Export limit exceeded: 11167 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (27475 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-79123 | 2 Google, Microsoft | 2 Chrome, Windows | 2026-08-27 | 6.5 Medium |
| Improper input validation in NTP Footer in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Low) | ||||
| CVE-2026-79247 | 2 Google, Microsoft | 2 Chrome, Windows | 2026-08-26 | 8.3 High |
| Use after free in Chromoting in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via crafted network traffic. (Chromium security severity: High) | ||||
| CVE-2026-79253 | 2 Google, Microsoft | 2 Chrome, Windows | 2026-08-26 | 6.5 Medium |
| Improper input validation in Network in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to leak sensitive information via a crafted HTML page. (Chromium security severity: Low) | ||||
| CVE-2026-19875 | 5 Apple, Ibm, Langflow and 2 more | 6 Macos, Langflow, Langflow Oss and 3 more | 2026-08-26 | 7.5 High |
| IBM Langflow OSS 1.0.0 through 1.10.0 could allow a remote attacker to overwrite administrator email information and abuse the server as an outbound relay due to missing authentication for the registration endpoint. | ||||
| CVE-2026-79048 | 2 Google, Microsoft | 2 Chrome, Windows | 2026-08-26 | 8.8 High |
| Out of bounds write in ANGLE in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High) | ||||
| CVE-2026-78989 | 2 Google, Microsoft | 2 Chrome, Windows | 2026-08-26 | 9.6 Critical |
| Out of bounds read in ANGLE in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High) | ||||
| CVE-2019-1068 | 1 Microsoft | 3 Sql Server, Sql Server 2016, Sql Server 2017 | 2026-08-26 | 8.8 High |
| A remote code execution vulnerability exists in Microsoft SQL Server when it incorrectly handles processing of internal functions, aka 'Microsoft SQL Server Remote Code Execution Vulnerability'. | ||||
| CVE-2026-79019 | 2 Google, Microsoft | 2 Chrome, Windows | 2026-08-26 | 9.6 Critical |
| Out of bounds write in ANGLE in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High) | ||||
| CVE-2026-78978 | 2 Google, Microsoft | 2 Chrome, Windows | 2026-08-26 | 8.8 High |
| Out of bounds read in ANGLE in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium) | ||||
| CVE-2026-19297 | 5 Apple, Ibm, Langflow and 2 more | 5 Macos, Langflow Oss, Langflow and 2 more | 2026-08-26 | 9.1 Critical |
| IBM Langflow OSS 1.0.0 through 1.9.6 could allow a remote attacker to obtain unauthorized access to user accounts due to improper restriction of excessive authentication attempts. | ||||
| CVE-2026-69543 | 1 Microsoft | 2 Azure Virtual Machine, Azure Virtual Machines | 2026-08-26 | 8.5 High |
| Server-side request forgery (ssrf) in Azure Virtual Machines allows an authorized attacker to elevate privileges over a network. | ||||
| CVE-2026-55015 | 1 Microsoft | 2 Remote Help, Windows-remote-help | 2026-08-26 | 5.5 Medium |
| Uncontrolled search path element in Windows Remote Help allows an authorized attacker to deny service locally. | ||||
| CVE-2026-55013 | 1 Microsoft | 2 Remote Help, Windows-remote-help | 2026-08-26 | 7.1 High |
| Uncontrolled search path element in Windows Remote Help Defense allows an authorized attacker to perform spoofing locally. | ||||
| CVE-2026-59131 | 2 Amd, Microsoft | 26 Ryzen, Windows 10 1607, Windows 10 1809 and 23 more | 2026-08-25 | 5.6 Medium |
| No cwe for this issue in AMD Zen allows an authorized attacker to disclose information locally. | ||||
| CVE-2026-59130 | 1 Microsoft | 25 Windows 10 1607, Windows 10 1809, Windows 10 21h2 and 22 more | 2026-08-25 | 5.6 Medium |
| No cwe for this issue in AMD Zen allows an authorized attacker to disclose information locally. | ||||
| CVE-2026-69851 | 1 Microsoft | 2 Entra Id, Microsoft Entra Id | 2026-08-25 | 9.9 Critical |
| Server-side request forgery (ssrf) in Azure Active Directory allows an authorized attacker to elevate privileges over a network. | ||||
| CVE-2026-69558 | 1 Microsoft | 1 Partner Center | 2026-08-25 | 8.6 High |
| Authorization bypass through user-controlled key in Microsoft Partner Center allows an unauthorized attacker to disclose information over a network. | ||||
| CVE-2026-69519 | 1 Microsoft | 1 Azure Stack Hci | 2026-08-25 | 8.6 High |
| Observable response discrepancy in Azure Stack HCI allows an unauthorized attacker to disclose information over a network. | ||||
| CVE-2026-65770 | 1 Microsoft | 1 Azure Managed Instance For Apache Cassandra | 2026-08-25 | 10 Critical |
| Improper neutralization of argument delimiters in a command ('argument injection') in Azure Managed Instance for Apache Cassandra allows an unauthorized attacker to execute code over a network. | ||||
| CVE-2026-62316 | 1 Microsoft | 1 Ufo | 2026-08-25 | 8.8 High |
| Microsoft UFO open-source framework for intelligent automation across devices and platforms. Prior to 3.0.8, ufo/client/mcp/http_servers/linux_mcp_server.py binds a FastMCP streamable HTTP server to localhost:8010 but does not validate the Host, Origin, or Sec-Fetch-Site headers. An attacker-controlled web page can use DNS rebinding to reach the local /mcp endpoint, enumerate tool schemas through tools/list, and invoke execute_command with a valid UFO_MCP_API_KEY to read files or execute allowed operating system commands as the victim's user. This issue is fixed in version 3.0.8. | ||||
