Total
396958 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2026-84324 | 1 Google | 1 Chrome | 2026-09-03 | N/A | 9.0 CRITICAL |
| Use after free in Proxy in Google Chrome prior to 152.0.7977.75 allowed a remote attacker to execute arbitrary code outside the sandbox via crafted network traffic. (Chromium security severity: High) | |||||
| CVE-2026-84325 | 1 Google | 1 Chrome | 2026-09-03 | N/A | 9.8 CRITICAL |
| Improper input validation in DataTransfer in Google Chrome prior to 152.0.7977.75 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a co-installed app. (Chromium security severity: High) | |||||
| CVE-2026-84326 | 1 Google | 1 Chrome | 2026-09-03 | N/A | 8.8 HIGH |
| Uninitialized resource in V8 in Google Chrome prior to 152.0.7977.75 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High) | |||||
| CVE-2026-84328 | 1 Google | 1 Chrome | 2026-09-03 | N/A | 3.1 LOW |
| Missing authorization in FileSystem in Google Chrome prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium) | |||||
| CVE-2026-84329 | 2 Google, Microsoft | 2 Chrome, Windows | 2026-09-03 | N/A | 5.3 MEDIUM |
| Confused deputy in CredentialProvider in Google Chrome on on Windows prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process to leak sensitive information via a crafted HTML page. (Chromium security severity: Low) | |||||
| CVE-2026-45204 | 2026-09-03 | N/A | 5.5 MEDIUM | ||
| Software installed and run as a non-privileged user may conduct improper GPU system calls to trigger OOB access and kernel null pointer dereference in an error path. Null pointer dereference occurs in an error path of a function running in kernel thread of execution leading to kernel exceptions, platform instability and denial of service. | |||||
| CVE-2026-45202 | 2026-09-03 | N/A | 5.5 MEDIUM | ||
| Software installed and run as a non-privileged user may conduct GPU system calls which cause GPU memory leaks and possible kernel heap corruption. Scenario caused by memory free paths not maintaining state data of upgraded higher order allocations. This could cause memory leak or double free event. | |||||
| CVE-2026-45201 | 2026-09-03 | N/A | 7.8 HIGH | ||
| Software installed and run as a non-privileged user may conduct improper GPU system calls to pass invalid log2 page size when allocating physical pages leading to OOB read and/or write due to improper validation of the said value. Such crafted log2 page size could lead to 4K pages being treated as higher order pages and allowing read and/or write access to the memory beyond 4K threshold. | |||||
| CVE-2026-45198 | 2026-09-03 | N/A | 7.8 HIGH | ||
| Kernel software from a non-secure operating system on a platform with Trusted Execution Environment support, may cause GPU Firmware to boot up using data from non-secure memory. The GPU thread of control (Firmware) uses a pointer from non-secure memory belonging to the Rich Execution Environment (REE) when saving or retrieving internal data between the tightly coupled private memory to main memory. An attacker with control over the REE kernel may modify the pointer value, corrupting the data used by the GPU Firmware. | |||||
| CVE-2026-49746 | 2026-09-03 | N/A | 7.1 HIGH | ||
| Software installed and run as a non-privileged user may conduct improper GPU system calls to cause OOB read kernel memory access and in certain cases cause GPU UAF of arbitrary pages. Incorrect validation of array index can lead to OOB read and potentially to GPU UAF of arbitrary pages. | |||||
| CVE-2026-45199 | 2026-09-03 | N/A | 7.8 HIGH | ||
| Kernel software installed and running inside a Guest VM may post improper commands to the GPU Firmware to trigger a write of data outside the Guest's virtualised GPU memory. Software installed and run under a Guest VM can send commands to the GPU which result in out of bounds memory accesses. These can be used to escalate privileges. | |||||
| CVE-2026-84331 | 1 Google | 1 Chrome | 2026-09-03 | N/A | 3.1 LOW |
| Incorrect authorization in Actor in Google Chrome prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Low) | |||||
| CVE-2026-84332 | 1 Google | 1 Chrome | 2026-09-03 | N/A | 6.5 MEDIUM |
| Incorrect authorization in SiteSettings in Google Chrome prior to 152.0.7977.75 allowed a remote attacker to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium) | |||||
| CVE-2026-84334 | 2 Google, Microsoft | 2 Chrome, Windows | 2026-09-03 | N/A | 8.1 HIGH |
| Incorrect authorization in Chromoting in Google Chrome on on Windows prior to 152.0.7977.75 allowed a local attacker to execute arbitrary code outside the sandbox via a local program. (Chromium security severity: Medium) | |||||
| CVE-2026-84335 | 1 Google | 1 Chrome | 2026-09-03 | N/A | 8.3 HIGH |
| Incorrect authorization in TabStrip in Google Chrome prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium) | |||||
| CVE-2026-64631 | 2026-09-03 | N/A | N/A | ||
| A vulnerability allowing a low-privileged user to inject SQL and extract database contents. | |||||
| CVE-2026-64630 | 2026-09-03 | N/A | N/A | ||
| A vulnerability allowing a low-privileged user to retrieve report data outside the scope of a shared report link. | |||||
| CVE-2026-58075 | 2026-09-03 | N/A | N/A | ||
| A vulnerability allowing an unauthenticated attacker to read arbitrary files from the host, which can be further leveraged toescalate privileges locally. | |||||
| CVE-2026-64633 | 2026-09-03 | N/A | N/A | ||
| A vulnerability allowing remote unauthenticated code execution on the agent host. | |||||
| CVE-2026-58074 | 2026-09-03 | N/A | N/A | ||
| A vulnerability allowing a high-privileged user to execute arbitrary code on the server. | |||||
