Search
31,862 CVEs
CVEs (31,862, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 201–225 of 31,862 (capped at 500)
| CVE ID | Severity ↓ | Patch | CVSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-87442 | NONE | — | 2026-09-09 | Confused deputy in Prerender in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to potentially bypass web origin pol… | |
| CVE-2026-87445 | NONE | — | 2026-09-09 | UI misrepresentation in Session in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium) | |
| CVE-2026-87446 | NONE | — | 2026-09-09 | Incomplete cleanup in Extensions in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a … | |
| CVE-2026-87432 | NONE | — | 2026-09-09 | Incorrect authorization in Navigation in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to spoof UI elements via a … | |
| CVE-2026-87433 | NONE | — | 2026-09-09 | Race condition in FileAPI in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted … | |
| CVE-2026-87434 | NONE | — | 2026-09-09 | Missing authorization in CORS in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a c… | |
| CVE-2026-87436 | NONE | — | 2026-09-09 | Incomplete cleanup in Browser in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass web origin policy via a crafted Chro… | |
| CVE-2026-87437 | NONE | — | 2026-09-09 | Information leak in Frames in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to leak sensitive information via a crafted HTML page. (Chromium security sever… | |
| CVE-2026-87429 | NONE | — | 2026-09-09 | Missing authorization in ServiceWorker in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to bypass system access re… | |
| CVE-2026-87431 | NONE | — | 2026-09-09 | Missing authorization in Extensions in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to obtain sensitive information via a crafted Chrome extension. (Chrom… | |
| CVE-2026-19201 | NONE | — | 2026-09-09 | An uncontrolled recursion vulnerability in the Windows SIPA event log parser of Google go-attestation versions up to and including 0.6.1 allows an attacker to cause a denia… | |
| CVE-2026-55250 | NONE | — | 2026-09-08 | Maravel, a PHP framework oriented towards dependency injection, prior to version 10.74.0 has a high-severity Token Replay Vulnerability arising from a structural lifecycle … | |
| CVE-2026-47680 | NONE | Patched | — | 2026-09-08 | The source-controller is a Kubernetes operator, specialised in artifacts acquisition from external sources such as Git, OCI, Helm repositories and S3-compatible buckets. In… |
| CVE-2026-53639 | NONE | Patched | — | 2026-09-08 | Sylius is an Open Source eCommerce Framework on Symfony. Starting in version 2.0.0 and prior to version 2.0.18, 2.1.15, and 2.2.6, the `GET /api/v2/shop/payment-requests/{h… |
| CVE-2026-86995 | NONE | Patched | — | 2026-09-08 | n8n is an open source workflow automation platform. Prior to 1.123.76, 2.37.7, and 2.38.2, the Git node validated the repository parameter for fetch or pull, but setUpstrea… |
| CVE-2026-86996 | NONE | Patched | — | 2026-09-08 | n8n is an open source workflow automation platform. Prior to 2.37.7 and 2.38.2, the workflow setting named This workflow can be called by was enforced by the Execute Workfl… |
| CVE-2026-86081 | NONE | Patched | — | 2026-09-08 | n8n is an open source workflow automation platform. Prior to 1.123.76, 2.37.7, and 2.38.2, the Git node clone operation matched an attacker-controlled destination path agai… |
| CVE-2026-86082 | NONE | Patched | — | 2026-09-08 | n8n is an open source workflow automation platform. Prior to 1.123.76, 2.37.7, and 2.38.2, the OpenAI Chat Model node enforced credential allowed-domain restrictions for no… |
| CVE-2026-86083 | NONE | Patched | — | 2026-09-08 | n8n is an open source workflow automation platform. Prior to 1.123.76, 2.37.7, and 2.38.2, the legacy expression engine generated source text by calling the mutable global … |
| CVE-2026-86084 | NONE | Patched | — | 2026-09-08 | n8n is an open source workflow automation platform. Prior to 1.123.76, 2.37.7, and 2.38.2, the public OIDC login and callback endpoints completed authentication even when O… |
| CVE-2026-86085 | NONE | Patched | — | 2026-09-08 | n8n is an open source workflow automation platform. Prior to 2.37.7 and 2.38.2, the /rest/roles/:slug/assignments and /rest/roles/:slug/assignments/:projectId/members endpo… |
| CVE-2026-86993 | NONE | Patched | — | 2026-09-08 | n8n is an open source workflow automation platform. Prior to 1.123.76, 2.37.7, and 2.38.2, a Log Streaming event destination could reference a generic HTTP credential and d… |
| CVE-2026-86994 | NONE | Patched | — | 2026-09-08 | n8n is an open source workflow automation platform. Prior to 1.123.76, 2.37.7, and 2.38.2, the /rest/active-workflows endpoint returned every active workflow ID on the inst… |
| CVE-2026-81904 | NONE | — | 2026-09-08 | Concrete CMS below 9.5.3 registered view assets for every sub-block of a Stack, Container, or layout area without checking whether the requesting user could view that sub-b… | |
| CVE-2026-86075 | NONE | Patched | — | 2026-09-08 | n8n is an open source workflow automation platform. Prior to 2.37.7 and 2.38.2, the OAuth Dynamic Client Registration endpoint bounded redirect_uris but accepted arbitraril… |