Skip to main content

CWE archive

CWE-472 CVEs

Programmatic archive

139 CVEs tagged with CWE-47215 Critical, 73 High, 46 Medium, 5 Low, 0 Unrated.

CVE-2026-7484

Published Jul 24, 2026

External control of Assumed-Immutable web parameter vulnerability in ABIS Technology Ltd. Co. AVESİS allows Accessing Functionality Not Properly Constrained by ACLs. This issue a…

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-65052

Published Jul 21, 2026

Ninja Forms WordPress plugin version 3.14.8 and prior contains an improper input validation vulnerability that allows unauthenticated attackers to inject arbitrary numeric values…

CVSS 8.7 · High
evidence mentions
3
Buzz score
23.9

CVE-2026-56877

Published Jul 13, 2026

The SCORM lab launch endpoint in Skillable (scorm.skillable.com) through 2026-07-13 does not validate the client-supplied userId parameter against the authenticated SCORM session…

CVSS 6.3 · Medium
evidence mentions
5
Buzz score
29.4

CVE-2026-59817

Published Jul 9, 2026

Ghost is a Node.js content management system. From 6.27.0 before 6.44.0, Ghost's public donation checkout flow allowed an unauthenticated attacker to control donation checkout met…

CVSS 5.3 · Medium
evidence mentions
5
Buzz score
22.9

CVE-2026-14430

Published Jul 1, 2026

Integer overflow in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security sev…

CVSS 8.8 · High
evidence mentions
4
Buzz score
32.6
Vendor/product tagsBeta · best-effort

CVE-2026-14391

Published Jul 1, 2026

Integer overflow in ANGLE in Google Chrome on Windows prior to 150.0.7871.46 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive inf…

CVSS 5.3 · Medium
evidence mentions
4
Buzz score
32.6
Vendor/product tagsBeta · best-effort

CVE-2026-14389

Published Jul 1, 2026

Integer overflow in Skia in Google Chrome prior to 150.0.7871.46 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a c…

CVSS 8.3 · High
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-14387

Published Jul 1, 2026

Integer overflow in Skia in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security seve…

CVSS 9.6 · Critical
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-13974

Published Jun 30, 2026

Integer overflow in Safe Browsing in Google Chrome on Mac prior to 150.0.7871.47 allowed a remote attacker to bypass navigation restrictions via a malicious file. (Chromium securi…

CVSS 8.1 · High
evidence mentions
4
Buzz score
32.6
Vendor/product tagsBeta · best-effort

CVE-2026-13938

Published Jun 30, 2026

Integer overflow in Fonts in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security se…

CVSS 8.8 · High
evidence mentions
4
Buzz score
32.6
Vendor/product tagsBeta · best-effort

CVE-2026-13841

Published Jun 30, 2026

Integer overflow in Skia in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a c…

CVSS 8.3 · High
evidence mentions
4
Buzz score
32.6
Vendor/product tagsBeta · best-effort

CVE-2026-42655

Published Jun 15, 2026

Unauthenticated Bypass Vulnerability in Best Payments Plugin for WP <= 4.6.19 versions.

CVSS 5.9 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2025-59382

Published Jun 10, 2026

QTS, QuTS hero, QuTScloud are not affected. We have already fixed the vulnerability in the following version:

CVSS 1.2 · Low
evidence mentions
1
Buzz score
11.9

CVE-2026-11669

Published Jun 9, 2026

Out of bounds read in Media in Google Chrome on ChromeOS prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive…

CVSS 5.3 · Medium
evidence mentions
3
Buzz score
28.9
Vendor/product tagsBeta · best-effort

CVE-2026-11655

Published Jun 9, 2026

Integer overflow in Media in Google Chrome on Mac prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escap…

CVSS 8.3 · High
evidence mentions
3
Buzz score
28.9
Vendor/product tagsBeta · best-effort

CVE-2026-11290

Published Jun 5, 2026

Integer overflow in WebView in Google Chrome on Android prior to 149.0.7827.53 allowed a local attacker to cause a denial of service via a malicious file. (Chromium security sever…

CVSS 5.0 · Medium
evidence mentions
3
Buzz score
28.9
Vendor/product tagsBeta · best-effort

CVE-2026-11281

Published Jun 5, 2026

Integer overflow in Chromoting in Google Chrome on Windows prior to 149.0.7827.53 allowed a local attacker to obtain potentially sensitive information from process memory via a cr…

CVSS 5.0 · Medium
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort
Showing 1-25 of 139 CVEsPage 1 of 6