Total
398043 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2026-78942 | 1 Google | 1 Chrome | 2026-08-28 | N/A | 4.3 MEDIUM |
| Incorrect reference resolution in Loader in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass web origin policy via crafted network traffic. (Chromium security severity: Medium) | |||||
| CVE-2026-78943 | 1 Google | 1 Chrome | 2026-08-28 | N/A | 3.1 LOW |
| Improper input validation in Editing in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium) | |||||
| CVE-2026-78947 | 1 Google | 1 Chrome | 2026-08-28 | N/A | 6.5 MEDIUM |
| Incomplete cleanup in Chromium in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to bypass web origin policy via a crafted Chrome extension. (Chromium security severity: Low) | |||||
| CVE-2026-78954 | 1 Google | 1 Chrome | 2026-08-28 | N/A | 4.3 MEDIUM |
| Incorrect authorization in Extensions in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: High) | |||||
| CVE-2026-79084 | 2 Google, Microsoft | 2 Chrome, Windows | 2026-08-28 | N/A | 4.3 MEDIUM |
| Inadequate encryption strength in Notifications in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium) | |||||
| CVE-2026-79085 | 1 Google | 1 Chrome | 2026-08-28 | N/A | 4.3 MEDIUM |
| Missing authorization in Network in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium) | |||||
| CVE-2026-79086 | 1 Google | 2 Android, Chrome | 2026-08-28 | N/A | 5.1 MEDIUM |
| Missing authorization in CustomTabs in Google Chrome on on Android prior to 152.0.7977.65 allowed a local attacker to obtain sensitive information via a co-installed app. (Chromium security severity: Medium) | |||||
| CVE-2026-79090 | 1 Google | 1 Chrome | 2026-08-28 | N/A | 9.8 CRITICAL |
| Improper privilege management in Actor in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Low) | |||||
| CVE-2026-79093 | 1 Google | 1 Chrome | 2026-08-28 | N/A | 4.3 MEDIUM |
| Incorrect authorization in Paint in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially bypass web origin policy via a crafted HTML page. (Chromium security severity: High) | |||||
| CVE-2026-79223 | 1 Google | 1 Chrome | 2026-08-28 | N/A | 8.8 HIGH |
| Integer overflow in Chromium in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to read memory inside the sandbox via a crafted file. (Chromium security severity: Low) | |||||
| CVE-2026-59638 | 1 Bouncycastle | 3 Bc-java, Bctls-fips, Bouncy Castle For Java Lts | 2026-08-28 | N/A | 6.5 MEDIUM |
| In Bouncy Castle for Java before 1.85, JSSE hostname verifier CN-fallback enabled by default despite documented opt-in. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bctls-fips 1.0.24 (1.0.X series), 2.0.24 (2.0.X series) and 2.1.24 (2.1.X series). | |||||
| CVE-2026-14682 | 1 Bouncycastle | 4 Bc-java, Bctls-fips, Bouncy Castle For Java Lts and 1 more | 2026-08-28 | N/A | 7.5 HIGH |
| In Bouncy Castle for Java before 1.85, Possible OOM from unbounded up-front allocation on a definite-length read. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7 (1.0.X series), 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series), and before bctls-fips 1.0.24. | |||||
| CVE-2026-13586 | 1 Bouncycastle | 3 Bc-java, Bouncy Castle For Java Lts, Fips Java Api | 2026-08-28 | N/A | 7.5 HIGH |
| In Bouncy Castle for Java before 1.85, PKCS#12 MAC and bag-decryption KDF iteration-count bound (DoS). This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7 (1.0.X series), 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series). | |||||
| CVE-2026-13506 | 1 Bouncycastle | 3 Bc-java, Bouncy Castle For Java Lts, Fips Java Api | 2026-08-28 | N/A | 7.5 HIGH |
| In Bouncy Castle for Java before 1.85, Lazy ASN.1 sequence forcing resets nesting-depth guard. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7 (1.0.X series), 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series). | |||||
| CVE-2026-12860 | 1 Bouncycastle | 2 Bc-java, Bouncy Castle For Java Lts | 2026-08-28 | N/A | 5.3 MEDIUM |
| In Bouncy Castle for Java before 1.85, RSA PKCS#1 verification skips last two hash bytes in NULL-omitted path. This issue also affects Bouncy Castle for Java LTS before 2.73.12. | |||||
| CVE-2026-82222 | 2026-08-28 | N/A | 10.0 CRITICAL | ||
| Deserialization of Untrusted Data vulnerability in Liquid Web / StellarWP GiveWP allows Object Injection. This issue affects GiveWP: from n/a through 4.16.7.1. | |||||
| CVE-2026-80697 | 2026-08-28 | N/A | N/A | ||
| In the Linux kernel, the following vulnerability has been resolved: erofs: ensure valid f_path for page cache sharing Previously, backing files for page cache sharing were set up with f_path left as NULL (only f_inode was valid). It worked, but a recent mincore fix relies on f_path.mnt and crashes (found by "erofs/028" on 7.2-rc4): BUG: kernel NULL pointer dereference, address: 0000000000000018 #PF: supervisor read access in kernel mode #PF: error_code(0x0000) - not-present page PGD 0 P4D 0 Oops: Oops: 0000 [#1] SMP PTI CPU: 3 UID: 0 PID: 675528 Comm: fincore Not tainted 7.2.0-rc4-00002-g[]-dirty #1 PREEMPT(lazy) Hardware name: Red Hat KVM, BIOS 1.16.0-4.al8 04/01/2014 RIP: 0010:__do_sys_mincore+0xc0/0x2c0 ... Specify valid paths using valid disconnected dentries together with erofs_ishare_mnt instead of leaving f_path empty, so they are more like real backing files in a pseudo filesystem and standard backing_file_open() can be used directly. | |||||
| CVE-2026-78073 | 2026-08-28 | N/A | N/A | ||
| Joomla Extension - mrvinoth.com - Reflected XSS in All Video Share 1.0.0-4.5.0 - Various user supplied inputs lacked escaping, leading to reflected XSS vectors | |||||
| CVE-2026-78072 | 2026-08-28 | N/A | N/A | ||
| Joomla Extension - Jefferson49 - Unauthenticated blind SQLi in Sexy Polling Reloaded < 5.6.1 | |||||
| CVE-2026-78070 | 2026-08-28 | N/A | N/A | ||
| Joomla Extension - digital-peak.com - Authenticated, privileged blind SQL injection in DP Calendar 5.5.0 - 10.11.2 - Saving an article can trigger a blind SQL injection with content plugin, needs update permission for articles. | |||||
