Common Vulnerabilities and Exposures (CVE)

CVE-2026-11603

Jul 30, 2026 17:51:02 UTC

The Product Filter Widget for Elementor plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via 'args[filterFormArray]' Parameter in all versions up to, and including, 1.0.6 due to insufficient input sanitization and output...

CVE-2026-17997

Jul 30, 2026 17:50:37 UTC

Inappropriate implementation in Passwords in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)

CVE-2026-17991

Jul 30, 2026 17:50:00 UTC

Insufficient validation of untrusted input in AI in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security ...

CVE-2026-18000

Jul 30, 2026 17:49:47 UTC

Insufficient policy enforcement in USB in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low...

CVE-2026-17904

Jul 30, 2026 17:49:18 UTC

Insufficient policy enforcement in NFC in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)

CVE-2026-47304

Jul 30, 2026 17:48:58 UTC

Improper verification of cryptographic signature in .NET allows an unauthorized attacker to bypass a security feature over a network.

CVE-2026-50343

Jul 30, 2026 17:48:57 UTC

Improper privilege management in Microsoft Install Service allows an authorized attacker to elevate privileges locally.

CVE-2026-54128

Jul 30, 2026 17:48:57 UTC

Use after free in Windows DHCP Client allows an unauthorized attacker to execute code locally.

CVE-2026-56197

Jul 30, 2026 17:48:56 UTC

Improper neutralization of special elements used in a command ('command injection') in Windows Admin Center allows an authorized attacker to execute code over a network.

CVE-2026-50377

Jul 30, 2026 17:48:56 UTC

Out-of-bounds read in Windows Kernel allows an authorized attacker to elevate privileges locally.

CVE-2026-62835

Jul 30, 2026 17:48:55 UTC

Improper authorization in Azure Portal allows an unauthorized attacker to disclose information over a network.

CVE-2026-58275

Jul 30, 2026 17:48:55 UTC

Missing authorization in Azure DNS allows an unauthorized attacker to elevate privileges over a network.

CVE-2026-58630

Jul 30, 2026 17:48:54 UTC

Improper access control in Azure App Service allows an unauthorized attacker to elevate privileges over a network.

CVE-2026-62825

Jul 30, 2026 17:48:54 UTC

Improper authentication in Azure Key Vault allows an unauthorized attacker to elevate privileges over a network.

CVE-2026-57106

Jul 30, 2026 17:48:53 UTC

Server-side request forgery (ssrf) in Data Quality allows an unauthorized attacker to elevate privileges over a network.