Search
2,281 CVEs
CVEs (2,281, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 451–475 of 2,281 (capped at 500)
| CVE ID | Severity | Patch | CVSS | Published ↑ | Description |
|---|---|---|---|---|---|
| CVE-2026-84480 | CRITICAL | 9.8 | 2026-09-01 | WWBN AVideo fails to validate password recovery token expiration in userRecoverPassSave.json.php, allowing attackers to use expired tokens to reset account passwords indefi… | |
| CVE-2026-84481 | NONE | — | 2026-09-01 | WWBN AVideo through 30.0 contains an information disclosure vulnerability in the MobileManager plugin getConfiguration endpoint that returns sensitive configuration data to… | |
| CVE-2026-84482 | HIGH | 8.8 | 2026-09-01 | WWBN AVideo through commit 9c39d8c8 contains a cross-site request forgery vulnerability in the get_domain() and isSameDomain() functions that fail to properly validate refe… | |
| CVE-2026-84483 | MEDIUM | 5.3 | 2026-09-01 | WWBN AVideo through commit 9c39d8c8 contains an incomplete authentication bypass in encryptPass.json.php that allows unauthenticated attackers to compute valid HMAC tokens … | |
| CVE-2026-81928 | HIGH | Patched | 7.5 | 2026-09-02 | Net::DNS versions before 1.57 for Perl allow memory exhaustion via unbounded recursion in sig_data when re-encoding a message with a misplaced TSIG record. sig_data signs … |
| CVE-2026-84323 | MEDIUM | Patched | 5.3 | 2026-09-02 | Missing authorization in FileSystem in Google Chrome prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process and leveraged social engineer… |
| CVE-2026-84324 | CRITICAL | Patched | 9.0 | 2026-09-02 | Use after free in Proxy in Google Chrome prior to 152.0.7977.75 allowed a remote attacker to execute arbitrary code outside the sandbox via crafted network traffic. (Chromi… |
| CVE-2026-84325 | CRITICAL | Patched | 9.8 | 2026-09-02 | Improper input validation in DataTransfer in Google Chrome prior to 152.0.7977.75 allowed a remote attacker leveraging social engineering to bypass system access restrictio… |
| CVE-2026-84326 | HIGH | Patched | 8.8 | 2026-09-02 | Uninitialized resource in V8 in Google Chrome prior to 152.0.7977.75 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromi… |
| CVE-2026-84327 | MEDIUM | 6.5 | 2026-09-02 | Incorrect authorization in Autofill in Google Chrome on on Android prior to 152.0.7977.75 allowed a remote attacker leveraging social engineering to obtain sensitive inform… | |
| CVE-2026-84328 | LOW | Patched | 3.1 | 2026-09-02 | Missing authorization in FileSystem in Google Chrome prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process to bypass web origin policy v… |
| CVE-2026-84329 | MEDIUM | Patched | 5.3 | 2026-09-02 | Confused deputy in CredentialProvider in Google Chrome on on Windows prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process to leak sensi… |
| CVE-2026-84330 | MEDIUM | 5.4 | 2026-09-02 | UI misrepresentation in FullScreen in Google Chrome on on Android prior to 152.0.7977.75 allowed a remote attacker to spoof address bar via a crafted HTML page. (Chromium s… | |
| CVE-2026-84331 | LOW | Patched | 3.1 | 2026-09-02 | Incorrect authorization in Actor in Google Chrome prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via … |
| CVE-2026-84332 | MEDIUM | Patched | 6.5 | 2026-09-02 | Incorrect authorization in SiteSettings in Google Chrome prior to 152.0.7977.75 allowed a remote attacker to bypass system access restrictions via a crafted HTML page. (Chr… |
| CVE-2026-84333 | CRITICAL | 9.6 | 2026-09-02 | Use after free in Dawn in Google Chrome on on Android prior to 152.0.7977.75 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page… | |
| CVE-2026-84334 | HIGH | Patched | 8.1 | 2026-09-02 | Incorrect authorization in Chromoting in Google Chrome on on Windows prior to 152.0.7977.75 allowed a local attacker to execute arbitrary code outside the sandbox via a loc… |
| CVE-2026-84335 | HIGH | Patched | 8.3 | 2026-09-02 | Incorrect authorization in TabStrip in Google Chrome prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process and leveraged social engineer… |
| CVE-2026-84347 | HIGH | Patched | 8.8 | 2026-09-02 | Use after free in WebRTC in Google Chrome prior to 152.0.7977.75 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium s… |
| CVE-2026-84348 | MEDIUM | Patched | 6.5 | 2026-09-02 | Information leak in MediaCapture in Google Chrome prior to 152.0.7977.75 allowed a remote attacker to potentially leak sensitive information via a crafted HTML page. (Chrom… |
| CVE-2026-84349 | HIGH | Patched | 8.3 | 2026-09-02 | Use after free in Browser in Google Chrome prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the s… |
| CVE-2026-84350 | HIGH | Patched | 8.8 | 2026-09-02 | Use after free in TabStrip in Google Chrome prior to 152.0.7977.75 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox via… |
| CVE-2026-84351 | HIGH | Patched | 8.3 | 2026-09-02 | Buffer overflow in GPU in Google Chrome on on Windows prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process to execute arbitrary code ou… |
| CVE-2026-84352 | CRITICAL | 9.6 | 2026-09-02 | Use after free in WebGL in Google Chrome on on Android prior to 152.0.7977.75 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML pag… | |
| CVE-2026-84353 | CRITICAL | 9.6 | 2026-09-02 | Use after free in Shared Tab Groups in Google Chrome on on Android prior to 152.0.7977.75 allowed a remote attacker leveraging social engineering to execute arbitrary code … |