Total
13237 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2026-17870 | 1 Google | 1 Chrome | 2026-08-03 | N/A | 4.3 MEDIUM |
| Insufficient validation of untrusted input in Cast in Google Chrome prior to 151.0.7922.72 allowed an attacker on the local network segment to leak cross-origin data via malicious network traffic. (Chromium security severity: Medium) | |||||
| CVE-2026-17844 | 1 Google | 1 Chrome | 2026-08-03 | N/A | 4.3 MEDIUM |
| Insufficient validation of untrusted input in Cast in Google Chrome prior to 151.0.7922.72 allowed an attacker on the local network segment to leak cross-origin data via malicious network traffic. (Chromium security severity: Medium) | |||||
| CVE-2026-17861 | 1 Google | 1 Chrome | 2026-08-03 | N/A | 7.8 HIGH |
| Insufficient validation of untrusted input in Updater in Google Chrome prior to 151.0.7922.72 allowed a local attacker to perform OS-level privilege escalation via a malicious file. (Chromium security severity: Medium) | |||||
| CVE-2026-17888 | 1 Google | 1 Chrome | 2026-08-03 | N/A | 7.1 HIGH |
| Insufficient validation of untrusted input in WebUI in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via malicious network traffic. (Chromium security severity: Medium) | |||||
| CVE-2026-17890 | 1 Google | 1 Chrome | 2026-08-03 | N/A | 5.8 MEDIUM |
| Insufficient validation of untrusted input in DevTools in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium) | |||||
| CVE-2026-17893 | 2 Apple, Google | 2 Macos, Chrome | 2026-08-03 | N/A | 5.8 MEDIUM |
| Insufficient validation of untrusted input in Updater in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium) | |||||
| CVE-2026-17906 | 1 Google | 1 Chrome | 2026-08-03 | N/A | 5.8 MEDIUM |
| Insufficient validation of untrusted input in Bluetooth in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low) | |||||
| CVE-2026-17909 | 1 Google | 1 Chrome | 2026-08-03 | N/A | 5.3 MEDIUM |
| Insufficient validation of untrusted input in Isolated Web Apps in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via malicious network traffic. (Chromium security severity: Low) | |||||
| CVE-2026-17921 | 1 Google | 1 Chrome | 2026-08-03 | N/A | 6.5 MEDIUM |
| Insufficient validation of untrusted input in Navigation in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Low) | |||||
| CVE-2026-17926 | 1 Google | 1 Chrome | 2026-08-03 | N/A | 6.5 MEDIUM |
| Insufficient validation of untrusted input in DevTools in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who convinced a user to engage in specific UI gestures to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Low) | |||||
| CVE-2026-17929 | 1 Google | 1 Chrome | 2026-08-03 | N/A | 6.5 MEDIUM |
| Insufficient validation of untrusted input in DevTools in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to bypass navigation restrictions via a malicious file. (Chromium security severity: Low) | |||||
| CVE-2026-17930 | 1 Google | 1 Chrome | 2026-08-03 | N/A | 7.5 HIGH |
| Insufficient validation of untrusted input in Extensions in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to perform privilege escalation via a crafted HTML page. (Chromium security severity: Low) | |||||
| CVE-2026-17934 | 1 Google | 1 Chrome | 2026-08-03 | N/A | 4.3 MEDIUM |
| Insufficient validation of untrusted input in DevTools in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Low) | |||||
| CVE-2026-17937 | 1 Google | 1 Chrome | 2026-08-03 | N/A | 4.3 MEDIUM |
| Insufficient validation of untrusted input in DevTools in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Low) | |||||
| CVE-2026-17939 | 1 Google | 1 Chrome | 2026-08-03 | N/A | 4.3 MEDIUM |
| Insufficient validation of untrusted input in Passwords in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to perform UI spoofing via malicious network traffic. (Chromium security severity: Low) | |||||
| CVE-2026-17955 | 1 Google | 1 Chrome | 2026-08-03 | N/A | 4.3 MEDIUM |
| Insufficient validation of untrusted input in Payments in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low) | |||||
| CVE-2026-17988 | 1 Google | 1 Chrome | 2026-08-03 | N/A | 6.5 MEDIUM |
| Insufficient validation of untrusted input in Navigation in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Low) | |||||
| CVE-2026-17990 | 1 Google | 1 Chrome | 2026-08-03 | N/A | 9.6 CRITICAL |
| Insufficient validation of untrusted input in WebAuthn in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted PDF file. (Chromium security severity: Low) | |||||
| CVE-2026-60719 | 1 Oracle | 1 Bi Publisher | 2026-08-03 | N/A | 9.9 CRITICAL |
| Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: Web Service API). Supported versions that are affected are 8.2.0.0.0, 12.2.1.4.0 and 26.01.0.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle BI Publisher. While the vulnerability is in Oracle BI Publisher, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle BI Publisher accessible data as well as unauthorized access to critical data or complete access to all Oracle BI Publisher accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle BI Publisher. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L). | |||||
| CVE-2026-17987 | 1 Google | 1 Chrome | 2026-08-03 | N/A | 9.6 CRITICAL |
| Insufficient validation of untrusted input in Notifications in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted PDF file. (Chromium security severity: Low) | |||||
