Export limit exceeded: 101148 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (101148 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-87617 | 1 Google | 1 Chrome | 2026-09-09 | 8.8 High |
| Use after free in DevTools in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Low) | ||||
| CVE-2026-87612 | 1 Google | 1 Chrome | 2026-09-09 | 8.8 High |
| Type confusion in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High) | ||||
| CVE-2026-87616 | 2 Google, Microsoft | 2 Chrome, Windows | 2026-09-09 | 8.3 High |
| Improper initialization in Views in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium) | ||||
| CVE-2026-87618 | 2 Google, Microsoft | 2 Chrome, Windows | 2026-09-09 | 8.3 High |
| Incorrect reference resolution in Storage in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Low) | ||||
| CVE-2026-87639 | 1 Google | 1 Chrome | 2026-09-09 | 8.3 High |
| Use after free in WebPackaging in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High) | ||||
| CVE-2026-69417 | 1 Microsoft | 1 Sharepoint Server | 2026-09-09 | 7.3 High |
| Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. | ||||
| CVE-2026-77897 | 1 Microsoft | 2 Power Automate Agent For Virtual Desktops, Power Automate For Desktop | 2026-09-09 | 7 High |
| Relative path traversal in Power Automate allows an authorized attacker to elevate privileges locally. | ||||
| CVE-2026-69478 | 1 Microsoft | 18 Windows 10 1607, Windows 10 1809, Windows 10 21h2 and 15 more | 2026-09-09 | 7.8 High |
| Heap-based buffer overflow in Windows Device Association Service allows an authorized attacker to elevate privileges locally. | ||||
| CVE-2026-65772 | 1 Microsoft | 1 Dynamics 365 | 2026-09-09 | 8.8 High |
| Deserialization of untrusted data in Microsoft Dynamics 365 allows an authorized attacker to execute code over a network. | ||||
| CVE-2026-58599 | 1 Microsoft | 3 Hevc Video Extensions, Hevc Video Extensions For Licensed Appplications, Hevc Video Extensions From Device Manufacturer | 2026-09-09 | 7.8 High |
| Heap-based buffer overflow in Microsoft Windows Codecs Library allows an unauthorized attacker to execute code locally. | ||||
| CVE-2026-87636 | 1 Google | 1 Chrome | 2026-09-09 | 8.8 High |
| Type confusion in XML in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium) | ||||
| CVE-2026-87479 | 1 Google | 1 Chrome | 2026-09-09 | 8.3 High |
| Insufficient policy enforcement in Extensions in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium) | ||||
| CVE-2026-87444 | 1 Google | 1 Chrome | 2026-09-09 | 8.8 High |
| Memory corruption in Codecs in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High) | ||||
| CVE-2026-87440 | 1 Google | 1 Chrome | 2026-09-09 | 8.8 High |
| Out of bounds read in Media in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High) | ||||
| CVE-2026-87430 | 1 Google | 1 Chrome | 2026-09-09 | 8.8 High |
| Buffer overflow in WebRTC in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Low) | ||||
| CVE-2026-85730 | 1 Squirrelchat | 1 Smol-toml | 2026-09-09 | 7.5 High |
| smol-toml is a small, fast, and correct TOML parser and serializer. Prior to 1.7.1, parse() can enter an infinite loop when a value inside an array or inline table is followed by a comment with no trailing newline. In src/util.ts, skipUntil() calls indexOfNewline(), receives -1 at the end of input, and resets the cursor to the beginning of the string instead of leaving the structure scan. The parser then hangs indefinitely and can consume a service's processing capacity when an application parses attacker-controlled TOML. This issue is fixed in version 1.7.1. | ||||
| CVE-2026-0294 | 4 Apple, Microsoft, Palo Alto Networks and 1 more | 4 Macos, Windows, Prisma Access Agent and 1 more | 2026-09-09 | 7.8 High |
| A privilege escalation (PE) vulnerability in the Palo Alto Networks Prisma® Access Agent app on Windows and macOS devices enables a local user to execute code with elevated privileges. The Prisma Access Agent on Linux, iOS, Android, and ChromeOS is not affected. | ||||
| CVE-2026-84068 | 2026-09-09 | 8.6 High | ||
| The Quentn WP WordPress plugin before 1.2.15 does not adequately escape a request parameter before using it in an unprepared SQL query, allowing unauthenticated attackers to extract arbitrary data from the database via SQL injection. | ||||
| CVE-2026-67367 | 1 Siemens | 8 Simove Fleetmanager V3.1, Simove Fleetmanager V3.2, Simove Fleetmanager V3.3 and 5 more | 2026-09-09 | 8.6 High |
| A vulnerability has been identified in SIMOVE Fleetmanager V3.1 (All versions < V3.1.13), SIMOVE Fleetmanager V3.2 (All versions < V3.2.4), SIMOVE Fleetmanager V3.3 (All versions < V3.3.2), SIMOVE Fleetmanager V4.0 (All versions < V4.0.1), SIPLANT V1.7 (All versions), SIPLANT V2.2 (All versions), SIPLANT V3.0 (All versions), SIPLANT V3.1 (All versions < V3.1.4). Affected devices do not properly validate and neutralize directory traversal sequences in the file-serving endpoint of the embedded HTTP server. This could allow an unauthenticated remote attacker to read arbitrary files from the underlying operating system without any credentials, potentially exposing sensitive data such as credential stores, private keys, and configuration secrets. | ||||
| CVE-2026-62649 | 1 Siemens | 1 Reyrolle 7sr5 | 2026-09-09 | 7.5 High |
| A vulnerability has been identified in Reyrolle 7SR5 (All versions < V2.70). The web server does not properly limit or manage system resources when processing a high volume of concurrent HTTP requests. This could allow an unauthenticated remote attacker to cause the entire device to crash and reboot, resulting in a denial-of-service condition. | ||||