Total
398400 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2021-47998 | 2026-08-27 | N/A | N/A | ||
| Rejected reason: This CVE ID has been rejected. | |||||
| CVE-2021-47997 | 2026-08-27 | N/A | N/A | ||
| Rejected reason: This CVE ID has been rejected. | |||||
| CVE-2021-47983 | 2026-08-27 | N/A | 6.4 MEDIUM | ||
| WordPress Plugin Stripe Payments before 2.0.40 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts through the AcceptStripePayments-settings[currency_code] parameter. Attackers can submit POST requests to /wp-admin/options.php with script payloads in the currency_code field to execute arbitrary JavaScript in administrator browsers when settings are viewed. | |||||
| CVE-2026-43670 | 1 Apple | 4 Ipados, Iphone Os, Macos and 1 more | 2026-08-27 | N/A | 8.8 HIGH |
| A Content Security Policy bypass was addressed with improved enforcement in AudioWorklet contexts. This issue is fixed in Safari 26.5, iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5. Processing maliciously crafted web content may bypass Content Security Policy. | |||||
| CVE-2026-78893 | 1 Google | 1 Chrome | 2026-08-27 | N/A | 6.5 MEDIUM |
| Information leak in QUIC in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to leak sensitive information via a crafted HTML page. (Chromium security severity: Medium) | |||||
| CVE-2026-78894 | 1 Google | 1 Chrome | 2026-08-27 | N/A | 3.1 LOW |
| Race condition in Payments in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium) | |||||
| CVE-2026-78896 | 1 Google | 1 Chrome | 2026-08-27 | N/A | 4.3 MEDIUM |
| Information leak in StorageAccessAPI in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (Chromium security severity: Low) | |||||
| CVE-2026-66299 | 1 Apache | 1 Tomcat | 2026-08-27 | N/A | 5.3 MEDIUM |
| Uncontrolled Resource Consumption vulnerability in Apache Tomcat's WebSocket chat example. This issue affects Apache Tomcat: from 11.0.0-M20 through 11.0.24, from 10.1.24 through 10.1.57, from 9.0.89 through 9.0.120. Users who have followed the security guidance to remove the examples web application are not affected by this issue. Users are recommended to remove the examples web application or to upgrade to version 11.0.25, 10.1.58 or 9.0.121 (when released), which fix the issue. | |||||
| CVE-2026-78897 | 1 Google | 1 Chrome | 2026-08-27 | N/A | 6.5 MEDIUM |
| Missing authorization in BrowserTag in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted Chrome extension. (Chromium security severity: Low) | |||||
| CVE-2026-78900 | 1 Google | 1 Chrome | 2026-08-27 | N/A | 9.6 CRITICAL |
| Improper input validation in Media in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High) | |||||
| CVE-2026-78904 | 1 Google | 1 Chrome | 2026-08-27 | N/A | 9.6 CRITICAL |
| Type confusion in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High) | |||||
| CVE-2026-78907 | 1 Google | 1 Chrome | 2026-08-27 | N/A | 6.5 MEDIUM |
| Incorrect authorization in WebProtect in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to leak sensitive information via a crafted HTML page. (Chromium security severity: Medium) | |||||
| CVE-2026-78911 | 1 Google | 1 Chrome | 2026-08-27 | N/A | 8.3 HIGH |
| Incorrect authorization in USB in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High) | |||||
| CVE-2026-78914 | 1 Google | 1 Chrome | 2026-08-27 | N/A | 6.5 MEDIUM |
| Uninitialized resource in Skia in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially read memory inside the sandbox via a crafted HTML page. (Chromium security severity: Low) | |||||
| CVE-2026-78934 | 1 Google | 1 Chrome | 2026-08-27 | N/A | 8.3 HIGH |
| Race condition in ReadAloud in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High) | |||||
| CVE-2026-44902 | 1 Opentelemetry | 3 Opentelemetry\/auto-instrumentations-node, Opentelemetry\/exporter-prometheus, Opentelemetry\/sdk-node | 2026-08-27 | N/A | 7.5 HIGH |
| opentelemetry-js is the OpenTelemetry JavaScript Client. Prior to 0.217.0, a single malformed HTTP request crashes any Node.js process running the OpenTelemetry JS Prometheus exporter. The metrics endpoint (default 0.0.0.0:9464) has no error handling around URL parsing, so a request with an invalid URI causes an uncaught TypeError that terminates the process. This vulnerability is fixed in 0.217.0. | |||||
| CVE-2026-54285 | 1 Opentelemetry | 1 Opentelemetry | 2026-08-27 | N/A | 5.3 MEDIUM |
| opentelemetry-js is the OpenTelemetry JavaScript Client. Prior to 2.8.0, W3CBaggagePropagator.extract() in @opentelemetry/core does not enforce size limits when parsing inbound baggage HTTP headers. The W3C Baggage specification recommends a maximum of 8,192 bytes and 180 entries; these limits were only enforced on the outbound (inject()) path, not on the inbound (extract()) path. Parsing oversized baggage causes memory allocation proportional to the header size without any cap. This vulnerability is fixed in 2.8.0. | |||||
| CVE-2026-65182 | 1 Apache | 1 Tomcat | 2026-08-27 | N/A | 9.1 CRITICAL |
| Improper Access Control, Incorrect Authorization vulnerability in Apache Tomcat leads to security constraint bypass if a constraint for a longer path is specified before a more restrictive constraint for a shorter sub-path. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, from 10.1.0-M1 through 10.1.57, from 9.0.0.M1 through 9.0.120, from 8.5.0 through 8.5.100, from 7.0.0 through 7.0.109. Users are recommended to upgrade to version 11.0.25, 10.1.58, 9.0.121, which fixes the issue. | |||||
| CVE-2026-65183 | 1 Apache | 1 Tomcat | 2026-08-27 | N/A | 8.1 HIGH |
| Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Apache Tomcat when creating unix domain sockets allows an unauthorised local user to access the unix domain socket. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, from 10.1.0-M1 through 10.1.57, from 9.0.42 through 9.0.120. Users are recommended to upgrade to version 11.0.25, 10.1.58, 9.0.121, which fixes the issue. | |||||
| CVE-2026-65637 | 1 Apache | 1 Tomcat | 2026-08-27 | N/A | 9.8 CRITICAL |
| Improper Input Validation vulnerability in Apache Tomcat due to incomplete fix for CVE-2026-32990. This issue affects Apache Tomcat: from 11.0.20 through 11.0.24, from 10.1.53 through 10.1.57, from 9.0.115 through 9.0.120. Users are recommended to upgrade to version 11.0.25, 10.1.58 or 9.0.121, which fix the issue. | |||||
