| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-87072 | Hig | 0.46 | 7.1 | 0.00 | Sep 9, 2026 | Tanium addressed an improper access controls vulnerability in Comply. | ||
| CVE-2026-87048 | Med | 0.35 | 5.4 | 0.00 | Sep 9, 2026 | Tanium addressed an improper access controls vulnerability in Comply. | ||
| CVE-2026-87047 | Med | 0.41 | 6.3 | 0.00 | Sep 9, 2026 | Tanium addressed an improper access controls vulnerability in Comply. | ||
| CVE-2026-87046 | Med | 0.28 | 4.3 | 0.00 | Sep 9, 2026 | Tanium addressed an improper access controls vulnerability in Comply. | ||
| CVE-2026-87037 | Med | 0.35 | 5.4 | 0.00 | Sep 9, 2026 | Tanium addressed an improper access controls vulnerability in Comply. | ||
| CVE-2026-87036 | Hig | 0.53 | 8.1 | 0.00 | Sep 9, 2026 | Tanium addressed an improper access controls vulnerability in Comply. | ||
| CVE-2026-87035 | Med | 0.28 | 4.3 | 0.00 | Sep 9, 2026 | Tanium addressed an information disclosure vulnerability in Comply. | ||
| CVE-2026-87034 | Hig | 0.54 | 8.3 | 0.00 | Sep 9, 2026 | Tanium addressed a SQL injection vulnerability in Comply. | ||
| CVE-2026-87033 | Med | 0.35 | 5.4 | 0.00 | Sep 9, 2026 | Tanium addressed an improper access controls vulnerability in Comply. | ||
| CVE-2026-87032 | Med | 0.28 | 4.3 | 0.00 | Sep 9, 2026 | Tanium addressed an information disclosure vulnerability in Tanium Server. | ||
| CVE-2026-87030 | Hig | 0.55 | 8.5 | 0.00 | Sep 9, 2026 | Tanium addressed a path traversal vulnerability in Comply. | ||
| CVE-2026-87025 | Med | 0.35 | 5.4 | 0.00 | Sep 9, 2026 | Tanium addressed an improper access controls vulnerability in Comply. | ||
| CVE-2026-87023 | Hig | 0.55 | 8.5 | 0.00 | Sep 9, 2026 | Tanium addressed a path traversal vulnerability in Comply. | ||
| CVE-2026-87021 | Hig | 0.47 | 7.2 | 0.00 | Sep 9, 2026 | Tanium addressed an unauthorized code execution vulnerability in Comply. | ||
| CVE-2026-87019 | Med | 0.28 | 4.3 | 0.00 | Sep 9, 2026 | Tanium addressed an improper access controls vulnerability in Comply. | ||
| CVE-2026-76801 | Hig | 0.57 | 8.8 | 0.01 | Sep 9, 2026 | The FireBox – WooCommerce Popup Builder, Exit Intent Popup, Email Optin & Cart Abandonment plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 3.1.10 via the value function. This is due to a trivially bypassable regex blacklist in… | ||
| CVE-2026-15667 | Hig | 0.49 | 7.5 | 0.01 | Sep 9, 2026 | The Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered) plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.1.22 via the 'event_layout' parameter parameter. This makes it possible for authenticated… | ||
| CVE-2026-15406 | Hig | 0.49 | 7.5 | 0.01 | Sep 9, 2026 | The Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered) plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.1.22 via the 'event_layout' parameter parameter. This makes it possible for authenticated… | ||
| CVE-2026-14892 | Med | 0.28 | 4.3 | 0.00 | Sep 9, 2026 | Tanium addressed an improper access controls vulnerability in Tanium Server. | ||
| CVE-2026-14505 | Med | 0.43 | 6.6 | 0.00 | Sep 9, 2026 | Tanium addressed a path traversal vulnerability in Tanium Data Service. | ||
| CVE-2026-13709 | Med | 0.42 | 6.4 | 0.00 | Sep 9, 2026 | The Graphina – Charts and Graphs For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'iq_tree_tree_chart_template' Widget Setting in all versions up to, and including, 3.1.11 due to insufficient input sanitization and output escaping. This makes… | ||
| CVE-2026-13359 | Hig | 0.40 | 7.2 | 0.00 | Sep 9, 2026 | The Contact Form to DB by BestWebSoft – Messages Database Plugin For WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via cntctfrm_contact_dropdown Parameter in all versions up to, and including, 1.7.5 due to insufficient input sanitization and… | ||
| CVE-2026-12956 | Med | 0.34 | 5.3 | 0.00 | Sep 9, 2026 | The WP Event Solution (Eventin) plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 4.1.22 via the create_item() handler for the /wp-json/eventin/v2/orders REST endpoint. The endpoint's create_item_permissions_check() function only… | ||
| CVE-2026-87724 | Med | 0.35 | 6.5 | 0.00 | Sep 9, 2026 | Tor before 0.4.9.12 interprets the CC_RESPONSE extension even when CC_REQUEST was not sent, which allows remote attackers to cause a denial of service (crash) because of corrupted congestion-control state. This is TROVE-2026-032. | ||
| CVE-2026-87083 | Med | 0.29 | 5.5 | 0.00 | Sep 9, 2026 | A weakness has been identified in tile-ai tilelang up to 0.1.14. This impacts the function KernelCache._load_kernel_from_disk of the file tilelang/cache/kernel_cache.py of the component Kernel Cache. Executing a manipulation can lead to deserialization. The attack may be… | ||
| CVE-2026-87658 | Med | 0.28 | 4.3 | 0.00 | Sep 9, 2026 | Information leak in Extensions in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to obtain cross-origin data via a crafted Chrome extension. (Chromium security severity: Medium) | ||
| CVE-2026-87657 | Low | 0.20 | 3.1 | 0.00 | Sep 9, 2026 | Use after free in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to read memory inside the sandbox via a crafted HTML page. (Chromium security severity: Medium) | ||
| CVE-2026-87656 | Med | 0.35 | 5.4 | 0.00 | Sep 9, 2026 | Improper state validation in Safebrowsing in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Low) | ||
| CVE-2026-87655 | Med | 0.35 | 5.4 | 0.00 | Sep 9, 2026 | Clickjacking in Downloads in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium) | ||
| CVE-2026-87654 | Cri | 0.62 | 9.6 | 0.00 | Sep 9, 2026 | Buffer overflow in ANGLE in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High) | ||
| CVE-2026-87653 | Med | 0.35 | 5.4 | 0.00 | Sep 9, 2026 | UI misrepresentation in FullScreen in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker to spoof UI elements via a crafted HTML page. (Chromium security severity: Low) | ||
| CVE-2026-87652 | Low | 0.20 | 3.1 | 0.00 | Sep 9, 2026 | Incorrect authorization in PushAPI in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium) | ||
| CVE-2026-87651 | Med | 0.28 | 4.3 | 0.00 | Sep 9, 2026 | Incorrect authorization in Paint in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (Chromium security severity: High) | ||
| CVE-2026-87650 | Cri | 0.62 | 9.6 | 0.00 | Sep 9, 2026 | Out of bounds read in WebGL in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High) | ||
| CVE-2026-87649 | Med | 0.35 | 5.4 | 0.00 | Sep 9, 2026 | UI misrepresentation in Downloads in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium) | ||
| CVE-2026-87648 | Hig | 0.54 | 8.3 | 0.00 | Sep 9, 2026 | Use after free in ANGLE in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium) | ||
| CVE-2026-87647 | Low | 0.22 | 3.4 | 0.00 | Sep 9, 2026 | Uninitialized resource in GPU in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: High) | ||
| CVE-2026-87646 | Cri | 0.62 | 9.6 | 0.00 | Sep 9, 2026 | Use after free in Web Authentication in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High) | ||
| CVE-2026-87645 | Med | 0.35 | 5.4 | 0.00 | Sep 9, 2026 | Improper state validation in Safebrowsing in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium) | ||
| CVE-2026-87644 | Hig | 0.54 | 8.3 | 0.00 | Sep 9, 2026 | Incorrect authorization in Views in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium… | ||
| CVE-2026-87643 | Cri | 0.62 | 9.6 | 0.00 | Sep 9, 2026 | Integer overflow in GPU in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium) | ||
| CVE-2026-87642 | Med | 0.28 | 4.3 | 0.00 | Sep 9, 2026 | Uninitialized resource in WebGL in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium) | ||
| CVE-2026-87641 | Med | 0.27 | 4.2 | 0.00 | Sep 9, 2026 | Race condition in Browser in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium) | ||
| CVE-2026-87640 | Med | 0.40 | 6.1 | 0.00 | Sep 9, 2026 | Out of bounds read in WebView in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: Medium) | ||
| CVE-2026-87639 | Hig | 0.54 | 8.3 | 0.00 | Sep 9, 2026 | Use after free in WebPackaging in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High) | ||
| CVE-2026-87638 | Cri | 0.62 | 9.6 | 0.00 | Sep 9, 2026 | Out of bounds write in Media in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium) | ||
| CVE-2026-87637 | Cri | 0.62 | 9.6 | 0.00 | Sep 9, 2026 | Use after free in Extensions in Google Chrome on on Mac prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium) | ||
| CVE-2026-87636 | Hig | 0.57 | 8.8 | 0.00 | Sep 9, 2026 | Type confusion in XML in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium) | ||
| CVE-2026-87635 | Med | 0.35 | 5.4 | 0.00 | Sep 9, 2026 | UI misrepresentation in Payments in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium) | ||
| CVE-2026-87634 | Cri | 0.62 | 9.6 | 0.00 | Sep 9, 2026 | Use after free in WebPackaging in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Low) |
- risk 0.46cvss 7.1epss 0.00
Tanium addressed an improper access controls vulnerability in Comply.
- risk 0.35cvss 5.4epss 0.00
Tanium addressed an improper access controls vulnerability in Comply.
- risk 0.41cvss 6.3epss 0.00
Tanium addressed an improper access controls vulnerability in Comply.
- risk 0.28cvss 4.3epss 0.00
Tanium addressed an improper access controls vulnerability in Comply.
- risk 0.35cvss 5.4epss 0.00
Tanium addressed an improper access controls vulnerability in Comply.
- risk 0.53cvss 8.1epss 0.00
Tanium addressed an improper access controls vulnerability in Comply.
- risk 0.28cvss 4.3epss 0.00
Tanium addressed an information disclosure vulnerability in Comply.
- risk 0.54cvss 8.3epss 0.00
Tanium addressed a SQL injection vulnerability in Comply.
- risk 0.35cvss 5.4epss 0.00
Tanium addressed an improper access controls vulnerability in Comply.
- risk 0.28cvss 4.3epss 0.00
Tanium addressed an information disclosure vulnerability in Tanium Server.
- risk 0.55cvss 8.5epss 0.00
Tanium addressed a path traversal vulnerability in Comply.
- risk 0.35cvss 5.4epss 0.00
Tanium addressed an improper access controls vulnerability in Comply.
- risk 0.55cvss 8.5epss 0.00
Tanium addressed a path traversal vulnerability in Comply.
- risk 0.47cvss 7.2epss 0.00
Tanium addressed an unauthorized code execution vulnerability in Comply.
- risk 0.28cvss 4.3epss 0.00
Tanium addressed an improper access controls vulnerability in Comply.
- risk 0.57cvss 8.8epss 0.01
The FireBox – WooCommerce Popup Builder, Exit Intent Popup, Email Optin & Cart Abandonment plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 3.1.10 via the value function. This is due to a trivially bypassable regex blacklist in…
- risk 0.49cvss 7.5epss 0.01
The Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered) plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.1.22 via the 'event_layout' parameter parameter. This makes it possible for authenticated…
- risk 0.49cvss 7.5epss 0.01
The Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered) plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.1.22 via the 'event_layout' parameter parameter. This makes it possible for authenticated…
- risk 0.28cvss 4.3epss 0.00
Tanium addressed an improper access controls vulnerability in Tanium Server.
- risk 0.43cvss 6.6epss 0.00
Tanium addressed a path traversal vulnerability in Tanium Data Service.
- risk 0.42cvss 6.4epss 0.00
The Graphina – Charts and Graphs For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'iq_tree_tree_chart_template' Widget Setting in all versions up to, and including, 3.1.11 due to insufficient input sanitization and output escaping. This makes…
- risk 0.40cvss 7.2epss 0.00
The Contact Form to DB by BestWebSoft – Messages Database Plugin For WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via cntctfrm_contact_dropdown Parameter in all versions up to, and including, 1.7.5 due to insufficient input sanitization and…
- risk 0.34cvss 5.3epss 0.00
The WP Event Solution (Eventin) plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 4.1.22 via the create_item() handler for the /wp-json/eventin/v2/orders REST endpoint. The endpoint's create_item_permissions_check() function only…
- risk 0.35cvss 6.5epss 0.00
Tor before 0.4.9.12 interprets the CC_RESPONSE extension even when CC_REQUEST was not sent, which allows remote attackers to cause a denial of service (crash) because of corrupted congestion-control state. This is TROVE-2026-032.
- risk 0.29cvss 5.5epss 0.00
A weakness has been identified in tile-ai tilelang up to 0.1.14. This impacts the function KernelCache._load_kernel_from_disk of the file tilelang/cache/kernel_cache.py of the component Kernel Cache. Executing a manipulation can lead to deserialization. The attack may be…
- risk 0.28cvss 4.3epss 0.00
Information leak in Extensions in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to obtain cross-origin data via a crafted Chrome extension. (Chromium security severity: Medium)
- risk 0.20cvss 3.1epss 0.00
Use after free in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to read memory inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
- risk 0.35cvss 5.4epss 0.00
Improper state validation in Safebrowsing in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Low)
- risk 0.35cvss 5.4epss 0.00
Clickjacking in Downloads in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)
- risk 0.62cvss 9.6epss 0.00
Buffer overflow in ANGLE in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
- risk 0.35cvss 5.4epss 0.00
UI misrepresentation in FullScreen in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker to spoof UI elements via a crafted HTML page. (Chromium security severity: Low)
- risk 0.20cvss 3.1epss 0.00
Incorrect authorization in PushAPI in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)
- risk 0.28cvss 4.3epss 0.00
Incorrect authorization in Paint in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (Chromium security severity: High)
- risk 0.62cvss 9.6epss 0.00
Out of bounds read in WebGL in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
- risk 0.35cvss 5.4epss 0.00
UI misrepresentation in Downloads in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)
- risk 0.54cvss 8.3epss 0.00
Use after free in ANGLE in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
- risk 0.22cvss 3.4epss 0.00
Uninitialized resource in GPU in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: High)
- risk 0.62cvss 9.6epss 0.00
Use after free in Web Authentication in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
- risk 0.35cvss 5.4epss 0.00
Improper state validation in Safebrowsing in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)
- risk 0.54cvss 8.3epss 0.00
Incorrect authorization in Views in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium…
- risk 0.62cvss 9.6epss 0.00
Integer overflow in GPU in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
- risk 0.28cvss 4.3epss 0.00
Uninitialized resource in WebGL in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
- risk 0.27cvss 4.2epss 0.00
Race condition in Browser in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)
- risk 0.40cvss 6.1epss 0.00
Out of bounds read in WebView in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
- risk 0.54cvss 8.3epss 0.00
Use after free in WebPackaging in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
- risk 0.62cvss 9.6epss 0.00
Out of bounds write in Media in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
- risk 0.62cvss 9.6epss 0.00
Use after free in Extensions in Google Chrome on on Mac prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
- risk 0.57cvss 8.8epss 0.00
Type confusion in XML in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
- risk 0.35cvss 5.4epss 0.00
UI misrepresentation in Payments in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)
- risk 0.62cvss 9.6epss 0.00
Use after free in WebPackaging in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Low)