Export limit exceeded: 384559 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (384559 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-79009 | 1 Google | 1 Chrome | 2026-08-28 | 4.3 Medium |
| UI misrepresentation in UI in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML page. (Chromium security severity: Low) | ||||
| CVE-2026-79095 | 1 Google | 1 Chrome | 2026-08-28 | 4.3 Medium |
| Information leak in Payments in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (Chromium security severity: Medium) | ||||
| CVE-2026-79015 | 1 Google | 1 Chrome | 2026-08-28 | 4.3 Medium |
| Improper input validation in ServiceWorker in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Low) | ||||
| CVE-2026-79021 | 1 Google | 1 Chrome | 2026-08-28 | 6.5 Medium |
| Missing authorization in InterestGroups in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass system access restrictions via a crafted PDF file. (Chromium security severity: Low) | ||||
| CVE-2026-79022 | 1 Google | 1 Chrome | 2026-08-28 | 4.3 Medium |
| UI misrepresentation in Transactions Platform in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to potentially spoof UI elements via a crafted HTML page. (Chromium security severity: Low) | ||||
| CVE-2026-79098 | 1 Google | 1 Chrome | 2026-08-28 | 4.3 Medium |
| UI misrepresentation in PermissionElement in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML page. (Chromium security severity: Low) | ||||
| CVE-2026-79104 | 1 Google | 1 Chrome | 2026-08-28 | 5.3 Medium |
| Missing authorization in Sensor in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium) | ||||
| CVE-2026-79105 | 2 Apple, Google | 2 Iphone Os, Chrome | 2026-08-28 | 4.3 Medium |
| Improper input validation in Mobile in Google Chrome on on iOS prior to 152.0.7977.65 allowed a remote attacker to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Low) | ||||
| CVE-2026-79177 | 2 Google, Microsoft | 2 Chrome, Windows | 2026-08-28 | 6.5 Medium |
| Incorrect authorization in Media in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Low) | ||||
| CVE-2026-79191 | 1 Google | 1 Chrome | 2026-08-28 | 3.1 Low |
| Incorrect authorization in SiteIsolation in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium) | ||||
| CVE-2026-79220 | 1 Google | 1 Chrome | 2026-08-28 | 5.3 Medium |
| Information leak in Network in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium) | ||||
| CVE-2026-79234 | 1 Google | 1 Chrome | 2026-08-28 | 6.5 Medium |
| Injection in CSS in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium) | ||||
| CVE-2026-79242 | 1 Google | 1 Chrome | 2026-08-28 | 5.3 Medium |
| Observable discrepancy in HTML in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium) | ||||
| CVE-2026-79246 | 1 Google | 1 Chrome | 2026-08-28 | 6.5 Medium |
| Information leak in DataTransfer in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Low) | ||||
| CVE-2026-79249 | 1 Google | 1 Chrome | 2026-08-28 | 6.5 Medium |
| Code injection in Bisection in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive information via a crafted file. (Chromium security severity: Medium) | ||||
| CVE-2026-81761 | 2026-08-28 | 4.3 Medium | ||
| Subscriber Broken Access Control in WpEvently <= 5.5.0 versions. | ||||
| CVE-2026-78195 | 1 Watchguard | 1 Dimension | 2026-08-28 | N/A |
| Rejecting as a duplicate of CVE-2026-78047 | ||||
| CVE-2026-81759 | 2026-08-28 | 5.4 Medium | ||
| Contributor Broken Access Control in WpEvently <= 5.5.0 versions. | ||||
| CVE-2026-81851 | 1 Watchguard | 1 Fireware Os | 2026-08-28 | N/A |
| A heap-based buffer overflow vulnerability in Fireware OS's iked process allows an authenticated administrator to crash the IKE daemon (iked), resulting in a denial of service, by saving a specially crafted configuration. | ||||
| CVE-2026-78174 | 1 Watchguard | 1 Dimension | 2026-08-28 | N/A |
| WatchGuard Dimension records unredacted session identifiers for logged-in users in its web UI diagnostic log. A low-privileged Dimension Administrator can retrieve this log and extract a Super Administrator's session token while that administrator is logged in, enabling account takeover. | ||||