Search
2,281 CVEs
CVEs (2,281, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 476–500 of 2,281 (capped at 500)
| CVE ID | Severity | Patch | CVSS | Published ↑ | Description |
|---|---|---|---|---|---|
| CVE-2026-84354 | CRITICAL | Patched | 9.6 | 2026-09-02 | Incorrect authorization in FileSystem in Google Chrome prior to 152.0.7977.75 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the … |
| CVE-2026-84355 | LOW | Patched | 3.1 | 2026-09-02 | Incorrect authorization in Navigation in Google Chrome prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process to bypass web origin policy… |
| CVE-2026-84356 | MEDIUM | Patched | 4.3 | 2026-09-02 | UI misrepresentation in FullScreen in Google Chrome prior to 152.0.7977.75 allowed a remote attacker to spoof address bar via a crafted HTML page. (Chromium security severity: Low) |
| CVE-2026-84357 | MEDIUM | Patched | 6.5 | 2026-09-02 | Improper input validation in Omnibox in Google Chrome prior to 152.0.7977.75 allowed a remote attacker leveraging social engineering to bypass web origin policy via crafted… |
| CVE-2026-84358 | MEDIUM | Patched | 4.2 | 2026-09-02 | Improper privilege management in Downloads in Google Chrome prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process to spoof address bar v… |
| CVE-2026-84359 | LOW | Patched | 3.1 | 2026-09-02 | Information leak in Skia in Google Chrome prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted … |
| CVE-2026-84425 | MEDIUM | 4.3 | 2026-09-02 | A vulnerability was found in zhayujie CowAgent up to 2.1.3. This impacts the function BrowserTool of the file agent/tools/browser/browser_tool.py of the component Browser T… | |
| CVE-2026-84427 | MEDIUM | 4.3 | 2026-09-02 | A vulnerability was determined in zhayujie CowAgent up to 2.1.7. Affected is an unknown function of the file agent/tools/bash/bash.py of the component Bash Tool. Executing … | |
| CVE-2026-84430 | MEDIUM | 6.3 | 2026-09-02 | A security vulnerability has been detected in gouguoa up to 5.10.0/6.0.1. This vulnerability affects the function update of the file app/home/controller/Index.php of the co… | |
| CVE-2026-84694 | HIGH | Patched | 8.8 | 2026-09-02 | Coolify before 4.2.0 fails to properly escape environment variable key names in Docker commands executed over SSH on managed servers. Authenticated attackers can inject she… |
| CVE-2026-84695 | HIGH | Patched | 8.7 | 2026-09-02 | BookStack before 26.05.4 contains a stored cross-site scripting vulnerability in the drawing upload endpoint that accepts unvalidated base64 content and stores it without c… |
| CVE-2026-84696 | HIGH | 8.2 | 2026-09-02 | Phison PS3111-S11 controller firmware versions through SBFQT1.3 expose privileged vendor unique commands over the ATA interface with absent or defeatable authentication mec… | |
| CVE-2026-84697 | MEDIUM | 5.3 | 2026-09-02 | Mailpit's IsInternalIP deny list function fails to block the Azure WireServer address 168.63.129.16 and the RFC 2765/6145 IPv4-translated IPv6 prefix, allowing server-side … | |
| CVE-2026-84698 | MEDIUM | 6.5 | 2026-09-02 | PX4 Autopilot contains a heap buffer overflow vulnerability in the sd_bench command that writes a four-byte block number into a user-supplied sized allocation. Attackers ca… | |
| CVE-2026-84699 | CRITICAL | Patched | 9.1 | 2026-09-02 | Team Password Manager before 14.184.308 fails to enforce authentication requirements in the local account password reset flow. Unauthenticated attackers can reset local acc… |
| CVE-2026-84700 | HIGH | 8.6 | 2026-09-02 | PikiwiDB (Pika) v3.5.7 exposes an internal protobuf replication server on a port derived from the client port plus 2000 (e.g. 11221 when the default client port 9221 is use… | |
| CVE-2026-84701 | MEDIUM | 5.4 | 2026-09-02 | NocoBase fails to sanitize rich text field values in the read renderer, allowing users with create permissions to store malicious HTML with event handlers. Attackers can wr… | |
| CVE-2026-84702 | HIGH | 7.5 | 2026-09-02 | facefusion through 3.6.1 fails to normalize job identifiers in get_job_file_name, allowing attackers to write files outside the jobs directory. Attackers can supply travers… | |
| CVE-2026-82968 | MEDIUM | 6.4 | 2026-09-02 | A flaw was found in the first-broker-login flow of the Keycloak identity management service. When a user links a social identity provider account to their local account, th… | |
| CVE-2026-84431 | MEDIUM | 4.4 | 2026-09-02 | A vulnerability was detected in AirAsia MOVE App up to 12.47.1 on Android. This issue affects the function com.airasia.core.utils.RealPathUtil.getRealPath of the component … | |
| CVE-2026-84437 | LOW | 3.5 | 2026-09-02 | A vulnerability was found in OpenCart 4.1.0.3/4.1.0.4. The impacted element is an unknown function of the file catalog/controller/account/address.php of the component Autoc… | |
| CVE-2026-84438 | LOW | 3.5 | 2026-09-02 | A vulnerability was determined in OpenCart 4.1.0.3/4.1.0.4. This affects an unknown function of the file catalog/controller/account/edit.php of the component Autocomplete W… | |
| CVE-2026-84484 | HIGH | Patched | 7.5 | 2026-09-02 | ION-DTN versions before 4.2.0 contain an out-of-bounds read vulnerability in the decodeSdnv function that allows unauthenticated remote attackers to read memory by sending … |
| CVE-2026-84485 | HIGH | 7.5 | 2026-09-02 | APITable through 1.13.0-beta.1 exposes the internal organization loadOrSearch endpoint without authentication, allowing unauthenticated attackers to retrieve member names, … | |
| CVE-2026-84715 | HIGH | Patched | 8.8 | 2026-09-02 | FeatherPanel versions before 1.3.7.10 fail to validate permissions in the SubuserController updateSubuser handler, allowing authenticated subusers to modify their own permi… |