Vulnerabilities (CVE)

Total 396958 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2026-84324 1 Google 1 Chrome 2026-09-03 N/A 9.0 CRITICAL
Use after free in Proxy in Google Chrome prior to 152.0.7977.75 allowed a remote attacker to execute arbitrary code outside the sandbox via crafted network traffic. (Chromium security severity: High)
CVE-2026-84325 1 Google 1 Chrome 2026-09-03 N/A 9.8 CRITICAL
Improper input validation in DataTransfer in Google Chrome prior to 152.0.7977.75 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a co-installed app. (Chromium security severity: High)
CVE-2026-84326 1 Google 1 Chrome 2026-09-03 N/A 8.8 HIGH
Uninitialized resource in V8 in Google Chrome prior to 152.0.7977.75 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
CVE-2026-84328 1 Google 1 Chrome 2026-09-03 N/A 3.1 LOW
Missing authorization in FileSystem in Google Chrome prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-84329 2 Google, Microsoft 2 Chrome, Windows 2026-09-03 N/A 5.3 MEDIUM
Confused deputy in CredentialProvider in Google Chrome on on Windows prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process to leak sensitive information via a crafted HTML page. (Chromium security severity: Low)
CVE-2026-45204 2026-09-03 N/A 5.5 MEDIUM
Software installed and run as a non-privileged user may conduct improper GPU system calls to trigger OOB access and kernel null pointer dereference in an error path. Null pointer dereference occurs in an error path of a function running in kernel thread of execution leading to kernel exceptions, platform instability and denial of service.
CVE-2026-45202 2026-09-03 N/A 5.5 MEDIUM
Software installed and run as a non-privileged user may conduct GPU system calls which cause GPU memory leaks and possible kernel heap corruption. Scenario caused by memory free paths not maintaining state data of upgraded higher order allocations. This could cause memory leak or double free event.
CVE-2026-45201 2026-09-03 N/A 7.8 HIGH
Software installed and run as a non-privileged user may conduct improper GPU system calls to pass invalid log2 page size when allocating physical pages leading to OOB read and/or write due to improper validation of the said value. Such crafted log2 page size could lead to 4K pages being treated as higher order pages and allowing read and/or write access to the memory beyond 4K threshold.
CVE-2026-45198 2026-09-03 N/A 7.8 HIGH
Kernel software from a non-secure operating system on a platform with Trusted Execution Environment support, may cause GPU Firmware to boot up using data from non-secure memory. The GPU thread of control (Firmware) uses a pointer from non-secure memory belonging to the Rich Execution Environment (REE) when saving or retrieving internal data between the tightly coupled private memory to main memory. An attacker with control over the REE kernel may modify the pointer value, corrupting the data used by the GPU Firmware.
CVE-2026-49746 2026-09-03 N/A 7.1 HIGH
Software installed and run as a non-privileged user may conduct improper GPU system calls to cause OOB read kernel memory access and in certain cases cause GPU UAF of arbitrary pages. Incorrect validation of array index can lead to OOB read and potentially to GPU UAF of arbitrary pages.
CVE-2026-45199 2026-09-03 N/A 7.8 HIGH
Kernel software installed and running inside a Guest VM may post improper commands to the GPU Firmware to trigger a write of data outside the Guest's virtualised GPU memory. Software installed and run under a Guest VM can send commands to the GPU which result in out of bounds memory accesses. These can be used to escalate privileges.
CVE-2026-84331 1 Google 1 Chrome 2026-09-03 N/A 3.1 LOW
Incorrect authorization in Actor in Google Chrome prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Low)
CVE-2026-84332 1 Google 1 Chrome 2026-09-03 N/A 6.5 MEDIUM
Incorrect authorization in SiteSettings in Google Chrome prior to 152.0.7977.75 allowed a remote attacker to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-84334 2 Google, Microsoft 2 Chrome, Windows 2026-09-03 N/A 8.1 HIGH
Incorrect authorization in Chromoting in Google Chrome on on Windows prior to 152.0.7977.75 allowed a local attacker to execute arbitrary code outside the sandbox via a local program. (Chromium security severity: Medium)
CVE-2026-84335 1 Google 1 Chrome 2026-09-03 N/A 8.3 HIGH
Incorrect authorization in TabStrip in Google Chrome prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-64631 2026-09-03 N/A N/A
A vulnerability allowing a low-privileged user to inject SQL and extract database contents.
CVE-2026-64630 2026-09-03 N/A N/A
A vulnerability allowing a low-privileged user to retrieve report data outside the scope of a shared report link.
CVE-2026-58075 2026-09-03 N/A N/A
A vulnerability allowing an unauthenticated attacker to read arbitrary files from the host, which can be further leveraged toescalate privileges locally.
CVE-2026-64633 2026-09-03 N/A N/A
A vulnerability allowing remote unauthenticated code execution on the agent host.
CVE-2026-58074 2026-09-03 N/A N/A
A vulnerability allowing a high-privileged user to execute arbitrary code on the server.