Export limit exceeded: 403577 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Search

Search Results (403577 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-102407 1 Elastic 1 Elasticsearch 2026-10-07 5.4 Medium
Incorrect Authorization (CWE-863) in Elasticsearch can lead to unauthorized data stream modification via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). An authenticated user with sufficient privileges over a single resource could use the Modify Data Streams API to modify a data stream to which they were not otherwise authorized, potentially injecting data into it or affecting its ability to be searched normally. This issue does not allow an attacker to read the contents of a data stream they do not otherwise have access to.
CVE-2026-102409 1 Elastic 1 Elasticsearch 2026-10-07 6.5 Medium
Uncontrolled Recursion (CWE-674) in Elasticsearch can allow an authenticated user with low privileges to terminate an Elasticsearch node, resulting in denial of service, via Excessive Allocation (CAPEC-130).
CVE-2026-106305 1 Google 2 Android, Chrome 2026-10-07 5.4 Medium
UI misrepresentation in Mobile in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker to spoof UI elements via a crafted HTML page. (Chromium security severity: Low)
CVE-2026-106308 1 Google 2 Android, Chrome 2026-10-07 8.8 High
Incorrect reference resolution in Autofill in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: High)
CVE-2026-106309 2 Apple, Google 2 Iphone Os, Chrome 2026-10-07 8.8 High
Incorrect authorization in Selection in Google Chrome on on iOS prior to 155.0.8059.39 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Low)
CVE-2026-106311 1 Google 1 Chrome 2026-10-07 5.4 Medium
Clickjacking in PermissionElement in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-106312 1 Google 1 Chrome 2026-10-07 6.5 Medium
Missing authorization in SignIn in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted Chrome extension. (Chromium security severity: Low)
CVE-2026-106313 1 Google 2 Android, Chrome 2026-10-07 5.1 Medium
Incorrect authorization in Browser in Google Chrome on on Android prior to 155.0.8059.39 allowed a local attacker leveraging social engineering to obtain sensitive information via a co-installed app. (Chromium security severity: Medium)
CVE-2026-106314 1 Google 1 Chrome 2026-10-07 8.8 High
Incorrect authorization in Bluetooth in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-106315 1 Google 1 Chrome 2026-10-07 8.8 High
Use after free in Modularization in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-106316 2 Apple, Google 2 Macos, Chrome 2026-10-07 5.4 Medium
UI misrepresentation in Chromoting in Google Chrome on on Mac prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to spoof UI elements via crafted network traffic. (Chromium security severity: Low)
CVE-2026-106317 1 Google 2 Android, Chrome 2026-10-07 5.4 Medium
UI misrepresentation in FullScreen in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker to spoof address bar via a crafted HTML page. (Chromium security severity: Low)
CVE-2026-106318 1 Google 1 Chrome 2026-10-07 8.8 High
Use after free in Media in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
CVE-2026-106323 2 Apple, Google 2 Iphone Os, Chrome 2026-10-07 9.6 Critical
Missing authorization in Chrome for iOS in Google Chrome on on iOS prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
CVE-2026-90462 3 Fedoraproject, Redhat, Sssd 5 Sssd, Enterprise Linux, Openshift and 2 more 2026-10-07 5.4 Medium
A flaw was found in SSSD. When configured with the LDAP access provider and `ldap_access_order` including `ppolicy` or `lockout`, a fail-open condition in the LDAP ppolicy access check can occur if a user lookup returns zero results. This can incorrectly return success and cache an allow decision, permitting continued authorization for a deleted or deprovisioned user. A remote attacker with prior valid account context could exploit this to maintain access to information and potentially make limited modifications to resources that should no longer be available.
CVE-2026-106388 1 Google 1 Chrome 2026-10-07 5.3 Medium
Missing authorization in DataTransfer in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-106390 1 Google 1 Chrome 2026-10-07 4.3 Medium
Incorrect provision of specified functionality in SanitizerAPI in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to leak sensitive information via a crafted HTML page. (Chromium security severity: Low)
CVE-2026-106391 1 Google 2 Android, Chrome 2026-10-07 4.2 Medium
Incorrect authorization in WebShare in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-106392 1 Google 1 Chrome 2026-10-07 4.3 Medium
Information leak in WebAudio in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentially leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-106393 1 Google 1 Chrome 2026-10-07 8.3 High
Use after free in Storage in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)