Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

2,372 CVEs

CVEs (2,372, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 151–175 of 2,372 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2026-85047 CRITICAL 9.6 2026-09-03 Improper input validation in Transactions Platform in Google Chrome on on iOS prior to 152.0.7977.82 allowed a remote attacker to potentially execute arbitrary code outside…
CVE-2026-85042 CRITICAL 9.6 2026-09-03 Use after free in DevTools in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromiu…
CVE-2026-53649 CRITICAL Patched 9.6 2026-09-02 Joro is a web exploitation framework. Prior to version 1.1.1, Joro's default proxy mode exposes a local API on 127.0.0.1:9090 that performs no authentication and applies a …
CVE-2026-84352 CRITICAL 9.6 2026-09-02 Use after free in WebGL in Google Chrome on on Android prior to 152.0.7977.75 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML pag…
CVE-2026-84353 CRITICAL 9.6 2026-09-02 Use after free in Shared Tab Groups in Google Chrome on on Android prior to 152.0.7977.75 allowed a remote attacker leveraging social engineering to execute arbitrary code …
CVE-2026-84354 CRITICAL Patched 9.6 2026-09-02 Incorrect authorization in FileSystem in Google Chrome prior to 152.0.7977.75 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the …
CVE-2026-84333 CRITICAL 9.6 2026-09-02 Use after free in Dawn in Google Chrome on on Android prior to 152.0.7977.75 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page…
CVE-2026-19766 CRITICAL Patched 9.6 2026-09-01 An authentication bypass vulnerability exists in the underlying operating system of HPE Networking Fabric Composer. Successful exploitation could allow an unauthenticated a…
CVE-2026-84119 CRITICAL Patched 9.6 2026-09-01 Sandbox escape due to use-after-free in the DOM: Navigation component. This vulnerability was fixed in Firefox 155, Firefox ESR 115.40, Firefox ESR 140.15, Firefox ESR 153.…
CVE-2026-84121 CRITICAL Patched 9.6 2026-09-01 Sandbox escape due to use-after-free in the DOM: Security component. This vulnerability was fixed in Firefox 155, Firefox ESR 115.40, Firefox ESR 140.15, Firefox ESR 153.2,…
CVE-2026-85216 NONE — 2026-09-03 MISP contains an authentication bypass vulnerability in its LDAP and LinOTP authentication components due to insufficient validation of user-supplied credentials. The cust…
CVE-2026-82180 NONE — 2026-09-03 In Eclipse Arrowhead versions from 5.0.0 to 5.2.1 when the MQTT API is enabled with the certificate authentication policy, CertificateMqttFilter parses an X.509 certificate…
CVE-2026-78069 NONE — 2026-09-03 Joomla Extension - j2commerce.com - Missing authorization on Apps controller delegation chain in J2Store 1.0.0-3.3.21, 4.0.0-4.0.21, 4.1.0-4.1.6 - `J2StoreControllerApps`'s…
CVE-2026-76969 CRITICAL 9.4 2026-09-08 @sap/cds-mtxs NPM library does not perform sufficient checks on certain functionality used in multitenant CAP applications with extensibility enabled. An unauthenticated at…
CVE-2026-61410 CRITICAL 9.4 2026-09-07 Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains a Missing Authorization vulnerability. An unauthenti…
CVE-2026-6223 CRITICAL 9.4 2026-09-07 Improper restriction of excessive authentication attempts vulnerability in Bahçelievler Muncipality BiHayat App allows Authentication Bypass. This issue affects BiHayat Ap…
CVE-2026-52777 NONE Patched — 2026-09-05 YesWiki is a wiki system written in PHP. Prior to version 4.6.6, there is an authenticated PHP object injection vulnerability in BazarImportAction via unserialize. This iss…
CVE-2026-85695 CRITICAL 9.4 2026-09-04 FastChat contains an authentication bypass vulnerability in the /register_worker endpoint that allows unauthenticated attackers to register arbitrary worker addresses and p…
CVE-2026-76174 NONE — 2026-09-03 Unrestricted file upload vulnerability in the CSV file upload functionality of the Ocsreports admin_info endpoint. The application validates files solely based on the name …
CVE-2026-4813 NONE — 2026-09-01 A vulnerability in the Lutece Core XSL export management module up to version 7.1.7, which allows authenticated administrators to execute code remotely. The XML/XSLT proces…
CVE-2026-77089 NONE Patched — 2026-09-08 Command Center API contained an authentication bypass issue affecting privilege management. Software customers upgrade to resolved maintenance release. Update Command Center.
CVE-2026-80238 CRITICAL 9.3 2026-09-07 Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Execution with Unnecessary Privileges vulnerabili…
CVE-2026-16876 NONE — 2026-09-07 An authentication bypass vulnerability exists in the WebGUI of Series UNIVERGE IX-R/IX-V. A user could bypass authentication and execute arbitrary CLI commands by tampering…
CVE-2026-85595 NONE — 2026-09-04 Traefik versions before v2.11.55 and versions v3.0.0 through v3.7.10 contain an authentication bypass vulnerability in the digestAuth middleware where unknown usernames rec…
CVE-2026-80098 CRITICAL 9.3 2026-09-03 Improper verification of cryptographic signature in Copilot Studio allows an unauthorized attacker to elevate privileges over a network.