Total
396388 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2024-14047 | 1 Elastic | 1 Winlogbeat | 2026-09-10 | N/A | 7.2 HIGH |
| A local vulnerability in the Winlogbeat Windows installer caused runtime files to be placed in a directory writable by unprivileged users. A low-privileged attacker with existing access to the system could pre-position malicious filesystem links, causing a subsequent elevated Winlogbeat operation to write to or delete arbitrary files. Successful exploitation could result in a denial of service. | |||||
| CVE-2026-87497 | 1 Google | 1 Chrome | 2026-09-10 | N/A | 4.3 MEDIUM |
| Uninitialized resource in Codecs in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to read memory inside the sandbox via a crafted HTML page. (Chromium security severity: Medium) | |||||
| CVE-2026-87496 | 1 Google | 1 Chrome | 2026-09-10 | N/A | 5.4 MEDIUM |
| UI misrepresentation in Browser in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium) | |||||
| CVE-2026-87441 | 1 Google | 1 Chrome | 2026-09-10 | N/A | 6.5 MEDIUM |
| Missing authorization in Downloads in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass system access restrictions via a crafted Chrome extension. (Chromium security severity: Medium) | |||||
| CVE-2026-86430 | 1 Thephpleague | 1 Commonmark | 2026-09-10 | N/A | 7.5 HIGH |
| league/commonmark versions before 2.9.1 contain multiple denial of service vulnerabilities in fenced code block detection, reference link label lookup, and emphasis delimiter processing that perform super-linear work on crafted input. Attackers can submit specially crafted Markdown with long backtick runs, nested brackets, or delimiter sequences to consume disproportionate CPU time and prevent legitimate requests from completing. | |||||
| CVE-2026-87442 | 1 Google | 1 Chrome | 2026-09-10 | N/A | 3.1 LOW |
| Confused deputy in Prerender in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to potentially bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium) | |||||
| CVE-2026-87445 | 1 Google | 1 Chrome | 2026-09-10 | N/A | 5.4 MEDIUM |
| UI misrepresentation in Session in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium) | |||||
| CVE-2026-75003 | 1 Roundcube | 1 Webmail | 2026-09-10 | N/A | 5.8 MEDIUM |
| In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, an unclosed url() in a FuncIRI attribute of an SVG image could evade the remote image blocking, which may lead to information disclosure or privilege escalation. | |||||
| CVE-2026-87446 | 1 Google | 1 Chrome | 2026-09-10 | N/A | 6.5 MEDIUM |
| Incomplete cleanup in Extensions in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted Chrome extension. (Chromium security severity: Medium) | |||||
| CVE-2026-87447 | 1 Google | 1 Chrome | 2026-09-10 | N/A | 6.5 MEDIUM |
| Incorrect authorization in Network in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass web origin policy via a crafted Chrome extension. (Chromium security severity: High) | |||||
| CVE-2026-9034 | 2026-09-10 | N/A | 7.8 HIGH | ||
| Use After Free vulnerability in Arm Ltd Bifrost GPU Userspace Driver, Arm Ltd Valhall GPU Userspace Driver, Arm Ltd Arm 5th Gen GPU Architecture Userspace Driver allows a non-privileged user process to perform valid GPU processing operations, including via WebGL or WebGPU, to access already freed memory. This issue affects Bifrost GPU Userspace Driver: from r42p0 through r49p5, from r50p0 through r51p0, from r54p1 through r54p3; Valhall GPU Userspace Driver: from r42p0 through r49p5, from r50p0 through r54p3, r55p0; Arm 5th Gen GPU Architecture Userspace Driver: from r42p0 through r49p5, from r50p0 through r54p3, r55p0. | |||||
| CVE-2026-87645 | 1 Google | 1 Chrome | 2026-09-10 | N/A | 5.4 MEDIUM |
| Improper state validation in Safebrowsing in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium) | |||||
| CVE-2026-87560 | 1 Google | 1 Chrome | 2026-09-10 | N/A | 4.3 MEDIUM |
| Missing authorization in Browser in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium) | |||||
| CVE-2026-87556 | 1 Google | 1 Chrome | 2026-09-10 | N/A | 4.3 MEDIUM |
| Missing authorization in Browser in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium) | |||||
| CVE-2026-87534 | 1 Google | 2 Android, Chrome | 2026-09-10 | N/A | 9.8 CRITICAL |
| Missing authorization in WebView in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass system access restrictions via crafted network traffic. (Chromium security severity: Medium) | |||||
| CVE-2026-86840 | 2026-09-10 | N/A | 9.1 CRITICAL | ||
| The `vtoken-minting` and `slpx` pallets in Bifrost contain an improper authorization vulnerability in channel commission attribution. A signed account can supply an arbitrary registered `channel_id` when minting tokens without verifying that the caller is authorized to mint on behalf of that channel. This allows an attacker to inflate a channel's recorded mint volume and cause protocol commission payments to be disproportionately distributed to that channel during commission settlement. | |||||
| CVE-2026-86152 | 2026-09-10 | 10.0 HIGH | 10.0 CRITICAL | ||
| A flaw has been found in Tenda CP3 27.5.57.101. The impacted element is the function CAutoAddWifi::ThreadProc of the file Functions/AutoAddWifi.cpp of the component Kylin. Executing a manipulation can lead to os command injection. The attack may be launched remotely. | |||||
| CVE-2026-85704 | 2026-09-10 | 2.6 LOW | 3.7 LOW | ||
| A security flaw has been discovered in ramon-victor freegpt-webui up to 098db3dfeb41555c2ca9269df0f13e10ec1c35dc. This issue affects the function getJailbreak of the file server/config.py of the component Jailbreak Mode. The manipulation results in race condition. It is possible to launch the attack remotely. The attack requires a high level of complexity. The exploitability is assessed as difficult. The exploit has been released to the public and may be used for attacks. This product takes the approach of rolling releases to provide continious delivery. Therefore, version details for affected and updated releases are not available. This vulnerability only affects products that are no longer supported by the maintainer. | |||||
| CVE-2026-85639 | 2026-09-10 | 5.1 MEDIUM | 5.6 MEDIUM | ||
| A security vulnerability has been detected in jofpin trape 2.0. This vulnerability affects unknown code of the file core/user.py of the component Telemetry Endpoint. Such manipulation of the argument vId leads to race condition. The attack can be executed remotely. Attacks of this nature are highly complex. It is stated that the exploitability is difficult. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through an issue report but has not responded yet. | |||||
| CVE-2026-83992 | 1 Microsoft | 13 Windows 10 1607, Windows 10 1809, Windows 10 21h2 and 10 more | 2026-09-10 | N/A | 8.8 HIGH |
| Heap-based buffer overflow in Windows Imaging Component allows an unauthorized attacker to execute code over a network. | |||||
