Search
2,372 CVEs
CVEs (2,372, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 151–175 of 2,372 (capped at 500)
| CVE ID | Severity | Patch | CVSS ↓ | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-85047 | CRITICAL | 9.6 | 2026-09-03 | Improper input validation in Transactions Platform in Google Chrome on on iOS prior to 152.0.7977.82 allowed a remote attacker to potentially execute arbitrary code outside… | |
| CVE-2026-85042 | CRITICAL | 9.6 | 2026-09-03 | Use after free in DevTools in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromiu… | |
| CVE-2026-53649 | CRITICAL | Patched | 9.6 | 2026-09-02 | Joro is a web exploitation framework. Prior to version 1.1.1, Joro's default proxy mode exposes a local API on 127.0.0.1:9090 that performs no authentication and applies a … |
| CVE-2026-84352 | CRITICAL | 9.6 | 2026-09-02 | Use after free in WebGL in Google Chrome on on Android prior to 152.0.7977.75 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML pag… | |
| CVE-2026-84353 | CRITICAL | 9.6 | 2026-09-02 | Use after free in Shared Tab Groups in Google Chrome on on Android prior to 152.0.7977.75 allowed a remote attacker leveraging social engineering to execute arbitrary code … | |
| CVE-2026-84354 | CRITICAL | Patched | 9.6 | 2026-09-02 | Incorrect authorization in FileSystem in Google Chrome prior to 152.0.7977.75 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the … |
| CVE-2026-84333 | CRITICAL | 9.6 | 2026-09-02 | Use after free in Dawn in Google Chrome on on Android prior to 152.0.7977.75 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page… | |
| CVE-2026-19766 | CRITICAL | Patched | 9.6 | 2026-09-01 | An authentication bypass vulnerability exists in the underlying operating system of HPE Networking Fabric Composer. Successful exploitation could allow an unauthenticated a… |
| CVE-2026-84119 | CRITICAL | Patched | 9.6 | 2026-09-01 | Sandbox escape due to use-after-free in the DOM: Navigation component. This vulnerability was fixed in Firefox 155, Firefox ESR 115.40, Firefox ESR 140.15, Firefox ESR 153.… |
| CVE-2026-84121 | CRITICAL | Patched | 9.6 | 2026-09-01 | Sandbox escape due to use-after-free in the DOM: Security component. This vulnerability was fixed in Firefox 155, Firefox ESR 115.40, Firefox ESR 140.15, Firefox ESR 153.2,… |
| CVE-2026-85216 | NONE | — | 2026-09-03 | MISP contains an authentication bypass vulnerability in its LDAP and LinOTP authentication components due to insufficient validation of user-supplied credentials. The cust… | |
| CVE-2026-82180 | NONE | — | 2026-09-03 | In Eclipse Arrowhead versions from 5.0.0 to 5.2.1 when the MQTT API is enabled with the certificate authentication policy, CertificateMqttFilter parses an X.509 certificate… | |
| CVE-2026-78069 | NONE | — | 2026-09-03 | Joomla Extension - j2commerce.com - Missing authorization on Apps controller delegation chain in J2Store 1.0.0-3.3.21, 4.0.0-4.0.21, 4.1.0-4.1.6 - `J2StoreControllerApps`'s… | |
| CVE-2026-76969 | CRITICAL | 9.4 | 2026-09-08 | @sap/cds-mtxs NPM library does not perform sufficient checks on certain functionality used in multitenant CAP applications with extensibility enabled. An unauthenticated at… | |
| CVE-2026-61410 | CRITICAL | 9.4 | 2026-09-07 | Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains a Missing Authorization vulnerability. An unauthenti… | |
| CVE-2026-6223 | CRITICAL | 9.4 | 2026-09-07 | Improper restriction of excessive authentication attempts vulnerability in Bahçelievler Muncipality BiHayat App allows Authentication Bypass. This issue affects BiHayat Ap… | |
| CVE-2026-52777 | NONE | Patched | — | 2026-09-05 | YesWiki is a wiki system written in PHP. Prior to version 4.6.6, there is an authenticated PHP object injection vulnerability in BazarImportAction via unserialize. This iss… |
| CVE-2026-85695 | CRITICAL | 9.4 | 2026-09-04 | FastChat contains an authentication bypass vulnerability in the /register_worker endpoint that allows unauthenticated attackers to register arbitrary worker addresses and p… | |
| CVE-2026-76174 | NONE | — | 2026-09-03 | Unrestricted file upload vulnerability in the CSV file upload functionality of the Ocsreports admin_info endpoint. The application validates files solely based on the name … | |
| CVE-2026-4813 | NONE | — | 2026-09-01 | A vulnerability in the Lutece Core XSL export management module up to version 7.1.7, which allows authenticated administrators to execute code remotely. The XML/XSLT proces… | |
| CVE-2026-77089 | NONE | Patched | — | 2026-09-08 | Command Center API contained an authentication bypass issue affecting privilege management. Software customers upgrade to resolved maintenance release. Update Command Center. |
| CVE-2026-80238 | CRITICAL | 9.3 | 2026-09-07 | Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Execution with Unnecessary Privileges vulnerabili… | |
| CVE-2026-16876 | NONE | — | 2026-09-07 | An authentication bypass vulnerability exists in the WebGUI of Series UNIVERGE IX-R/IX-V. A user could bypass authentication and execute arbitrary CLI commands by tampering… | |
| CVE-2026-85595 | NONE | — | 2026-09-04 | Traefik versions before v2.11.55 and versions v3.0.0 through v3.7.10 contain an authentication bypass vulnerability in the digestAuth middleware where unknown usernames rec… | |
| CVE-2026-80098 | CRITICAL | 9.3 | 2026-09-03 | Improper verification of cryptographic signature in Copilot Studio allows an unauthorized attacker to elevate privileges over a network. |