Export limit exceeded: 389808 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (389808 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-87480 | 1 Google | 1 Chrome | 2026-09-09 | 8.3 High |
| Use after free in Printing in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High) | ||||
| CVE-2026-87487 | 1 Google | 1 Chrome | 2026-09-09 | 8.3 High |
| Missing authorization in FileSystem in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium) | ||||
| CVE-2026-87481 | 1 Google | 2 Android, Chrome | 2026-09-09 | 8.3 High |
| Incorrect authorization in WebView in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium) | ||||
| CVE-2026-87582 | 1 Google | 1 Chrome | 2026-09-09 | 8.3 High |
| Confused deputy in DataTransfer in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium) | ||||
| CVE-2026-87613 | 1 Google | 1 Chrome | 2026-09-09 | 9 Critical |
| Incorrect reference resolution in Extensions in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via crafted network traffic. (Chromium security severity: Medium) | ||||
| CVE-2026-87579 | 1 Google | 1 Chrome | 2026-09-09 | 8.8 High |
| Buffer overflow in WebRTC in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium) | ||||
| CVE-2026-87631 | 1 Google | 1 Chrome | 2026-09-09 | 6.5 Medium |
| Missing authorization in DOM in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially leak sensitive information via a crafted HTML page. (Chromium security severity: Low) | ||||
| CVE-2026-87437 | 1 Google | 1 Chrome | 2026-09-09 | 6.5 Medium |
| Information leak in Frames in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to leak sensitive information via a crafted HTML page. (Chromium security severity: Low) | ||||
| CVE-2026-87601 | 1 Google | 1 Chrome | 2026-09-09 | 7.5 High |
| Race condition in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Low) | ||||
| CVE-2026-75861 | 2026-09-09 | 6.5 Medium | ||
| The Ultimate Gift Cards for WooCommerce WordPress plugin before 3.2.10 does not verify that the user redeeming a gift card is its intended recipient, allowing any authenticated user, such as a subscriber, to redeem gift cards belonging to other users, zeroing their balance and crediting the value to themselves. In 3.2.9 an ownership check was added on one of the two affected redemption paths; the one that remains requires a companion Ultimate Gift Cards for WooCommerce WordPress plugin before 3.2.10 from the same vendor to be active. | ||||
| CVE-2026-87572 | 1 Google | 1 Chrome | 2026-09-09 | 8.3 High |
| Injection in DevTools in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High) | ||||
| CVE-2026-87574 | 1 Google | 1 Chrome | 2026-09-09 | 4.3 Medium |
| Information leak in ServiceWorker in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (Chromium security severity: Medium) | ||||
| CVE-2026-80081 | 1 Microsoft | 1 365 Apps | 2026-09-09 | 8.8 High |
| Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code over a network. | ||||
| CVE-2026-78525 | 1 Microsoft | 10 365 Apps, Microsoft 365, Office 2019 and 7 more | 2026-09-09 | 8.8 High |
| Use after free in Microsoft Office Outlook allows an unauthorized attacker to execute code over a network. | ||||
| CVE-2026-87648 | 2 Google, Microsoft | 2 Chrome, Windows | 2026-09-09 | 8.3 High |
| Use after free in ANGLE in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium) | ||||
| CVE-2026-80341 | 2026-09-09 | 5.9 Medium | ||
| The Payment Plugins for PayPal WooCommerce WordPress plugin before 2.0.26 does not verify that a stored payment method belongs to the user attaching it, allowing any authenticated user, such as a subscriber, to bind another customer's stored card to their own account and then charge or delete it. Exploitation requires the attacker to already know the payment provider's identifier for the victim's stored method, which the Payment Plugins for PayPal WooCommerce WordPress plugin before 2.0.26 does not expose. | ||||
| CVE-2026-82184 | 2026-09-09 | 5.3 Medium | ||
| The WPLP Cookie Consent WordPress plugin before 4.4.2 does not have any authorisation or CSRF checks when storing visitor consent state, and the code that does so runs on every front-end page load, allowing unauthenticated attackers to overwrite a site-wide option with arbitrary data. | ||||
| CVE-2026-82848 | 2026-09-09 | 5.3 Medium | ||
| The Masteriyo LMS WordPress plugin before 3.4.0 does not perform any authorization check before returning a course enrolment record over its REST API, allowing unauthenticated users to read any learner's enrolment status, timestamps and course-progress data by walking sequential record identifiers. A related gap lets any enrolled user retrieve other learners' enrolment records as well. | ||||
| CVE-2026-85132 | 2026-09-09 | 4.3 Medium | ||
| The WPLP Cookie Consent WordPress plugin before 4.4.2 does not perform nonce or capability checks on one of its cookie scanner AJAX actions, allowing any authenticated user, such as a subscriber, to read back the automated scan schedule the administrator configured. | ||||
| CVE-2026-85133 | 2026-09-09 | 5.4 Medium | ||
| The WPLP Cookie Consent WordPress plugin before 4.4.2 does not perform nonce or capability checks on several of its settings AJAX actions, allowing any authenticated user, such as a subscriber, to read and destroy scan data belonging to the administrator and to overwrite the WPLP Cookie Consent WordPress plugin before 4.4.2's stored configuration. | ||||