Skip to main content

CWE archive

CWE-843 CVEs

Programmatic archive

837 CVEs tagged with CWE-843100 Critical, 555 High, 156 Medium, 26 Low, 0 Unrated.

CVE-2026-13066

Published Jul 22, 2026

Improper handling of DBPointer objects during BSON serialization in MongoDB's server-side JavaScript engine can result in internal process memory contents being included in data r…

CVSS 7.1 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-16420

Published Jul 21, 2026

Type Confusion in WebAudio in Google Chrome prior to 150.0.7871.182 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium securit…

CVSS 8.8 · High
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-16410

Published Jul 21, 2026

JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.

CVSS 9.8 · Critical
evidence mentions
3
Buzz score
23.9
Vendor/product tagsBeta · best-effort

CVE-2026-16363

Published Jul 21, 2026

JIT miscompilation in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.

CVSS 9.8 · Critical
evidence mentions
5
Buzz score
27.9
Vendor/product tagsBeta · best-effort

CVE-2026-16355

Published Jul 21, 2026

JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 1…

CVSS 9.8 · Critical
evidence mentions
6
Buzz score
29.5
Vendor/product tagsBeta · best-effort

CVE-2026-64608

Published Jul 21, 2026

Heap type confusion and out-of-bounds read/write in the Apache Fory C++ implementation. When deserializing data in compatible mode, the field-skip paths do not correctly validate…

CVSS 9.8 · Critical
evidence mentions
2
Buzz score
21.0

CVE-2026-15776

Published Jul 14, 2026

Inappropriate implementation in V8 in Google Chrome prior to 150.0.7871.125 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium…

CVSS 8.8 · High
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-58541

Published Jul 14, 2026

Access of resource using incompatible type ('type confusion') in Windows DWM allows an authorized attacker to elevate privileges locally.

CVSS 7.8 · High
evidence mentions
4
Buzz score
29.1

CVE-2026-54116

Published Jul 14, 2026

Access of resource using incompatible type ('type confusion') in SQL Server allows an authorized attacker to disclose information over a network.

CVSS 6.5 · Medium
evidence mentions
4
Buzz score
29.1
Vendor/product tagsBeta · best-effort

CVE-2026-50686

Published Jul 14, 2026

Access of resource using incompatible type ('type confusion') in Windows OLE allows an unauthorized attacker to execute code over a network.

CVSS 8.1 · High
evidence mentions
4
Buzz score
29.1

CVE-2026-50421

Published Jul 14, 2026

Access of resource using incompatible type ('type confusion') in Windows Connected User Experiences and Telemetry allows an authorized attacker to elevate privileges locally.

CVSS 7.8 · High
evidence mentions
5
Buzz score
32.4

CVE-2026-50390

Published Jul 14, 2026

Access of resource using incompatible type ('type confusion') in Windows Kernel allows an authorized attacker to elevate privileges locally.

CVSS 7.0 · High
evidence mentions
7
Buzz score
38.3

CVE-2026-55771

Published Jul 13, 2026

CedarJava is an open source Java implementation of the Cedar policy language, used for fine-grained authorization decisions. In versions prior to 4.9.0, the EntityIdentifier.equal…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-55772

Published Jul 13, 2026

CedarJava is an open source Java implementation of the Cedar policy language, used for fine-grained authorization decisions. In versions prior to 2.3.6, 3.4.1 and 4.9.0, under cer…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-58305

Published Jul 9, 2026

Access of resource using incompatible type ('type confusion') vulnerability in Samsung Open Source Escargot allows Pointer Manipulation. This issue affects Escargot: before 779f6…

CVSS 6.1 · Medium
evidence mentions
2
Buzz score
16.0

CVE-2026-59152

Published Jul 6, 2026

LangSmith Client SDKs provide SDK's for interacting with the LangSmith platform. Prior to 0.8.18, an attacker who can send an HTTP request to a server running the LangSmith SDK's…

CVSS 5.0 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-58295

Published Jul 3, 2026

Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to bypass a security feature over a network.

CVSS 8.3 · High
evidence mentions
3
Buzz score
21.9
Vendor/product tagsBeta · best-effort

CVE-2026-58290

Published Jul 3, 2026

Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

CVSS 7.5 · High
evidence mentions
3
Buzz score
21.9
Vendor/product tagsBeta · best-effort
Showing 1-25 of 837 CVEsPage 1 of 34