Total
397891 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2026-79016 | 1 Google | 1 Chrome | 2026-08-31 | N/A | 4.3 MEDIUM |
| Observable discrepancy in SVG in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (Chromium security severity: Medium) | |||||
| CVE-2026-79077 | 1 Google | 1 Chrome | 2026-08-31 | N/A | 4.3 MEDIUM |
| Incorrect authorization in WebProtect in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Low) | |||||
| CVE-2026-76927 | 1 Wireshark | 1 Wireshark | 2026-08-31 | N/A | 4.7 MEDIUM |
| H.245 protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service | |||||
| CVE-2026-79082 | 1 Google | 1 Chrome | 2026-08-31 | N/A | 4.3 MEDIUM |
| Incorrect authorization in Transactions Platform in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: High) | |||||
| CVE-2026-79087 | 1 Google | 1 Chrome | 2026-08-31 | N/A | 4.3 MEDIUM |
| Injection in Chrome Tabs in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium) | |||||
| CVE-2026-79089 | 1 Google | 2 Android, Chrome | 2026-08-31 | N/A | 5.3 MEDIUM |
| Race condition in Transactions Platform in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Low) | |||||
| CVE-2026-79094 | 1 Google | 1 Chrome | 2026-08-31 | N/A | 6.5 MEDIUM |
| Race condition in Workers in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium) | |||||
| CVE-2026-79099 | 1 Google | 1 Chrome | 2026-08-31 | N/A | 6.5 MEDIUM |
| Missing authorization in Network in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium) | |||||
| CVE-2026-79120 | 1 Google | 1 Chrome | 2026-08-31 | N/A | 6.5 MEDIUM |
| Uninitialized resource in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially obtain cross-origin data via a crafted HTML page. (Chromium security severity: Medium) | |||||
| CVE-2026-79146 | 1 Google | 2 Android, Chrome | 2026-08-31 | N/A | 5.5 MEDIUM |
| Information leak in CustomTabs in Google Chrome on on Android prior to 152.0.7977.65 allowed a local attacker to obtain cross-origin data via a co-installed app. (Chromium security severity: Medium) | |||||
| CVE-2026-79199 | 1 Google | 1 Chrome | 2026-08-31 | N/A | 4.3 MEDIUM |
| Incorrect authorization in Network in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium) | |||||
| CVE-2026-79206 | 1 Google | 1 Chrome | 2026-08-31 | N/A | 6.5 MEDIUM |
| Out of bounds read in FileSystem in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: Low) | |||||
| CVE-2026-76928 | 1 Wireshark | 1 Wireshark | 2026-08-31 | N/A | 7.5 HIGH |
| X.509IF protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service | |||||
| CVE-2026-76929 | 1 Wireshark | 1 Wireshark | 2026-08-31 | N/A | 4.7 MEDIUM |
| Pcapng file parser crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service | |||||
| CVE-2026-10053 | 1 Gitlab | 1 Gitlab | 2026-08-31 | N/A | 8.5 HIGH |
| GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.8 before 19.0.6, 19.1 before 19.1.4, and 19.2 before 19.2.2 that under certain conditions could have allowed an authenticated user to achieve remote code execution due to a path traversal vulnerability in the package registry. | |||||
| CVE-2026-20885 | 1 Intel | 153 Tdx Module, Xeon 4108, Xeon 6315p and 150 more | 2026-08-31 | N/A | 7.2 HIGH |
| Improper authentication in the Intel(R) TDX module for some Intel(R) platforms within Ring 0: Trust Domain may allow an information disclosure and escalation of privilege. System software adversary with a privileged user combined with a high complexity attack may enable escalation of privilege. This result may potentially occur via local access when attack requirements are present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (high), integrity (high) and availability (none) of the vulnerable system, resulting in subsequent system confidentiality (low), integrity (low) and availability (none) impacts. | |||||
| CVE-2026-20783 | 1 Intel | 1 Neural Processing Unit Driver | 2026-08-31 | N/A | 6.1 MEDIUM |
| Improper conditions check in the firmware for the Intel(R) NPU Driver for all versions within Ring 1: Device Drivers may allow a denial of service. Unprivileged software adversary with an authenticated user combined with a low complexity attack may enable denial of service. This result may potentially occur via local access when attack requirements are not present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (none), integrity (low) and availability (high) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts. | |||||
| CVE-2026-43657 | 1 Apple | 1 Iphone Os | 2026-08-31 | N/A | 3.3 LOW |
| A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 26.5 and iPadOS 26.5. A malicious app may be able to enumerate installed apps. | |||||
| CVE-2026-15143 | 2026-08-31 | N/A | 9.3 CRITICAL | ||
| A flaw was found in the file_type content detector of guardrails-detectors. This vulnerability allows a remote attacker to supply an arbitrary XML Schema Definition (XSD) string, which is processed without proper restrictions. This can lead to server-side requests to arbitrary URLs or local file reads, potentially resulting in sensitive information disclosure, such as cloud provider credentials or access to internal network services. | |||||
| CVE-2025-53811 | 2026-08-31 | N/A | N/A | ||
| The configuration of Mosh-Pro on macOS, specifically the "RunAsNode" fuse enabled, allows a local attacker with unprivileged access to execute arbitrary code that inherits Mosh-Pro TCC (Transparency, Consent, and Control) permissions. Acquired resource access is limited to previously granted permissions by the user. Accessing other resources beyond previously granted TCC permissions will prompt the user for approval in the name of Mosh-Pro, potentially disguising attacker's malicious intent. This issue was fixed in 1.3.7 version of Mosh-Pro. | |||||
