Export limit exceeded: 403070 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (403070 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-106183 | 1 Google | 1 Chrome | 2026-10-07 | 5.9 Medium |
| Missing authorization in Chromoting in Google Chrome on on Windows prior to 155.0.8059.39 allowed a remote attacker to obtain sensitive information via crafted network traffic. (Chromium security severity: Medium) | ||||
| CVE-2026-106355 | 1 Google | 1 Chrome | 2026-10-07 | 5.3 Medium |
| Missing authorization in Media in Google Chrome on on Windows prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to obtain sensitive information via a crafted HTML page. (Chromium security severity: Low) | ||||
| CVE-2026-106357 | 1 Google | 1 Chrome | 2026-10-07 | 8.8 High |
| Use after free in WebRTC in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High) | ||||
| CVE-2026-106181 | 1 Google | 1 Chrome | 2026-10-07 | 5.3 Medium |
| Incorrect reference resolution in DevTools in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium) | ||||
| CVE-2026-106422 | 1 Google | 1 Chrome | 2026-10-07 | 4.3 Medium |
| Incorrect authorization in API in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to bypass web origin policy via a crafted HTML page. (Chromium security severity: Low) | ||||
| CVE-2026-106331 | 1 Google | 1 Chrome | 2026-10-07 | N/A |
| Improper input validation in Extensions in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to bypass web origin policy into a privileged page via a crafted Chrome extension. (Chromium security severity: Low) | ||||
| CVE-2026-106211 | 1 Google | 1 Chrome | 2026-10-07 | 9.6 Critical |
| Use after free in TabStrip in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High) | ||||
| CVE-2026-106274 | 1 Google | 1 Chrome | 2026-10-07 | 8.8 High |
| Incorrect reference resolution in Browser in Google Chrome on on Mac prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium) | ||||
| CVE-2026-106196 | 1 Google | 1 Chrome | 2026-10-07 | N/A |
| Missing authorization in Navigation in Google Chrome on on iOS prior to 155.0.8059.39 allowed a remote attacker to bypass web origin policy into a privileged page via a crafted HTML page. (Chromium security severity: Medium) | ||||
| CVE-2026-106352 | 1 Google | 1 Chrome | 2026-10-07 | 8.8 High |
| Incorrect authorization in WebProtect in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium) | ||||
| CVE-2026-106384 | 1 Google | 1 Chrome | 2026-10-07 | 5.3 Medium |
| Missing authorization in SiteIsolation in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium) | ||||
| CVE-2026-55655 | 3 Openbsd, Openssh, Redhat | 10 Openssh, Openssh, Enterprise Linux and 7 more | 2026-10-07 | 5 Medium |
| A flaw was found in OpenSSH. A local unprivileged attacker on a Linux client host can hijack client-side X11 forwarding connections. This is possible by pre-binding the preferred abstract X socket name when X11 forwarding is enabled and a local UNIX-domain X socket is used. A successful attack can compromise the confidentiality of forwarded X11 traffic, including sensitive window contents and input, and may allow some manipulation of the forwarded session. | ||||
| CVE-2026-55653 | 3 Openbsd, Openssh, Redhat | 10 Openssh, Openssh, Enterprise Linux and 7 more | 2026-10-07 | 4.3 Medium |
| A flaw was found in OpenSSH. A malicious SSH server can exploit a double free vulnerability in the Diffie-Hellman Group Exchange (DH-GEX) client path. This occurs during FIPS (Federal Information Processing Standards) mode known-group validation when the client processes attacker-controlled DH-GEX group parameters. Successful exploitation leads to client-side process termination, resulting in a Denial of Service (DoS). | ||||
| CVE-2026-106346 | 1 Google | 1 Chrome | 2026-10-07 | 8.8 High |
| Improper state validation in DevTools in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High) | ||||
| CVE-2026-106200 | 1 Google | 1 Chrome | 2026-10-07 | 8.8 High |
| Use after free in Track in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High) | ||||
| CVE-2026-106208 | 1 Google | 1 Chrome | 2026-10-07 | N/A |
| Missing authorization in API in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to leak sensitive information via a crafted Chrome extension. (Chromium security severity: Medium) | ||||
| CVE-2026-106359 | 1 Google | 1 Chrome | 2026-10-07 | N/A |
| Confused deputy in DeviceBoundSessionCredentials in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to bypass web origin policy via a crafted HTML page. (Chromium security severity: Low) | ||||
| CVE-2026-106353 | 1 Google | 1 Chrome | 2026-10-07 | N/A |
| Improper input validation in Mobile in Google Chrome on on iOS prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to bypass web origin policy via a co-installed app. (Chromium security severity: Low) | ||||
| CVE-2026-106362 | 1 Google | 1 Chrome | 2026-10-07 | N/A |
| Missing authorization in DevTools in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to bypass web origin policy via a crafted Chrome extension. (Chromium security severity: Low) | ||||
| CVE-2026-106368 | 1 Google | 1 Chrome | 2026-10-07 | 5.4 Medium |
| UI misrepresentation in UI in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker to spoof UI elements via a crafted HTML page. (Chromium security severity: Low) | ||||