Vulnerabilities (CVE)

Total 404126 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2026-66326 1 Microsoft 1 Edge Chromium 2026-08-06 N/A 6.5 MEDIUM
Missing authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
CVE-2026-66325 1 Microsoft 1 Edge Chromium 2026-08-06 N/A 6.1 MEDIUM
Server-side request forgery (ssrf) in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
CVE-2026-66322 1 Microsoft 1 Edge Chromium 2026-08-06 N/A 7.1 HIGH
Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
CVE-2026-66321 1 Microsoft 1 Edge Chromium 2026-08-06 N/A 7.4 HIGH
Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
CVE-2026-66318 1 Microsoft 1 Edge Chromium 2026-08-06 N/A 8.1 HIGH
Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.
CVE-2026-66317 1 Microsoft 1 Edge Chromium 2026-08-06 N/A 5.4 MEDIUM
Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform tampering over a network.
CVE-2026-66316 1 Microsoft 1 Edge Chromium 2026-08-06 N/A 5.4 MEDIUM
Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
CVE-2026-66315 1 Microsoft 1 Edge Chromium 2026-08-06 N/A 7.5 HIGH
Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
CVE-2026-66314 1 Microsoft 1 Edge Chromium 2026-08-06 N/A 6.5 MEDIUM
Time-of-check time-of-use (toctou) race condition in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.
CVE-2026-66313 1 Microsoft 1 Edge Chromium 2026-08-06 N/A 6.8 MEDIUM
Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform tampering locally.
CVE-2026-66312 1 Microsoft 1 Edge Chromium 2026-08-06 N/A 6.5 MEDIUM
Buffer over-read in Microsoft Edge (Chromium-based) allows an authorized attacker to execute code over a network.
CVE-2026-66311 1 Microsoft 1 Edge Chromium 2026-08-06 N/A 6.2 MEDIUM
Missing authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform tampering locally.
CVE-2026-65804 1 Microsoft 1 Edge Chromium 2026-08-06 N/A 6.1 MEDIUM
Improper control of generation of code ('code injection') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
CVE-2026-54463 1 Faye 1 Websocket-driver 2026-08-06 N/A 7.5 HIGH
websocket-driver is a WebSocket protocol handler with pluggable I/O. Prior to 0.8.1, draft versions of the WebSocket protocol in websocket-driver include a length header that allows an arbitrarily large integer to be encoded as bytes with the high bit set, and a server or client can send an indefinite sequence of 0x80 or higher bytes that the peer parses into an ever-growing Ruby integer. This can make a WebSocket connection consume an unbounded amount of memory and lead to the host process running out of memory. This issue is fixed in version 0.8.1.
CVE-2025-11362 1 Pdfmake 1 Pdfmake 2026-08-06 N/A 7.5 HIGH
Versions of the package pdfmake from 0.3.0-beta.1 and before 0.3.0-beta.17 are vulnerable to Allocation of Resources Without Limits or Throttling via repeatedly redirect URL in file embedding. An attacker can cause the application to crash or become unresponsive by providing crafted input that triggers this condition.
CVE-2024-21549 2026-08-06 N/A 8.6 HIGH
Versions of the package spatie/browsershot before 5.0.3 are vulnerable to Improper Input Validation due to improper URL validation in the setUrl method. An attacker can exploit this vulnerability by utilizing view-source:file://, which allows for arbitrary file reading on a local file. **Note:** This is a bypass of the fix for [CVE-2024-21544](https://security.snyk.io/vuln/SNYK-PHP-SPATIEBROWSERSHOT-8496745).
CVE-2026-54465 1 Faye 1 Websocket-driver 2026-08-06 N/A 7.5 HIGH
websocket-driver is a WebSocket protocol handler with pluggable I/O. Prior to 0.8.1, when websocket-driver is used to implement a WebSocket server on top of a TCP server using WebSocket::Driver.server() or to complement a WebSocket client, a peer can make a single connection consume an unbounded amount of memory by sending an HTTP request or response with a never-ending list of headers. This can lead to the receiving process running out of memory. This issue is fixed in version 0.8.1.
CVE-2026-54466 1 Faye 1 Websocket-driver 2026-08-06 N/A 7.5 HIGH
websocket-driver is a WebSocket protocol handler with pluggable I/O. Prior to 0.7.5, the frame format in draft versions of the WebSocket protocol includes a length header that allows an arbitrarily large integer to be encoded as a sequence of bytes with the high bit set. By sending an indefinite sequence of bytes with values 0x80 or above, a client can make the server parse these bytes into an ever-growing integer in lib/websocket/driver/draft75.js; because JavaScript numbers are 64-bit floating point values, this number will eventually lose precision and lead to the subsequent payload being parsed incorrectly. This issue is fixed in version 0.7.5.
CVE-2026-57585 1 Msgpack 1 Messagepack 2026-08-06 N/A 7.5 HIGH
MessagePack is the serializer implementation for Python msgpack.org. Prior to 1.2.1, there is an Out-of-bounds read/crash on Unpacker reuse after a caught error, potentially leading to a DoS attack. If the Unpacker is used repeatedly after an error occurs, the process may crash with a SEGV. This issue has been fixed in version 1.2.1.
CVE-2026-18830 2026-08-06 N/A 8.1 HIGH
Insufficient input validation in Amazon Bedrock AgentCore harness might allow an authenticated remote user to execute configured tools bypassing model invocation and security controls via crafted content blocks in conversation messages. AWS has addressed this issue. No customer action is required.