Export limit exceeded: 395153 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 395153 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (395153 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-91721 | 1 Google | 1 Chrome | 2026-09-17 | 8.8 High |
| Use after free in Internals in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical) | ||||
| CVE-2026-91718 | 1 Google | 1 Chrome | 2026-09-17 | 9.6 Critical |
| Use after free in Core in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High) | ||||
| CVE-2026-91717 | 1 Google | 2 Android, Chrome | 2026-09-17 | 5.1 Medium |
| Missing authorization in Android in Google Chrome on on Android prior to 153.0.8010.47 allowed a local attacker to obtain sensitive information via a co-installed app. (Chromium security severity: High) | ||||
| CVE-2026-91716 | 1 Google | 1 Chrome | 2026-09-17 | 9.6 Critical |
| Use after free in Auth in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High) | ||||
| CVE-2026-91715 | 1 Google | 1 Chrome | 2026-09-17 | 8.8 High |
| Type confusion in ServiceWorker in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High) | ||||
| CVE-2026-91714 | 1 Google | 1 Chrome | 2026-09-17 | 5.3 Medium |
| Observable discrepancy in Fonts in Google Chrome prior to 153.0.8010.47 allowed a remote attacker leveraging social engineering to leak sensitive information via a crafted HTML page. (Chromium security severity: Medium) | ||||
| CVE-2026-91713 | 1 Google | 1 Chrome | 2026-09-17 | 4.2 Medium |
| Missing authorization in Browser in Google Chrome prior to 153.0.8010.47 allowed a remote attacker who had compromised the renderer process to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium) | ||||
| CVE-2026-91712 | 2 Apple, Google | 2 Macos, Chrome | 2026-09-17 | 8.3 High |
| Race condition in Extensions in Google Chrome on on Mac prior to 153.0.8010.47 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High) | ||||
| CVE-2026-91711 | 1 Google | 1 Chrome | 2026-09-17 | 8.8 High |
| Out of bounds write in ServiceWorker in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High) | ||||
| CVE-2026-91710 | 1 Google | 1 Chrome | 2026-09-17 | 9.6 Critical |
| Use after free in WebAppInstalls in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High) | ||||
| CVE-2026-91709 | 1 Google | 1 Chrome | 2026-09-17 | 8.8 High |
| Type confusion in ServiceWorker in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High) | ||||
| CVE-2026-91708 | 1 Google | 1 Chrome | 2026-09-17 | 3.1 Low |
| Race condition in Network in Google Chrome prior to 153.0.8010.47 allowed a remote attacker who had compromised the renderer process to obtain cross-origin data via a crafted HTML page. (Chromium security severity: High) | ||||
| CVE-2026-77874 | 2026-09-17 | 7.1 High | ||
| A flaw was found in Hibernate ORM. This vulnerability allows an authenticated attacker to inject arbitrary SQL commands into the underlying database by manipulating the JSON path argument. The issue arises from improper handling of JSON path segments in the JsonPathHelper.appendInlinedJsonPathIncludingPassingClause() method, specifically when using Oracle, DB2, or HANA database dialects. Successful exploitation can lead to authorization bypass and significant data exfiltration, enabling the attacker to access sensitive information from the database. | ||||
| CVE-2026-66572 | 2026-09-17 | 6.5 Medium | ||
| Contributor Cross Site Scripting (XSS) in JetBlog <= 2.4.10 versions. | ||||
| CVE-2026-66577 | 2026-09-17 | 6.5 Medium | ||
| Contributor Cross Site Scripting (XSS) in JetSearch <= 3.6.3 versions. | ||||
| CVE-2026-66579 | 2026-09-17 | 6.5 Medium | ||
| Contributor Cross Site Scripting (XSS) in JetElements For Elementor <= 2.9.2.1 versions. | ||||
| CVE-2026-78528 | 2026-09-17 | 5.3 Medium | ||
| Unauthenticated Broken Access Control in BerqWP <= 4.1.15 versions. | ||||
| CVE-2026-73999 | 2026-09-17 | 5.4 Medium | ||
| Contributor Insecure Direct Object References (IDOR) in Cooked <= 1.16.0 versions. | ||||
| CVE-2026-66626 | 2026-09-17 | 7.6 High | ||
| Editor SQL Injection in SKT Addons for Elementor <= 4.0 versions. | ||||
| CVE-2026-66619 | 2026-09-17 | 7.6 High | ||
| Administrator SQL Injection in Newsletters <= 4.18 versions. | ||||
