Vulnerabilities (CVE)

Total 396528 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2026-87495 1 Google 1 Chrome 2026-09-09 N/A 4.3 MEDIUM
Information leak in Scroll in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-87498 1 Google 1 Chrome 2026-09-09 N/A 3.1 LOW
Missing authorization in WebUI in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: High)
CVE-2026-87508 1 Google 1 Chrome 2026-09-09 N/A 4.3 MEDIUM
Incorrect authorization in Loader in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-87516 1 Google 1 Chrome 2026-09-09 N/A 4.3 MEDIUM
Observable discrepancy in Navigation in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-87517 2 Apple, Google 2 Iphone Os, Chrome 2026-09-09 N/A 3.1 LOW
Race condition in Mobile in Google Chrome on on iOS prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass web origin policy via a crafted HTML page. (Chromium security severity: High)
CVE-2026-87531 1 Google 1 Chrome 2026-09-09 N/A 3.1 LOW
Information leak in CORS in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to obtain cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-87573 1 Google 1 Chrome 2026-09-09 N/A 4.3 MEDIUM
Improper input validation in Network in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-87574 1 Google 1 Chrome 2026-09-09 N/A 4.3 MEDIUM
Information leak in ServiceWorker in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-85089 1 Freerdp 1 Freerdp 2026-09-09 N/A 6.5 MEDIUM
FreeRDP versions 3.0.0 through 3.30.0 (before 3.31.0) transmit uninitialized heap memory in Save Session Info PDU reserved padding fields. Three PDU writers in libfreerdp/core/info.c (rdp_write_logon_info_v2, rdp_write_logon_info_plain, and rdp_write_logon_info_ex) use Stream_Seek instead of Stream_Zero for reserved pad bytes (up to 576 bytes), leaving previously freed heap contents in the outgoing PDU. Because the send buffer is allocated with malloc (not zeroed), stale heap data — which may include cleartext credentials from prior sessions — can be sent to the receiving peer. FreeRDP-based servers using rdpUpdate::SaveSessionInfo and freerdp-proxy (which forwards these PDUs) are affected, allowing disclosure of server/proxy process memory to a downstream client.
CVE-2026-87642 1 Google 1 Chrome 2026-09-09 N/A 4.3 MEDIUM
Uninitialized resource in WebGL in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-87652 1 Google 1 Chrome 2026-09-09 N/A 3.1 LOW
Incorrect authorization in PushAPI in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-87658 1 Google 1 Chrome 2026-09-09 N/A 4.3 MEDIUM
Information leak in Extensions in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to obtain cross-origin data via a crafted Chrome extension. (Chromium security severity: Medium)
CVE-2026-80081 1 Microsoft 1 365 Apps 2026-09-09 N/A 8.8 HIGH
Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code over a network.
CVE-2026-78519 1 Microsoft 5 365 Apps, Office 2019, Office 2021 and 2 more 2026-09-09 N/A 8.8 HIGH
Use of uninitialized resource in Microsoft Office Outlook allows an unauthorized attacker to execute code over a network.
CVE-2026-80171 1 Dell 1 Secure Connect Gateway 2026-09-09 N/A 4.7 MEDIUM
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Insufficient Entropy in PRNG vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to elevation of privileges.
CVE-2026-80073 1 Microsoft 5 365 Apps, Office 2019, Office 2021 and 2 more 2026-09-09 N/A 6.5 MEDIUM
Out-of-bounds read in Microsoft Office Outlook allows an unauthorized attacker to disclose information over a network.
CVE-2026-81168 1 Captcha Protected Page Project 1 Captcha Protected Page 2026-09-09 N/A 3.7 LOW
Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal CAPTCHA Protected Page allows Functionality Bypass. This issue affects CAPTCHA Protected Page versions: from 0.0.0 to 1.0.2.
CVE-2026-81167 1 Address Suggestion Project 1 Address Suggestion 2026-09-09 N/A 4.8 MEDIUM
Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Address Suggestion allows Cross-Site Scripting (XSS). This issue affects Address Suggestion versions: from 0.0.0 to 1.0.25.
CVE-2026-81162 1 Dxpr Builder Project 1 Dxpr Builder 2026-09-09 N/A 5.3 MEDIUM
Insertion of Sensitive Information Into Sent Data vulnerability in Drupal DXPR Builder: The Best Editing (AI) Experience for Drupal allows Forceful Browsing. This issue affects DXPR Builder: The Best Editing (AI) Experience for Drupal versions: from 0.0.0 to 2.8.1.
CVE-2026-69857 1 Microsoft 1 Azure Cosmos Db 2026-09-09 N/A 8.5 HIGH
Authorization bypass through user-controlled key in Azure Cosmos DB allows an authorized attacker to perform spoofing over a network.