1: 8.8 HIGH

  • CVE-2026-47871 - VMware Avi Load Balancer contains a directory traversal vulnerability. Flaws in file path validation allow malicious, authenticated network users to perform directory traversal attacks. Affected versions: 32.1.1 (fixed in 32.1.2) 31.1.1 through 3... read CVE-2026-47871
    Published: July 18, 2026; 5:17:08 AM -0400

  • CVE-2026-74241 - A flaw was found in Red Hat Quay's external Lightweight Directory Access Protocol (LDAP) authentication handling. When an LDAP referral is returned during authentication, the system does not properly escape the username input. This allows an attac... read CVE-2026-74241
    Published: August 14, 2026; 7:16:34 PM -0400

    V3.1: 6.5 MEDIUM

  • CVE-2026-72529 - A remote unauthorized attacker with network access via port 4307/TCP to the TrueConf server versions 5.3.X to 5.3.9, 5.4.X to 5.4.9, 5.5.X to 5.5.5, and earlier could execute an arbitrary script by calling an undocumented function.
    Published: August 19, 2026; 1:21:00 PM -0400

  • CVE-2026-72530 - A remote unauthorized attacker with network access via port 4307/TCP to the TrueConf server versions 5.3.X to 5.3.9, 5.4.X to 5.4.9, 5.5.X to 5.5.5, and earlier could use a specially crafted script to break out of the isolated environment and exec... read CVE-2026-72530
    Published: August 19, 2026; 1:21:01 PM -0400

  • CVE-2026-74242 - A flaw was found in Red Hat Quay. An administrator of any repository, by knowing or guessing a target notification's Universally Unique Identifier (UUID), can read the notification configuration, including sensitive details like webhook URLs, Slac... read CVE-2026-74242
    Published: August 14, 2026; 7:16:34 PM -0400

    V3.1: 4.4 MEDIUM

  • CVE-2025-66824 - A Stored Cross-Site Scripting (XSS) vulnerability exists in the Meeting location field of the Create/Edit Conference functionality in TrueConf Server v5.5.2.10813. The injected payload is stored via the meeting_room parameter and executed when use... read CVE-2025-66824
    Published: December 30, 2025; 2:15:44 PM -0500

    V3.1: 8.7 HIGH

  • CVE-2025-66834 - A CSV Formula Injection vulnerability in TrueConf Server v5.5.2.10813 allows a normal user to inject malicious spreadsheet formulas into exported chat logs via crafted Display Name.
    Published: December 30, 2025; 2:15:44 PM -0500

  • CVE-2025-66823 - An HTML Injection vulnerability in TrueConf server 5.5.2.10813 in the conference description field allows an attacker to inject arbitrary HTML in the Create/Edit conference functionality. The payload will be triggered when the victim opens the Con... read CVE-2025-66823
    Published: December 30, 2025; 3:16:01 PM -0500

    V3.1: 5.4 MEDIUM