CWE-843
Access of Resource Using Incompatible Type ('Type Confusion')
The product allocates or initializes a resource such as a pointer, object, or variable using one type, but it later accesses that resource using a type that is incompatible with the original type.
745 vulnerabilities with CWE-843
CVE-2026-7337
HIGH
Google Chrome <147.0.7727.138 - Type Confusion RCE
CVSS 8.8
CVE-2026-6732
MEDIUM
Libxml2: libxml2: denial of service via crafted xsd-validated document
CVSS 6.5
CVE-2026-31502
HIGH
team: fix header_ops type confusion with non-Ethernet ports
CVSS 7.8
CVE-2026-6363
HIGH
Google Chrome < 147.0.7727.101 - Out-of-Bounds Access
CVSS 8.8
CVE-2026-6307
HIGH
Google Chrome <147.0.7727.101 - Type Confusion
CVSS 8.8
CVE-2026-6301
HIGH
Google Chrome <147.0.7727.101 - Type Confusion
CVSS 8.8
CVE-2026-27298
HIGH
Adobe Framemaker | Access of Resource Using Incompatible Type ('Type Confusion') (CWE-843)
CVSS 7.8
CVE-2026-40683
HIGH
OpenStack Keystone <25.0.1 - Auth Bypass
CVSS 7.7
CVE-2026-26162
HIGH
Windows OLE Elevation of Privilege Vulnerability
CVSS 7.8
CVE-2026-20806
MEDIUM
Windows COM Server Information Disclosure Vulnerability
CVSS 5.5
CVE-2026-39956
MEDIUM
jq: Missing runtime type checks for _strindices lead to crash and limited memory disclosure
CVSS 6.1
CVE-2026-40446
MEDIUM
Samsung Open Source Escargot 97e8115ab1110bc502b4b5e4a0c689a71520d335 - Type Confusion
CVSS 6.9
CVE-2026-25204
MEDIUM
Samsung Open Source Escargot - Denial of Service
CVSS 6.2
CVE-2026-5496
HIGH
Labcenter Electronics Proteus PDSPRJ File Parsing Type Confusion Remote Code Execution Vulnerability
CVSS 7.8
CVE-2026-5914
HIGH
Google Chrome <147.0.7727.55 - Memory Corruption
CVSS 8.8
CVE-2026-5871
HIGH
Google Chrome <147.0.7727.55 - Type Confusion
CVSS 8.8
CVE-2026-5865
HIGH
Google Chrome <147.0.7727.55 - Type Confusion
CVSS 8.8
CVE-2026-27144
HIGH
Miscompilation allows memory corruption via CONVNOP-wrapped array copy in cmd/compile
CVSS 7.1
CVE-2026-34379
HIGH
OpenEXR has a misaligned write in LossyDctDecoder_execute leading to undefined behavior (DWA/DWAB decompression)
CVSS 7.1
CVE-2026-35541
MEDIUM
Roundcube Webmail <1.5.14 - Auth Bypass
CVSS 4.2
CVE-2026-5360
LOW
Free5GC aper type confusion
CVSS 3.7
CVE-2026-34595
MEDIUM
Parse Server: LiveQuery protected-field guard bypass via array-like logical operator value
CVSS 4.3
CVE-2026-33940
HIGH
Handlebars.js has JavaScript Injection via AST Type Confusion when passing an object as dynamic partial
CVSS 8.1
CVE-2026-33938
HIGH
Handlebars.js has JavaScript Injection via AST Type Confusion by tampering @partial-block
CVSS 8.1
CVE-2026-33937
CRITICAL
Handlebars.js has JavaScript Injection via AST Type Confusion
CVSS 9.8
Details
Vulnerabilities
745