Total
404126 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2026-66326 | 1 Microsoft | 1 Edge Chromium | 2026-08-06 | N/A | 6.5 MEDIUM |
| Missing authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. | |||||
| CVE-2026-66325 | 1 Microsoft | 1 Edge Chromium | 2026-08-06 | N/A | 6.1 MEDIUM |
| Server-side request forgery (ssrf) in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network. | |||||
| CVE-2026-66322 | 1 Microsoft | 1 Edge Chromium | 2026-08-06 | N/A | 7.1 HIGH |
| Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network. | |||||
| CVE-2026-66321 | 1 Microsoft | 1 Edge Chromium | 2026-08-06 | N/A | 7.4 HIGH |
| Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. | |||||
| CVE-2026-66318 | 1 Microsoft | 1 Edge Chromium | 2026-08-06 | N/A | 8.1 HIGH |
| Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network. | |||||
| CVE-2026-66317 | 1 Microsoft | 1 Edge Chromium | 2026-08-06 | N/A | 5.4 MEDIUM |
| Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform tampering over a network. | |||||
| CVE-2026-66316 | 1 Microsoft | 1 Edge Chromium | 2026-08-06 | N/A | 5.4 MEDIUM |
| Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network. | |||||
| CVE-2026-66315 | 1 Microsoft | 1 Edge Chromium | 2026-08-06 | N/A | 7.5 HIGH |
| Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. | |||||
| CVE-2026-66314 | 1 Microsoft | 1 Edge Chromium | 2026-08-06 | N/A | 6.5 MEDIUM |
| Time-of-check time-of-use (toctou) race condition in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network. | |||||
| CVE-2026-66313 | 1 Microsoft | 1 Edge Chromium | 2026-08-06 | N/A | 6.8 MEDIUM |
| Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform tampering locally. | |||||
| CVE-2026-66312 | 1 Microsoft | 1 Edge Chromium | 2026-08-06 | N/A | 6.5 MEDIUM |
| Buffer over-read in Microsoft Edge (Chromium-based) allows an authorized attacker to execute code over a network. | |||||
| CVE-2026-66311 | 1 Microsoft | 1 Edge Chromium | 2026-08-06 | N/A | 6.2 MEDIUM |
| Missing authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform tampering locally. | |||||
| CVE-2026-65804 | 1 Microsoft | 1 Edge Chromium | 2026-08-06 | N/A | 6.1 MEDIUM |
| Improper control of generation of code ('code injection') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network. | |||||
| CVE-2026-54463 | 1 Faye | 1 Websocket-driver | 2026-08-06 | N/A | 7.5 HIGH |
| websocket-driver is a WebSocket protocol handler with pluggable I/O. Prior to 0.8.1, draft versions of the WebSocket protocol in websocket-driver include a length header that allows an arbitrarily large integer to be encoded as bytes with the high bit set, and a server or client can send an indefinite sequence of 0x80 or higher bytes that the peer parses into an ever-growing Ruby integer. This can make a WebSocket connection consume an unbounded amount of memory and lead to the host process running out of memory. This issue is fixed in version 0.8.1. | |||||
| CVE-2025-11362 | 1 Pdfmake | 1 Pdfmake | 2026-08-06 | N/A | 7.5 HIGH |
| Versions of the package pdfmake from 0.3.0-beta.1 and before 0.3.0-beta.17 are vulnerable to Allocation of Resources Without Limits or Throttling via repeatedly redirect URL in file embedding. An attacker can cause the application to crash or become unresponsive by providing crafted input that triggers this condition. | |||||
| CVE-2024-21549 | 2026-08-06 | N/A | 8.6 HIGH | ||
| Versions of the package spatie/browsershot before 5.0.3 are vulnerable to Improper Input Validation due to improper URL validation in the setUrl method. An attacker can exploit this vulnerability by utilizing view-source:file://, which allows for arbitrary file reading on a local file. **Note:** This is a bypass of the fix for [CVE-2024-21544](https://security.snyk.io/vuln/SNYK-PHP-SPATIEBROWSERSHOT-8496745). | |||||
| CVE-2026-54465 | 1 Faye | 1 Websocket-driver | 2026-08-06 | N/A | 7.5 HIGH |
| websocket-driver is a WebSocket protocol handler with pluggable I/O. Prior to 0.8.1, when websocket-driver is used to implement a WebSocket server on top of a TCP server using WebSocket::Driver.server() or to complement a WebSocket client, a peer can make a single connection consume an unbounded amount of memory by sending an HTTP request or response with a never-ending list of headers. This can lead to the receiving process running out of memory. This issue is fixed in version 0.8.1. | |||||
| CVE-2026-54466 | 1 Faye | 1 Websocket-driver | 2026-08-06 | N/A | 7.5 HIGH |
| websocket-driver is a WebSocket protocol handler with pluggable I/O. Prior to 0.7.5, the frame format in draft versions of the WebSocket protocol includes a length header that allows an arbitrarily large integer to be encoded as a sequence of bytes with the high bit set. By sending an indefinite sequence of bytes with values 0x80 or above, a client can make the server parse these bytes into an ever-growing integer in lib/websocket/driver/draft75.js; because JavaScript numbers are 64-bit floating point values, this number will eventually lose precision and lead to the subsequent payload being parsed incorrectly. This issue is fixed in version 0.7.5. | |||||
| CVE-2026-57585 | 1 Msgpack | 1 Messagepack | 2026-08-06 | N/A | 7.5 HIGH |
| MessagePack is the serializer implementation for Python msgpack.org. Prior to 1.2.1, there is an Out-of-bounds read/crash on Unpacker reuse after a caught error, potentially leading to a DoS attack. If the Unpacker is used repeatedly after an error occurs, the process may crash with a SEGV. This issue has been fixed in version 1.2.1. | |||||
| CVE-2026-18830 | 2026-08-06 | N/A | 8.1 HIGH | ||
| Insufficient input validation in Amazon Bedrock AgentCore harness might allow an authenticated remote user to execute configured tools bypassing model invocation and security controls via crafted content blocks in conversation messages. AWS has addressed this issue. No customer action is required. | |||||
