Export limit exceeded: 389501 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 389501 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (389501 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-87474 | 1 Google | 1 Chrome | 2026-09-09 | 9.6 Critical |
| Use after free in Payments in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High) | ||||
| CVE-2026-69417 | 1 Microsoft | 1 Sharepoint Server | 2026-09-09 | 7.3 High |
| Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. | ||||
| CVE-2026-87476 | 1 Google | 1 Chrome | 2026-09-09 | 6.5 Medium |
| Incorrect authorization in Loader in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium) | ||||
| CVE-2026-87625 | 1 Google | 1 Chrome | 2026-09-09 | 8.8 High |
| Use after free in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to execute arbitrary code inside the sandbox via a crafted Chrome extension. (Chromium security severity: Medium) | ||||
| CVE-2026-87628 | 1 Google | 1 Chrome | 2026-09-09 | 8.3 High |
| Use after free in Cast in Google Chrome prior to 153.0.8010.36 allowed an adjacent attacker to potentially execute arbitrary code outside the sandbox via crafted network traffic. (Chromium security severity: Critical) | ||||
| CVE-2026-87874 | 1 Redhat | 2 Ceph Storage, Openstack | 2026-09-09 | 8.1 High |
| A flaw was found in the memcached cache plugin of the community.general Ansible collection. Although its documentation states that records are stored in JSON format, the plugin performs no explicit serialization and relies on python-memcached, which pickles values on write and unpickles them on read. Because memcached is unauthenticated and cache keys are predictable, an attacker able to reach a network-exposed or shared memcached instance can write a crafted pickle payload that is deserialized and executed on the Ansible controller when the poisoned fact cache is next read, leading to remote code execution. | ||||
| CVE-2026-87823 | 2026-09-09 | 8.2 High | ||
| zstd-jni before 1.5.7-14 performs 32-bit signed bounds checks on three direct-ByteBuffer frame-size native methods, allowing out-of-bounds memory reads via negative or overflowing offsets. Attackers can supply negative offset values near Integer.MIN_VALUE to read unmapped memory, causing JVM termination or extracting arbitrary frame size data from unintended memory locations. | ||||
| CVE-2026-87766 | 1 Redhat | 2 Enterprise Linux, Hummingbird | 2026-09-09 | 8.8 High |
| A flaw was found in bubblewrap. During sandbox setup, creating files or directories under the new root can follow a parent symlink onto the host via /oldroot, writing attacker-chosen paths outside the sandbox as the launching user. This happens before the sandboxed process starts. This issue is GHSA-pxhw-h44j-8pfx. It is fixed in bubblewrap 0.12.0. | ||||
| CVE-2026-87602 | 2026-09-09 | 4.7 Medium | ||
| Out of bounds read in ANGLE in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker to potentially read memory outside the sandbox via a crafted HTML page. (Chromium security severity: Low) | ||||
| CVE-2026-87088 | 2026-09-09 | 7 High | ||
| Tanium addressed an unauthorized code execution vulnerability in Enforce. | ||||
| CVE-2026-87084 | 2026-09-09 | 7.7 High | ||
| Tanium addressed a server-side request forgery vulnerability in Enforce. | ||||
| CVE-2026-87075 | 2026-09-09 | 8.1 High | ||
| Tanium addressed an improper access controls vulnerability in Comply. | ||||
| CVE-2026-87073 | 2026-09-09 | 6.5 Medium | ||
| Tanium addressed an improper access controls vulnerability in Comply. | ||||
| CVE-2026-87072 | 2026-09-09 | 7.1 High | ||
| Tanium addressed an improper access controls vulnerability in Comply. | ||||
| CVE-2026-87048 | 2026-09-09 | 5.4 Medium | ||
| Tanium addressed an improper access controls vulnerability in Comply. | ||||
| CVE-2026-87047 | 2026-09-09 | 6.3 Medium | ||
| Tanium addressed an improper access controls vulnerability in Comply. | ||||
| CVE-2026-87046 | 2026-09-09 | 4.3 Medium | ||
| Tanium addressed an improper access controls vulnerability in Comply. | ||||
| CVE-2026-87037 | 2026-09-09 | 5.4 Medium | ||
| Tanium addressed an improper access controls vulnerability in Comply. | ||||
| CVE-2026-87036 | 2026-09-09 | 8.1 High | ||
| Tanium addressed an improper access controls vulnerability in Comply. | ||||
| CVE-2026-87035 | 2026-09-09 | 4.3 Medium | ||
| Tanium addressed an information disclosure vulnerability in Comply. | ||||