Export limit exceeded: 402796 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Export limit exceeded: 402796 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Search

Search Results (402796 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-106246 1 Google 1 Chrome 2026-10-07 5.4 Medium
Incorrect authorization in Browser in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to spoof address bar via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-106411 1 Google 1 Chrome 2026-10-07 8.8 High
Use after free in Parser in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
CVE-2026-106247 1 Google 1 Chrome 2026-10-07 8.3 High
Buffer overflow in ANGLE in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Low)
CVE-2026-106248 1 Google 1 Chrome 2026-10-07 8.8 High
Use after free in Bindings in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
CVE-2026-106249 1 Google 2 Android, Chrome 2026-10-07 8.8 High
Incorrect authorization in Autofill in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Low)
CVE-2026-106412 2 Apple, Google 2 Macos, Chrome 2026-10-07 8.3 High
Race condition in Core in Google Chrome on on Mac prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
CVE-2026-106328 1 Google 2 Android, Chrome 2026-10-07 5.9 Medium
Incorrect authorization in PDF in Google Chrome on on Android prior to 155.0.8059.39 allowed a local attacker leveraging social engineering to obtain sensitive information via a co-installed app. (Chromium security severity: Medium)
CVE-2026-106423 1 Google 1 Chrome 2026-10-07 8.8 High
Use after free in Media in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
CVE-2026-106337 1 Google 2 Android, Chrome 2026-10-07 5.4 Medium
UI misrepresentation in UI in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-106426 1 Google 1 Chrome 2026-10-07 8.3 High
Race condition in Fonts in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
CVE-2026-106338 1 Google 2 Android, Chrome 2026-10-07 5.4 Medium
UI misrepresentation in PictureInPicture in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker to spoof address bar via a crafted HTML page. (Chromium security severity: Low)
CVE-2026-106321 1 Google 1 Chrome 2026-10-07 4.3 Medium
Information leak in Editing in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to leak sensitive information via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-106320 1 Google 1 Chrome 2026-10-07 4.2 Medium
Use of released resource in UI in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to spoof UI elements via a crafted HTML page. (Chromium security severity: Low)
CVE-2026-106329 1 Google 1 Chrome 2026-10-07 9.6 Critical
Incorrect authorization in FileSystem in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
CVE-2026-106325 1 Google 1 Chrome 2026-10-07 4.3 Medium
Incorrect reference resolution in Core in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)
CVE-2026-45161 2026-10-07 5.4 Medium
wger is a free, open-source workout and fitness manager. Prior to version 2.6, the `trainer_login` view in wger accepts GET requests and executes `django_login()` without any CSRF protection, because Django's `CsrfViewMiddleware` only enforces tokens on unsafe methods (POST/PUT/PATCH/DELETE). An attacker can embed a single `<img>` tag on a malicious page; when an authenticated trainer loads that page, their browser auto-issues the GET with the session cookie, forcibly rebinding the trainer's session to an arbitrary user account. Version 2.6 fixes the issue.
CVE-2026-107181 1 Telegram 1 Telegram Desktop 2026-10-07 8.1 High
Telegram Desktop before 7.2.9 contains an IPC record-separator injection vulnerability in Core::Sandbox that allows remote attackers to inject OPEN: records via crafted tg:// links containing unescaped semicolons. Attackers can reach the interpret: scheme handler to upload local files, including tdata session keys, to an attacker channel, enabling account takeover.
CVE-2026-43976 2026-10-07 7.1 High
wger is a free, open-source workout and fitness manager. Prior to version 2.6, five gym management views in wger apply a flawed gym-scope guard (`gym_a != gym_b`) that silently passes when both operands are `None`. A trainer with `gym.gym_trainer` and `gym.add_adminusernote` permissions and no gym assignment (`gym=None`) can read private admin notes, uploaded documents, gym contracts, user configuration, and user permission data for **any other unaffiliated user** on the instance. The subsequent querysets filter only on the attacker-supplied `member_id` with no secondary gym-scoped validation, so all records are disclosed. Version 2.6 fixes the issue.
CVE-2026-106333 1 Google 1 Chrome 2026-10-07 5.4 Medium
Incorrect authorization in Input in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-106059 1 Gitahead 1 Gitahead 2026-10-07 8.8 High
GitAhead through 2.7.1 on macOS contains a command injection vulnerability that allows attackers to execute shell commands by crafting repository filenames interpolated unescaped into the Show in Finder AppleScript. Attackers can commit a file whose path contains a double quote followed by a do shell script payload, which runs as the victim user when Show in Finder is chosen.