VYPR

CVEs

37,811 total · page 26 of 757

  • CVE-2026-87544CriSep 9, 2026
    risk 0.64cvss 9.8epss 0.00

    Incorrect authorization in Extensions in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass system access restrictions into a privileged page via a crafted HTML page. (Chromium security severity: Low)

  • CVE-2026-87534CriSep 9, 2026
    risk 0.64cvss 9.8epss 0.00

    Missing authorization in WebView in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass system access restrictions via crafted network traffic. (Chromium security severity: Medium)

  • CVE-2026-87529CriSep 9, 2026
    risk 0.62cvss 9.6epss 0.01

    Numeric truncation error in Media in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-87528CriSep 9, 2026
    risk 0.62cvss 9.6epss 0.00

    Type confusion in Rust in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-87527CriSep 9, 2026
    risk 0.62cvss 9.6epss 0.01

    Buffer overflow in WebGL in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)

  • CVE-2026-87526CriSep 9, 2026
    risk 0.62cvss 9.6epss 0.00

    Use after free in Passwords in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via UI Interaction. (Chromium security severity: Medium)

  • CVE-2026-87520CriSep 9, 2026
    risk 0.62cvss 9.6epss 0.00

    Use after free in Dawn in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

  • CVE-2026-87512CriSep 9, 2026
    risk 0.62cvss 9.6epss 0.00

    Use after free in ANGLE in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

  • CVE-2026-87504CriSep 9, 2026
    risk 0.62cvss 9.6epss 0.00

    Use after free in Core in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox via a crafted Chrome extension. (Chromium security severity: Medium)

  • CVE-2026-87500CriSep 9, 2026
    risk 0.62cvss 9.6epss 0.00

    Improper validation of array index in ANGLE in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

  • CVE-2026-87494CriSep 9, 2026
    risk 0.62cvss 9.6epss 0.00

    Use after free in Browser in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-87492CriSep 9, 2026
    risk 0.62cvss 9.6epss 0.00

    Incorrect authorization in DevTools in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

  • CVE-2026-87488CriSep 9, 2026
    risk 0.62cvss 9.6epss 0.00

    Use after free in WebGL in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)

  • CVE-2026-87474CriSep 9, 2026
    risk 0.62cvss 9.6epss 0.00

    Use after free in Payments in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

  • CVE-2026-87470CriSep 9, 2026
    risk 0.62cvss 9.6epss 0.00

    Improper quantity validation in Tint in Google Chrome on on Mac prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-87464CriSep 9, 2026
    risk 0.62cvss 9.6epss 0.01

    Use after free in WebGL in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)

  • CVE-2026-87455CriSep 9, 2026
    risk 0.62cvss 9.6epss 0.00

    Use after free in Aura in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-87448CriSep 9, 2026
    risk 0.62cvss 9.6epss 0.00

    Use after free in DevTools in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Low)

  • CVE-2026-87438CriSep 9, 2026
    risk 0.62cvss 9.6epss 0.00

    Out of bounds write in WebGL in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)

  • CVE-2026-53939CriSep 9, 2026
    risk 0.52cvss 9.1epss 0.00

    OpenIDC/cjose is a C library implementing the Javascript Object Signing and Encryption (JOSE). In versions 0.6.1 through 0.6.2.5, when cjose encrypts a JWE using an AES-CBC-HMAC content-encryption algorithm (`A128CBC-HS256`, `A192CBC-HS384`, or `A256CBC-HS512`) together with any…

  • CVE-2026-53581CriSep 8, 2026
    risk 0.52cvss 9.0epss 0.00

    OPNsense is a FreeBSD based firewall and routing platform. Prior to version 26.1.9 of opnsense/core and version 26.4_20 of BE/opnsense/core, a path traversal vulnerability in the NTP configuration module allows an attacker to overwrite arbitrary files on the system as the root…

  • CVE-2026-85982CriSep 8, 2026
    risk 0.59cvss 9.0epss 0.00

    The Auth0 AD/LDAP Connector is vulnerable to stored Cross-Site Scripting (XSS) issues due to improper HTML encoding of data in search results and updater log content displayed in the admin panel. An authenticated user with privileges to modify directory attributes, or a…

  • CVE-2026-86464CriSep 8, 2026
    risk 0.57cvss —epss 0.01

    In the current development version of Eclipse aeriOS, for which no official release has yet been published, the Identity Manager (IdM) deployment included insecure default configurations and credentials for security-sensitive services. The Helm chart exposed the Keycloak…

  • CVE-2026-84869CriKEVSep 8, 2026
    risk 0.76cvss 9.9epss 0.01

    A condition in the ScreenConnect client may allow files to be transferred and executed through an active remote session without authorization or Host confirmation in certain circumstances. ScreenConnect servers are not impacted.

  • CVE-2026-84197CriSep 8, 2026
    risk 0.60cvss —epss 0.00

    In Eclipse Ditto's Node.js JavaScript client, all released versions of @eclipse-ditto/ditto-javascript-client-node from 2.0.0 to 3.9.0 and of its predecessor package @eclipse-ditto/ditto-javascript-client-node_1.0 from 1.0.0 to 2.1.0, the WebSocket transport hard-codes…

  • CVE-2026-75746CriSep 8, 2026
    risk 0.59cvss 9.1epss 0.01

    ColdFusion is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker with high privileges could exploit this vulnerability to…

  • CVE-2026-48273CriSep 8, 2026
    risk 0.64cvss 9.9epss 0.01

    ColdFusion is affected by an Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') vulnerability that could result in arbitrary code execution in the context of the current user. A low-privileged attacker could exploit this vulnerability to…

  • CVE-2026-19232CriSep 8, 2026
    risk 0.64cvss 9.9epss 0.01

    Adobe Experience Manager is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user, potentially gaining elevated access or control over the victim's account or session. A low-privileged attacker could…

  • CVE-2026-82004CriSep 8, 2026
    risk 0.65cvss 10.0epss 0.03

    Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability…

  • CVE-2026-76201CriSep 8, 2026
    risk 0.60cvss 9.3epss 0.01

    Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the…

  • CVE-2026-76200CriSep 8, 2026
    risk 0.60cvss 9.3epss 0.01

    Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the…

  • CVE-2026-66302CriSep 8, 2026
    risk 0.64cvss 9.8epss 0.01

    External control of file name or path in Skype for Business allows an unauthorized attacker to execute code over a network.

  • CVE-2026-58822CriSep 8, 2026
    risk 0.64cvss 9.8epss 0.00

    In multiple functions of ftsmooth.c, there is a possible memory safety issue due to improper casting. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2026-49921CriSep 8, 2026
    risk 0.64cvss 9.8epss 0.00

    In multiple locations, there is a possible memory safety issue due to a heap buffer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2026-28606CriSep 8, 2026
    risk 0.64cvss 9.8epss 0.00

    In handleBondStateChanged of AdapterService.java, there is a possible way to skip pairing due to a logic error in the code. This could lead to remote escalation of privilege without user consent with no additional execution privileges needed. User interaction is not needed for…

  • CVE-2026-83941CriSep 8, 2026
    risk 0.64cvss 9.9epss 0.01

    Missing authorization in Entra ID allows an authorized attacker to elevate privileges over a network.

  • CVE-2026-81376CriSep 8, 2026
    risk 0.62cvss 9.6epss 0.01

    Incomplete comparison with missing factors in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network.

  • CVE-2026-78509CriSep 8, 2026
    risk 0.64cvss 9.8epss 0.01

    Heap-based buffer overflow in Microsoft Office Outlook allows an unauthorized attacker to execute code over a network.

  • CVE-2026-78445CriSep 8, 2026
    risk 0.64cvss 9.8epss 0.01

    Use after free in Windows Services for NFS ONCRPC XDR Driver allows an unauthorized attacker to execute code over a network.

  • CVE-2026-77493CriSep 8, 2026
    risk 0.64cvss 9.8epss 0.01

    Double free in Microsoft Graphics Component allows an unauthorized attacker to execute code over a network.

  • CVE-2026-73025CriSep 8, 2026
    risk 0.64cvss 9.8epss 0.01

    Weak authentication in Windows iSCSI allows an unauthorized attacker to bypass a security feature over a network.

  • CVE-2026-73010CriSep 8, 2026
    risk 0.64cvss 9.8epss 0.01

    Use after free in Windows Failover Cluster allows an unauthorized attacker to execute code over a network.

  • CVE-2026-73009CriSep 8, 2026
    risk 0.64cvss 9.8epss 0.01

    Use after free in Windows Secure Socket Tunneling Protocol (SSTP) allows an unauthorized attacker to execute code over a network.

  • CVE-2026-72983CriSep 8, 2026
    risk 0.64cvss 9.8epss 0.01

    Use after free in Windows Internet Connection Sharing (ICS) allows an unauthorized attacker to execute code over a network.

  • CVE-2026-72982CriSep 8, 2026
    risk 0.64cvss 9.8epss 0.01

    Stack-based buffer overflow in Windows Netlogon allows an unauthorized attacker to execute code over a network.

  • CVE-2026-72979CriSep 8, 2026
    risk 0.64cvss 9.8epss 0.01

    Use after free in Windows DHCP Server allows an unauthorized attacker to execute code over a network.

  • CVE-2026-70296CriSep 8, 2026
    risk 0.64cvss 9.8epss 0.01

    Out-of-bounds write in Windows Imaging Component allows an unauthorized attacker to execute code over a network.

  • CVE-2026-69910CriSep 8, 2026
    risk 0.64cvss 9.8epss 0.01

    Stack-based buffer overflow in Windows Hyper-V allows an unauthorized attacker to execute code over a network.

  • CVE-2026-69854CriSep 8, 2026
    risk 0.59cvss 9.0epss 0.01

    Improper authentication in Spring Cloud Azure allows an unauthorized attacker to elevate privileges over a network.

  • CVE-2026-69845CriSep 8, 2026
    risk 0.64cvss 9.8epss 0.01

    Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over a network.