Export limit exceeded: 364829 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 364829 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (364829 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-79013 | 1 Google | 1 Chrome | 2026-08-25 | N/A |
| Improper input validation in Sync in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive information via crafted network traffic. (Chromium security severity: Medium) | ||||
| CVE-2026-24262 | 1 Nvidia | 1 Dgx Spark | 2026-08-25 | 8.2 High |
| NVIDIA DGX Spark contains a vulnerability in the system firmware, where a privileged attacker could be able to cause an out-of-bounds write. A successful exploit of this vulnerability may lead to code execution, escalation of privileges, denial of service, information disclosure, and data tampering. | ||||
| CVE-2026-78963 | 1 Google | 1 Chrome | 2026-08-25 | N/A |
| Improper input validation in Media in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium) | ||||
| CVE-2026-78950 | 1 Google | 1 Chrome | 2026-08-25 | N/A |
| Integer overflow in WebRTC in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Low) | ||||
| CVE-2026-78896 | 1 Google | 1 Chrome | 2026-08-25 | N/A |
| Information leak in StorageAccessAPI in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (Chromium security severity: Low) | ||||
| CVE-2026-78980 | 1 Google | 1 Chrome | 2026-08-25 | N/A |
| Improper input validation in ReaderMode in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to bypass web origin policy into a privileged page via a crafted HTML page. (Chromium security severity: Low) | ||||
| CVE-2026-78957 | 1 Google | 1 Chrome | 2026-08-25 | N/A |
| Information leak in Mobile in Google Chrome on on iOS prior to 152.0.7977.65 allowed a local attacker to obtain sensitive information via a crafted file. (Chromium security severity: Low) | ||||
| CVE-2026-65086 | 2026-08-25 | 6.8 Medium | ||
| NVIDIA OpenShell for Linux contains a vulnerability in its sandbox exec handler, where an attacker could cause an OS command injection. A successful exploit of this vulnerability might lead to code execution, information disclosure, and data tampering. | ||||
| CVE-2026-15089 | 1 Drupal | 1 Commerce Guest Registration | 2026-08-25 | 9.1 Critical |
| Vulnerability in Drupal Commerce guest registration. This issue affects Commerce guest registration versions: *.*. | ||||
| CVE-2026-15917 | 2026-08-25 | N/A | ||
| Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Drupal core allows Cross-Site Scripting (XSS). This issue affects Drupal core versions: from 11.3.0 to 11.3.14, from 11.4.0 to 11.4.4, from 0.0.0 to 11.2.*. | ||||
| CVE-2026-16638 | 2026-08-25 | N/A | ||
| Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Media Folders allows Stored XSS. This issue affects Media Folders versions: from 0.0.0 to 1.0.8. | ||||
| CVE-2026-16639 | 2026-08-25 | N/A | ||
| Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Internationalization Single Sign-On allows Authentication Bypass. This issue affects Internationalization Single Sign-On versions: from 0.0.0 to 1.8.0. | ||||
| CVE-2026-16640 | 2026-08-25 | N/A | ||
| Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Search API Autocomplete allows Reflected XSS. This issue affects Search API Autocomplete versions: from 0.0.0 to 1.12.0. | ||||
| CVE-2026-16644 | 2026-08-25 | N/A | ||
| Incorrect Authorization vulnerability in Drupal Webform REST allows Forceful Browsing. This issue affects Webform REST versions: from 0.0.0 to 4.1.0. | ||||
| CVE-2026-16645 | 2026-08-25 | N/A | ||
| Missing Authorization vulnerability in Drupal PhotoSwipe - Responsive JavaScript Modal Image Gallery allows Forceful Browsing. This issue affects PhotoSwipe - Responsive JavaScript Modal Image Gallery versions: from 0.0.0 to 3.2.0. | ||||
| CVE-2026-15088 | 2026-08-25 | N/A | ||
| Vulnerability in Drupal Development Environment. This issue affects Development Environment versions: *.*. | ||||
| CVE-2026-18259 | 2026-08-25 | N/A | ||
| Observable Timing Discrepancy vulnerability in Drupal Token Content Access allows Brute Force. This issue affects Token Content Access versions: from 0.0.0 to 3.1.2. | ||||
| CVE-2026-18985 | 2026-08-25 | N/A | ||
| Incorrect Authorization vulnerability in Drupal Edit in-place field allows Forceful Browsing. This issue affects Edit in-place field versions: from 0.0.0 to 2.1.1. | ||||
| CVE-2026-80186 | 1 Redhat | 1 Enterprise Linux | 2026-08-25 | 7.6 High |
| A stack-based buffer overflow vulnerability exists in BlueZ, the Linux Bluetooth protocol stack. A remote user within Bluetooth radio range can send a specially crafted Extended Inquiry Response (EIR) packet that causes a buffer overflow when the target device performs Bluetooth discovery. This vulnerability can lead to a Denial of Service (DoS) by crashing the bluetoothd service and may allow for arbitrary code execution. | ||||
| CVE-2026-80185 | 1 Redhat | 1 Enterprise Linux | 2026-08-25 | 5.7 Medium |
| BlueZ sdp-xml.c type confusion via RegisterProfile(ServiceRecord) can crash bluetoothd (local DoS): a crafted nested ServiceRecord can corrupt the SDP XML parser stack so scalar union data is treated as a sequence pointer, allowing a local caller to crash bluetoothd. | ||||