U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.


The NVD is the U.S. government repository of standards based vulnerability management data represented using the Security Content Automation Protocol (SCAP). This data enables automation of vulnerability management, security measurement, and compliance. The NVD includes databases of security checklist references, security-related software flaws, product names, and impact metrics.

For information on how to cite the NVD, including the database's Digital Object Identifier (DOI), please consult NIST's Public Data Repository.

Last 20 Scored Vulnerability IDs & Summaries CVSS Severity
  • CVE-2026-60739 - Vulnerability in the Oracle Field Service product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network a... read CVE-2026-60739
    Published: 七月 21, 2026; 6:18:14 下午 -0400

  • CVE-2026-17991 - Insufficient validation of untrusted input in AI in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severit... read CVE-2026-17991
    Published: 七月 29, 2026; 9:17:03 下午 -0400

  • CVE-2026-17966 - Inappropriate implementation in Views in Google Chrome on Mac prior to 151.0.7922.72 allowed a local attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Low)
    Published: 七月 29, 2026; 9:17:01 下午 -0400

  • CVE-2026-17977 - Policy bypass in CSS in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)
    Published: 七月 29, 2026; 9:17:02 下午 -0400

  • CVE-2026-62343 - ImageMagick is free and open-source software used for editing and manipulating digital images. In versions prior to 6.9.13-51 and 7.0.1-0 and above prior to 7.1.2-26, an invalid kernel can cause a heap buffer over-write when performing a morpholog... read CVE-2026-62343
    Published: 七月 29, 2026; 8:16:24 下午 -0400

  • CVE-2026-17970 - Insufficient validation of untrusted input in Passwords in Google Chrome prior to 151.0.7922.72 allowed an attacker in a privileged network position to perform UI spoofing via malicious network traffic. (Chromium security severity: Low)
    Published: 七月 29, 2026; 9:17:01 下午 -0400

  • CVE-2026-60756 - Vulnerability in the Oracle EDI Gateway product of Oracle E-Business Suite (component: All Miscellaneous EDI Issues). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows unauthenticated attacker with... read CVE-2026-60756
    Published: 七月 21, 2026; 6:18:15 下午 -0400

  • CVE-2026-62363 - ImageMagick is free and open-source software used for editing and manipulating digital images. In versions prior to 7.1.2-27, a heap buffer over-write can occur in the fx operation by passing a crafted argument. This issue has been fixed in versio... read CVE-2026-62363
    Published: 七月 29, 2026; 8:16:25 下午 -0400

  • CVE-2026-17971 - Inappropriate implementation in Frame in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page. (Chromium security severity: Low)
    Published: 七月 29, 2026; 9:17:01 下午 -0400

  • CVE-2026-17981 - Inappropriate implementation in Blink in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)
    Published: 七月 29, 2026; 9:17:02 下午 -0400

  • CVE-2026-62946 - ImageMagick is free and open-source software used for editing and manipulating digital images. In versions prior to both 6.9.13-52 and 7.1.2-27, processing an extremely large JNX file on 32-bit platforms can cause an integer overflow, leading to a... read CVE-2026-62946
    Published: 七月 29, 2026; 8:16:25 下午 -0400

    V3.1: 4.7 MEDIUM

  • CVE-2026-60760 - Vulnerability in the Oracle Enterprise Asset Management product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacke... read CVE-2026-60760
    Published: 七月 21, 2026; 6:18:15 下午 -0400

  • CVE-2026-60762 - Vulnerability in the Oracle Applications Technology Stack product of Oracle E-Business Suite (component: Configuration). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows high privileged attacker w... read CVE-2026-60762
    Published: 七月 21, 2026; 6:18:15 下午 -0400

  • CVE-2026-18005 - Inappropriate implementation in WebXR in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Low)
    Published: 七月 29, 2026; 9:17:05 下午 -0400

  • CVE-2026-18006 - Inappropriate implementation in Google Lens in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)
    Published: 七月 29, 2026; 9:17:05 下午 -0400

  • CVE-2026-63144 - Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to denial of service via a specially crafted search request submitted by a low-privileged authenticated user. A user with read-level index access can submit a request that triggers unbound... read CVE-2026-63144
    Published: 七月 21, 2026; 7:18:02 下午 -0400

  • CVE-2026-18008 - Inappropriate implementation in Settings in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to perform UI spoofing via malicious network traffic. (Chromium security severity: Low)
    Published: 七月 29, 2026; 9:17:05 下午 -0400

  • CVE-2026-18001 - Inappropriate implementation in WebGL in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Low)
    Published: 七月 29, 2026; 9:17:04 下午 -0400

  • CVE-2026-18002 - Insufficient validation of untrusted input in Google Lens in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium securit... read CVE-2026-18002
    Published: 七月 29, 2026; 9:17:04 下午 -0400

  • CVE-2026-18004 - Insufficient policy enforcement in Speech in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)
    Published: 七月 29, 2026; 9:17:05 下午 -0400

Created September 20, 2022 , Updated August 27, 2024