Total
396511 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2026-87449 | 1 Google | 1 Chrome | 2026-09-09 | N/A | 4.3 MEDIUM |
| Cross-site request forgery in DeviceBoundSessionCredentials in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium) | |||||
| CVE-2026-87432 | 1 Google | 1 Chrome | 2026-09-09 | N/A | 4.2 MEDIUM |
| Incorrect authorization in Navigation in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium) | |||||
| CVE-2026-87653 | 2 Google, Microsoft | 2 Chrome, Windows | 2026-09-09 | N/A | 5.4 MEDIUM |
| UI misrepresentation in FullScreen in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker to spoof UI elements via a crafted HTML page. (Chromium security severity: Low) | |||||
| CVE-2026-87647 | 1 Google | 1 Chrome | 2026-09-09 | N/A | 3.4 LOW |
| Uninitialized resource in GPU in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: High) | |||||
| CVE-2026-87576 | 1 Google | 2 Android, Chrome | 2026-09-09 | N/A | 3.4 LOW |
| Uninitialized resource in GPU in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: Medium) | |||||
| CVE-2026-87635 | 1 Google | 1 Chrome | 2026-09-09 | N/A | 5.4 MEDIUM |
| UI misrepresentation in Payments in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium) | |||||
| CVE-2026-84001 | 1 Microsoft | 13 Windows 10 1607, Windows 10 1809, Windows 10 21h2 and 10 more | 2026-09-09 | N/A | 7.5 HIGH |
| Out-of-bounds read in Windows Key Distribution Center allows an unauthorized attacker to deny service over a network. | |||||
| CVE-2026-87655 | 1 Google | 1 Chrome | 2026-09-09 | N/A | 5.4 MEDIUM |
| Clickjacking in Downloads in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium) | |||||
| CVE-2026-87657 | 1 Google | 1 Chrome | 2026-09-09 | N/A | 3.1 LOW |
| Use after free in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to read memory inside the sandbox via a crafted HTML page. (Chromium security severity: Medium) | |||||
| CVE-2026-83989 | 1 Microsoft | 13 Windows 10 1607, Windows 10 1809, Windows 10 21h2 and 10 more | 2026-09-09 | N/A | 7.5 HIGH |
| Out-of-bounds read in Windows Services for NFS ONCRPC XDR Driver allows an unauthorized attacker to deny service over a network. | |||||
| CVE-2026-10031 | 2026-09-09 | N/A | 4.2 MEDIUM | ||
| SFTPGo prior to 2.7.4 contains a permission bypass vulnerability that allows authenticated users to circumvent per-directory access controls by creating symbolic links in a permitted directory that point to files in directories where download, upload, or overwrite permissions are denied. Attackers can exploit the create_symlinks permission combined with read and write access in one directory to read or modify files in restricted directories, as operations are authorized against the link's directory permissions rather than the dereferenced target's directory permissions. | |||||
| CVE-2026-66420 | 2026-09-09 | N/A | 8.8 HIGH | ||
| MeshCentral 1.1.21 contains a cross-site WebSocket hijacking protection bypass vulnerability that allows unauthenticated remote attackers to hijack authenticated administrator sessions by exploiting an unconditional early return in the CheckWebServerOriginName() function within webserver.js when self-signed certificates are in use. Attackers can open cross-origin WebSocket connections to any of the twelve WebSocket endpoints, send crafted action commands to exfiltrate the server sessionKey used to sign session cookies, forge session tokens as arbitrary users, and gain full remote control of all managed devices governed by the MeshCentral instance. | |||||
| CVE-2026-67308 | 2026-09-09 | N/A | N/A | ||
| Wazuh workflows before 44bf114 contain a shell injection vulnerability in GitHub Actions that allows attackers to execute arbitrary commands by submitting pull requests with crafted VERSION.json files. Attackers can inject shell metacharacters into environment variables that are directly interpolated into run steps, enabling command execution and exfiltration of secrets including GITHUB_TOKEN and AWS credentials on self-hosted runners. | |||||
| CVE-2026-87550 | 1 Google | 1 Chrome | 2026-09-09 | N/A | 4.3 MEDIUM |
| Improper encoding or escaping of output in CSS in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium) | |||||
| CVE-2026-87545 | 2 Apple, Google | 2 Iphone Os, Chrome | 2026-09-09 | N/A | 6.5 MEDIUM |
| Information leak in Mobile in Google Chrome on on iOS prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to leak sensitive information via a crafted HTML page. (Chromium security severity: Low) | |||||
| CVE-2026-87555 | 1 Google | 2 Android, Chrome | 2026-09-09 | N/A | 4.7 MEDIUM |
| Uninitialized resource in GPU in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: Medium) | |||||
| CVE-2026-87559 | 1 Google | 1 Chrome | 2026-09-09 | N/A | 4.2 MEDIUM |
| UI misrepresentation in UI in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium) | |||||
| CVE-2026-87598 | 1 Google | 1 Chrome | 2026-09-09 | N/A | 4.3 MEDIUM |
| Incorrect authorization in ServiceWorker in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass web origin policy via a crafted HTML page. (Chromium security severity: Low) | |||||
| CVE-2026-87602 | 2 Google, Microsoft | 2 Chrome, Windows | 2026-09-09 | N/A | 4.7 MEDIUM |
| Out of bounds read in ANGLE in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker to potentially read memory outside the sandbox via a crafted HTML page. (Chromium security severity: Low) | |||||
| CVE-2026-87614 | 1 Google | 1 Chrome | 2026-09-09 | N/A | 3.1 LOW |
| Incorrect authorization in ServiceWorker in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Low) | |||||
