Total
8659 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2026-87524 | 2 Google, Microsoft | 2 Chrome, Windows | 2026-09-10 | N/A | 8.3 HIGH |
| Use after free in Core in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High) | |||||
| CVE-2026-87520 | 1 Google | 2 Android, Chrome | 2026-09-10 | N/A | 9.6 CRITICAL |
| Use after free in Dawn in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High) | |||||
| CVE-2026-87514 | 1 Google | 1 Chrome | 2026-09-10 | N/A | 8.1 HIGH |
| Use after free in Views in Google Chrome prior to 153.0.8010.36 allowed a local attacker to execute arbitrary code outside the sandbox via a local program. (Chromium security severity: High) | |||||
| CVE-2026-87512 | 2 Google, Microsoft | 2 Chrome, Windows | 2026-09-10 | N/A | 9.6 CRITICAL |
| Use after free in ANGLE in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High) | |||||
| CVE-2026-87504 | 1 Google | 1 Chrome | 2026-09-10 | N/A | 9.6 CRITICAL |
| Use after free in Core in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox via a crafted Chrome extension. (Chromium security severity: Medium) | |||||
| CVE-2026-87488 | 1 Google | 2 Android, Chrome | 2026-09-10 | N/A | 9.6 CRITICAL |
| Use after free in WebGL in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical) | |||||
| CVE-2026-87480 | 1 Google | 1 Chrome | 2026-09-10 | N/A | 8.3 HIGH |
| Use after free in Printing in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High) | |||||
| CVE-2026-87474 | 1 Google | 1 Chrome | 2026-09-10 | N/A | 9.6 CRITICAL |
| Use after free in Payments in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High) | |||||
| CVE-2026-87460 | 1 Google | 1 Chrome | 2026-09-10 | N/A | 8.8 HIGH |
| Use after free in Platform in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High) | |||||
| CVE-2026-87455 | 1 Google | 1 Chrome | 2026-09-10 | N/A | 9.6 CRITICAL |
| Use after free in Aura in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium) | |||||
| CVE-2026-87448 | 1 Google | 1 Chrome | 2026-09-10 | N/A | 9.6 CRITICAL |
| Use after free in DevTools in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Low) | |||||
| CVE-2026-77505 | 2026-09-10 | N/A | 8.1 HIGH | ||
| Use after free in DNS Server allows an unauthorized attacker to execute code over a network. | |||||
| CVE-2026-72987 | 2026-09-10 | N/A | 8.1 HIGH | ||
| Use after free in Windows DNS allows an unauthorized attacker to execute code over a network. | |||||
| CVE-2026-69775 | 2026-09-10 | N/A | 7.1 HIGH | ||
| Use after free in Windows DWM Core Library allows an authorized attacker to elevate privileges over a network. | |||||
| CVE-2026-69730 | 2026-09-10 | N/A | 9.8 CRITICAL | ||
| Use after free in Windows DNS allows an unauthorized attacker to execute code over a network. | |||||
| CVE-2026-69645 | 2026-09-10 | N/A | 7.0 HIGH | ||
| Use after free in Windows Message Queuing allows an authorized attacker to elevate privileges locally. | |||||
| CVE-2026-69575 | 2026-09-10 | N/A | 7.0 HIGH | ||
| Use after free in Windows Storage Spaces Controller allows an authorized attacker to elevate privileges locally. | |||||
| CVE-2026-69551 | 2026-09-10 | N/A | 8.8 HIGH | ||
| Use after free in Windows DNS allows an authorized attacker to execute code over a network. | |||||
| CVE-2026-69310 | 2026-09-10 | N/A | 7.0 HIGH | ||
| Use after free in Windows DNS allows an authorized attacker to elevate privileges locally. | |||||
| CVE-2026-63380 | 2026-09-09 | N/A | N/A | ||
| Libevent is an event notification library. Prior to 2.2.2-alpha, libevent can dereference invalid list pointers in ws.c when evws_new_session enters its error path after evhttp_start_ws_ succeeds but bufferevent_enable_locking_ fails. evws_connection_free sees a non-null http_server and unconditionally calls TAILQ_REMOVE even though the session was never inserted into http_server->ws_sessions. A local caller able to induce this allocation or locking failure can crash the process. This issue is fixed in version 2.2.2-alpha. | |||||
