Total
396528 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2026-87495 | 1 Google | 1 Chrome | 2026-09-09 | N/A | 4.3 MEDIUM |
| Information leak in Scroll in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium) | |||||
| CVE-2026-87498 | 1 Google | 1 Chrome | 2026-09-09 | N/A | 3.1 LOW |
| Missing authorization in WebUI in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: High) | |||||
| CVE-2026-87508 | 1 Google | 1 Chrome | 2026-09-09 | N/A | 4.3 MEDIUM |
| Incorrect authorization in Loader in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium) | |||||
| CVE-2026-87516 | 1 Google | 1 Chrome | 2026-09-09 | N/A | 4.3 MEDIUM |
| Observable discrepancy in Navigation in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium) | |||||
| CVE-2026-87517 | 2 Apple, Google | 2 Iphone Os, Chrome | 2026-09-09 | N/A | 3.1 LOW |
| Race condition in Mobile in Google Chrome on on iOS prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass web origin policy via a crafted HTML page. (Chromium security severity: High) | |||||
| CVE-2026-87531 | 1 Google | 1 Chrome | 2026-09-09 | N/A | 3.1 LOW |
| Information leak in CORS in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to obtain cross-origin data via a crafted HTML page. (Chromium security severity: Medium) | |||||
| CVE-2026-87573 | 1 Google | 1 Chrome | 2026-09-09 | N/A | 4.3 MEDIUM |
| Improper input validation in Network in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium) | |||||
| CVE-2026-87574 | 1 Google | 1 Chrome | 2026-09-09 | N/A | 4.3 MEDIUM |
| Information leak in ServiceWorker in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (Chromium security severity: Medium) | |||||
| CVE-2026-85089 | 1 Freerdp | 1 Freerdp | 2026-09-09 | N/A | 6.5 MEDIUM |
| FreeRDP versions 3.0.0 through 3.30.0 (before 3.31.0) transmit uninitialized heap memory in Save Session Info PDU reserved padding fields. Three PDU writers in libfreerdp/core/info.c (rdp_write_logon_info_v2, rdp_write_logon_info_plain, and rdp_write_logon_info_ex) use Stream_Seek instead of Stream_Zero for reserved pad bytes (up to 576 bytes), leaving previously freed heap contents in the outgoing PDU. Because the send buffer is allocated with malloc (not zeroed), stale heap data — which may include cleartext credentials from prior sessions — can be sent to the receiving peer. FreeRDP-based servers using rdpUpdate::SaveSessionInfo and freerdp-proxy (which forwards these PDUs) are affected, allowing disclosure of server/proxy process memory to a downstream client. | |||||
| CVE-2026-87642 | 1 Google | 1 Chrome | 2026-09-09 | N/A | 4.3 MEDIUM |
| Uninitialized resource in WebGL in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium) | |||||
| CVE-2026-87652 | 1 Google | 1 Chrome | 2026-09-09 | N/A | 3.1 LOW |
| Incorrect authorization in PushAPI in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium) | |||||
| CVE-2026-87658 | 1 Google | 1 Chrome | 2026-09-09 | N/A | 4.3 MEDIUM |
| Information leak in Extensions in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to obtain cross-origin data via a crafted Chrome extension. (Chromium security severity: Medium) | |||||
| CVE-2026-80081 | 1 Microsoft | 1 365 Apps | 2026-09-09 | N/A | 8.8 HIGH |
| Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code over a network. | |||||
| CVE-2026-78519 | 1 Microsoft | 5 365 Apps, Office 2019, Office 2021 and 2 more | 2026-09-09 | N/A | 8.8 HIGH |
| Use of uninitialized resource in Microsoft Office Outlook allows an unauthorized attacker to execute code over a network. | |||||
| CVE-2026-80171 | 1 Dell | 1 Secure Connect Gateway | 2026-09-09 | N/A | 4.7 MEDIUM |
| Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Insufficient Entropy in PRNG vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to elevation of privileges. | |||||
| CVE-2026-80073 | 1 Microsoft | 5 365 Apps, Office 2019, Office 2021 and 2 more | 2026-09-09 | N/A | 6.5 MEDIUM |
| Out-of-bounds read in Microsoft Office Outlook allows an unauthorized attacker to disclose information over a network. | |||||
| CVE-2026-81168 | 1 Captcha Protected Page Project | 1 Captcha Protected Page | 2026-09-09 | N/A | 3.7 LOW |
| Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal CAPTCHA Protected Page allows Functionality Bypass. This issue affects CAPTCHA Protected Page versions: from 0.0.0 to 1.0.2. | |||||
| CVE-2026-81167 | 1 Address Suggestion Project | 1 Address Suggestion | 2026-09-09 | N/A | 4.8 MEDIUM |
| Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Address Suggestion allows Cross-Site Scripting (XSS). This issue affects Address Suggestion versions: from 0.0.0 to 1.0.25. | |||||
| CVE-2026-81162 | 1 Dxpr Builder Project | 1 Dxpr Builder | 2026-09-09 | N/A | 5.3 MEDIUM |
| Insertion of Sensitive Information Into Sent Data vulnerability in Drupal DXPR Builder: The Best Editing (AI) Experience for Drupal allows Forceful Browsing. This issue affects DXPR Builder: The Best Editing (AI) Experience for Drupal versions: from 0.0.0 to 2.8.1. | |||||
| CVE-2026-69857 | 1 Microsoft | 1 Azure Cosmos Db | 2026-09-09 | N/A | 8.5 HIGH |
| Authorization bypass through user-controlled key in Azure Cosmos DB allows an authorized attacker to perform spoofing over a network. | |||||
