Total
396416 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2026-87474 | 1 Google | 1 Chrome | 2026-09-10 | N/A | 9.6 CRITICAL |
| Use after free in Payments in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High) | |||||
| CVE-2026-87470 | 2 Apple, Google | 2 Macos, Chrome | 2026-09-10 | N/A | 9.6 CRITICAL |
| Improper quantity validation in Tint in Google Chrome on on Mac prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium) | |||||
| CVE-2026-87467 | 2 Google, Microsoft | 2 Chrome, Windows | 2026-09-10 | N/A | 8.1 HIGH |
| Race condition in Updater in Google Chrome on on Windows prior to 153.0.8010.36 allowed a local attacker to potentially execute arbitrary code outside the sandbox via a local program. (Chromium security severity: High) | |||||
| CVE-2026-87460 | 1 Google | 1 Chrome | 2026-09-10 | N/A | 8.8 HIGH |
| Use after free in Platform in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High) | |||||
| CVE-2026-87457 | 2 Google, Microsoft | 2 Chrome, Windows | 2026-09-10 | N/A | 8.1 HIGH |
| Race condition in Updater in Google Chrome on on Windows prior to 153.0.8010.36 allowed a local attacker to execute arbitrary code outside the sandbox via a local program. (Chromium security severity: Medium) | |||||
| CVE-2026-87455 | 1 Google | 1 Chrome | 2026-09-10 | N/A | 9.6 CRITICAL |
| Use after free in Aura in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium) | |||||
| CVE-2026-87448 | 1 Google | 1 Chrome | 2026-09-10 | N/A | 9.6 CRITICAL |
| Use after free in DevTools in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Low) | |||||
| CVE-2026-87444 | 1 Google | 1 Chrome | 2026-09-10 | N/A | 8.8 HIGH |
| Memory corruption in Codecs in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High) | |||||
| CVE-2026-87440 | 1 Google | 1 Chrome | 2026-09-10 | N/A | 8.8 HIGH |
| Out of bounds read in Media in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High) | |||||
| CVE-2026-87438 | 1 Google | 2 Android, Chrome | 2026-09-10 | N/A | 9.6 CRITICAL |
| Out of bounds write in WebGL in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical) | |||||
| CVE-2026-87430 | 1 Google | 1 Chrome | 2026-09-10 | N/A | 8.8 HIGH |
| Buffer overflow in WebRTC in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Low) | |||||
| CVE-2026-85384 | 2026-09-10 | N/A | N/A | ||
| A stack-based buffer overflow vulnerability exists in the httpd component of RE210 AC750 due to improper bounds checking in the splitString function when processing an uploaded configuration file. An authenticated attacker on the local network can upload a crafted configuration file to trigger the overflow, leading to remote code execution. Successful exploitation may allow unauthorized access to sensitive information, modification of device configuration and network behavior, or disruption of device availability. | |||||
| CVE-2026-85103 | 2026-09-10 | N/A | 9.8 CRITICAL | ||
| A heap-based buffer overflow in VPN certificate ASN.1 decoding may allow an unauthenticated remote attacker to execute arbitrary code on Check Point Quantum Security Management and Quantum Security Gateway systems. | |||||
| CVE-2026-84393 | 2026-09-10 | N/A | 8.1 HIGH | ||
| A improper validation of certificate with host mismatch vulnerability in Fortinet FortiOS 7.6.1 through 7.6.6, FortiProxy 7.6.2 through 7.6.6 may allow attacker to information disclosure via <insert attack vector here> | |||||
| CVE-2026-84389 | 2026-09-10 | N/A | 3.1 LOW | ||
| A url redirection to untrusted site ('open redirect') vulnerability in Fortinet FortiSIEM 7.5.0 through 7.5.1, FortiSIEM 7.4.1 through 7.4.2 may allow attacker to execute unauthorized code or commands via <insert attack vector here> | |||||
| CVE-2026-84385 | 2026-09-10 | N/A | 5.4 MEDIUM | ||
| A improper access control vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.6, FortiSOAR PaaS 7.5.0 through 7.5.3, FortiSOAR PaaS 7.4 all versions, FortiSOAR PaaS 7.3 all versions, FortiSOAR on-premise 7.6.0 through 7.6.6, FortiSOAR on-premise 7.5.0 through 7.5.3, FortiSOAR on-premise 7.4 all versions, FortiSOAR on-premise 7.3 all versions may allow attacker to escalation of privilege via <insert attack vector here> | |||||
| CVE-2026-77505 | 2026-09-10 | N/A | 8.1 HIGH | ||
| Use after free in DNS Server allows an unauthorized attacker to execute code over a network. | |||||
| CVE-2026-69290 | 2026-09-10 | N/A | 7.8 HIGH | ||
| Stack-based buffer overflow in Windows Storage Spaces Controller allows an authorized attacker to elevate privileges locally. | |||||
| CVE-2026-68877 | 2026-09-10 | N/A | 7.8 HIGH | ||
| Heap-based buffer overflow in Windows Storage Spaces Controller allows an authorized attacker to execute code locally. | |||||
| CVE-2026-67401 | 2026-09-10 | N/A | 9.9 CRITICAL | ||
| A vulnerability in cPanel allows a mail-enabled account to achieve remote code execution as root through SQLi in EmailTrack component | |||||
