Total
385 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2026-63020 | 1 F5 | 21 Big-ip Access Policy Manager, Big-ip Advanced Firewall Manager, Big-ip Advanced Web Application Firewall and 18 more | 2026-09-15 | N/A | 3.1 LOW |
| A vulnerability exists in an undisclosed BIG-IP Configuration utility page that may allow an attacker to spoof error messages Impact: An attacker may trick authenticated BIG-IP users into accessing malicious links and reflect a spoofed error message in the victim's BIG-IP Configuration utility web browser session. This is a control plane issue; there is no data plane exposure. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | |||||
| CVE-2026-87507 | 1 Google | 1 Chrome | 2026-09-10 | N/A | 5.4 MEDIUM |
| UI misrepresentation in Downloads in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium) | |||||
| CVE-2026-87501 | 1 Google | 1 Chrome | 2026-09-10 | N/A | 5.4 MEDIUM |
| UI misrepresentation in Passwords in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium) | |||||
| CVE-2026-87496 | 1 Google | 1 Chrome | 2026-09-10 | N/A | 5.4 MEDIUM |
| UI misrepresentation in Browser in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium) | |||||
| CVE-2026-87445 | 1 Google | 1 Chrome | 2026-09-10 | N/A | 5.4 MEDIUM |
| UI misrepresentation in Session in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium) | |||||
| CVE-2026-87484 | 1 Google | 1 Chrome | 2026-09-10 | N/A | 5.4 MEDIUM |
| UI misrepresentation in Geometry in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium) | |||||
| CVE-2026-18622 | 3 Apple, Foxit, Microsoft | 4 Macos, Pdf Editor, Pdf Reader and 1 more | 2026-09-10 | N/A | 4.7 MEDIUM |
| Foxit PDF Editor/Reader inconsistently alerts users when signature fields are abnormally modified, including alterations to appearance, coordinates, or field duplication. This may mislead users into trusting tampered documents, since the UI cannot accurately reflect the actual integrity status of signatures. | |||||
| CVE-2026-87649 | 1 Google | 1 Chrome | 2026-09-10 | N/A | 5.4 MEDIUM |
| UI misrepresentation in Downloads in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium) | |||||
| CVE-2026-87583 | 1 Google | 2 Android, Chrome | 2026-09-10 | N/A | 5.4 MEDIUM |
| UI misrepresentation in Passwords in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker to spoof UI elements via a crafted HTML page. (Chromium security severity: Low) | |||||
| CVE-2026-87597 | 1 Google | 2 Android, Chrome | 2026-09-10 | N/A | 4.8 MEDIUM |
| UI misrepresentation in CustomTabs in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker to spoof address bar via a co-installed app. (Chromium security severity: Low) | |||||
| CVE-2026-87624 | 1 Google | 2 Android, Chrome | 2026-09-10 | N/A | 4.2 MEDIUM |
| UI misrepresentation in Passwords in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to spoof UI elements via a crafted HTML page. (Chromium security severity: Low) | |||||
| CVE-2026-87458 | 1 Google | 1 Chrome | 2026-09-09 | N/A | 5.4 MEDIUM |
| UI misrepresentation in Geometry in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium) | |||||
| CVE-2026-87462 | 1 Google | 1 Chrome | 2026-09-09 | N/A | 5.4 MEDIUM |
| UI misrepresentation in FedCM in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium) | |||||
| CVE-2026-87653 | 2 Google, Microsoft | 2 Chrome, Windows | 2026-09-09 | N/A | 5.4 MEDIUM |
| UI misrepresentation in FullScreen in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker to spoof UI elements via a crafted HTML page. (Chromium security severity: Low) | |||||
| CVE-2026-87635 | 1 Google | 1 Chrome | 2026-09-09 | N/A | 5.4 MEDIUM |
| UI misrepresentation in Payments in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium) | |||||
| CVE-2026-87559 | 1 Google | 1 Chrome | 2026-09-09 | N/A | 4.2 MEDIUM |
| UI misrepresentation in UI in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium) | |||||
| CVE-2026-87567 | 1 Google | 1 Chrome | 2026-09-09 | N/A | 4.3 MEDIUM |
| UI misrepresentation in UrlFormatting in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to spoof address bar via a crafted domain name. (Chromium security severity: Medium) | |||||
| CVE-2026-86853 | 2026-09-08 | N/A | 4.3 MEDIUM | ||
| A malicious webpage could repeatedly trigger external URL schemes, causing system prompts or external application launches. This could make Firefox for iOS temporarily unusable until the page is closed. This vulnerability was fixed in Firefox for iOS 155.1. | |||||
| CVE-2026-84330 | 1 Google | 2 Android, Chrome | 2026-09-08 | N/A | 5.4 MEDIUM |
| UI misrepresentation in FullScreen in Google Chrome on on Android prior to 152.0.7977.75 allowed a remote attacker to spoof address bar via a crafted HTML page. (Chromium security severity: Medium) | |||||
| CVE-2025-52652 | 2026-09-08 | N/A | 3.5 LOW | ||
| HCL MyXalytics was affected by Content Spoofing Vulnerability. It may allow an attacker to manipulate displayed content, making it appear as though it originates from a trusted source, potentially leading to phishing or data theft. | |||||
