Vulnerabilities (CVE)

Filtered by vendor Microsoft Subscribe
Filtered by product Windows
Total 10318 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2026-87524 2 Google, Microsoft 2 Chrome, Windows 2026-09-10 N/A 8.3 HIGH
Use after free in Core in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
CVE-2026-87512 2 Google, Microsoft 2 Chrome, Windows 2026-09-10 N/A 9.6 CRITICAL
Use after free in ANGLE in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
CVE-2026-87509 2 Google, Microsoft 2 Chrome, Windows 2026-09-10 N/A 8.1 HIGH
Incorrect authorization in Updater in Google Chrome on on Windows prior to 153.0.8010.36 allowed a local attacker to execute arbitrary code outside the sandbox via a local program. (Chromium security severity: Low)
CVE-2026-87467 2 Google, Microsoft 2 Chrome, Windows 2026-09-10 N/A 8.1 HIGH
Race condition in Updater in Google Chrome on on Windows prior to 153.0.8010.36 allowed a local attacker to potentially execute arbitrary code outside the sandbox via a local program. (Chromium security severity: High)
CVE-2026-87457 2 Google, Microsoft 2 Chrome, Windows 2026-09-10 N/A 8.1 HIGH
Race condition in Updater in Google Chrome on on Windows prior to 153.0.8010.36 allowed a local attacker to execute arbitrary code outside the sandbox via a local program. (Chromium security severity: Medium)
CVE-2026-87653 2 Google, Microsoft 2 Chrome, Windows 2026-09-09 N/A 5.4 MEDIUM
UI misrepresentation in FullScreen in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker to spoof UI elements via a crafted HTML page. (Chromium security severity: Low)
CVE-2026-87602 2 Google, Microsoft 2 Chrome, Windows 2026-09-09 N/A 4.7 MEDIUM
Out of bounds read in ANGLE in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker to potentially read memory outside the sandbox via a crafted HTML page. (Chromium security severity: Low)
CVE-2026-87494 2 Google, Microsoft 2 Chrome, Windows 2026-09-09 N/A 9.6 CRITICAL
Use after free in Browser in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-87454 2 Google, Microsoft 2 Chrome, Windows 2026-09-09 N/A 6.5 MEDIUM
Information leak in Enterprise in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-0294 3 Apple, Microsoft, Paloaltonetworks 3 Macos, Windows, Prisma Access Agent 2026-09-09 N/A 7.8 HIGH
A privilege escalation (PE) vulnerability in the Palo Alto Networks Prisma® Access Agent app on Windows and macOS devices enables a local user to execute code with elevated privileges. The Prisma Access Agent on Linux, iOS, Android, and ChromeOS is not affected.
CVE-2026-0293 2 Microsoft, Paloaltonetworks 2 Windows, Prisma Access Agent 2026-09-09 N/A 6.0 MEDIUM
A vulnerability in Palo Alto Networks Prisma® Access Agent on Windows enables a local attacker with administrator privileges to bypass the anti-tamper protection, enabling unauthorized access to protected processes and files. The Prisma Access Agent on Linux, macOS, iOS, Android, and Chrome OS is not affected.
CVE-2026-0292 2 Microsoft, Paloaltonetworks 2 Windows, Prisma Access Agent 2026-09-09 N/A 6.0 MEDIUM
An authentication bypass vulnerability in the network driver of Palo Alto Networks Prisma® Access Agent on Windows enables a local administrator to bypass security inspection, subsequently allowing them to inject and intercept arbitrary network traffic. The Prisma Access Agent on Linux, macOS, iOS, Android, and Chrome OS is not affected.
CVE-2026-77104 3 Commvault, Linux, Microsoft 3 Commvault, Linux Kernel, Windows 2026-09-09 N/A 7.5 HIGH
CommServe contained a path traversal issue affecting information disclosure. Software customers upgrade to resolved maintenance release. Update CommServe.
CVE-2026-77103 3 Commvault, Linux, Microsoft 3 Commvault, Linux Kernel, Windows 2026-09-09 N/A 7.5 HIGH
CommServe contained an authentication bypass issue affecting access authorization and information disclosure. Software customers upgrade to resolved maintenance release. Update CommServe.
CVE-2026-77102 3 Commvault, Linux, Microsoft 3 Commvault, Linux Kernel, Windows 2026-09-09 N/A 7.5 HIGH
CommServe contained a heap-based buffer overflow issue affecting service availability. Software customers upgrade to resolved maintenance release. Update CommServe.
CVE-2026-77101 3 Commvault, Linux, Microsoft 3 Commvault, Linux Kernel, Windows 2026-09-09 N/A 7.5 HIGH
CommServe contained a stack-based buffer overflow issue affecting service availability. Software customers upgrade to resolved maintenance release. Update CommServe.
CVE-2026-77105 3 Commvault, Linux, Microsoft 3 Commvault, Linux Kernel, Windows 2026-09-09 N/A 8.8 HIGH
CommServe contained a cryptographic signature verification issue affecting privilege management. Software customers upgrade to resolved maintenance release. Update CommServe and Web Server.
CVE-2026-17622 4 Apple, Langflow, Linux and 1 more 4 Macos, Langflow, Linux Kernel and 1 more 2026-09-09 N/A 6.5 MEDIUM
IBM Langflow OSS 1.0.0 through 1.10.2 could allow a remote authenticated attacker to obtain sensitive information due to improper limitation of a pathname to a restricted directory.
CVE-2026-17627 4 Apple, Langflow, Linux and 1 more 4 Macos, Langflow, Linux Kernel and 1 more 2026-09-09 N/A 4.9 MEDIUM
IBM Langflow OSS 1.0.0 through 1.10.2 could allow a remote authenticated attacker to obtain sensitive information and inject messages into workflow history due to improper authorization.
CVE-2026-17631 4 Apple, Langflow, Linux and 1 more 4 Macos, Langflow, Linux Kernel and 1 more 2026-09-09 N/A 5.0 MEDIUM
IBM Langflow OSS 1.0.0 through 1.10.2 could allow a remote authenticated attacker to obtain sensitive information due to a server-side request forgery (SSRF) vulnerability.