Security Box Score — September 29, 2026 — page 2
Edition of September 29, 2026, continued — page 2 of 2. Back to page 1
| CVE | CVSS | EPSS %ile | Vendor | Product | CWE | Title |
|---|---|---|---|---|---|---|
| CVE-2026-92224 | 5.9 | — | Joomla! Project | Joomla! CMS | CWE-79 | Joomla! Core - [20260911] - Core - XSS in link toolbar layout in Joomla 4.0.0… |
| CVE-2026-92225 | 5.9 | — | Joomla! Project | Joomla! CMS | CWE-79 | Joomla! Core - [20260912] - Core - XSS in module list in Joomla 4.0.0-5.4.8, … |
| CVE-2026-102729 | 5.9 | — | Eclipse Foundation | GUIX | CWE-131 | `gx_binres_theme_load()` sizes its theme buffer for the theme it was asked fo… |
| CVE-2026-102938 | 5.8 | — | pypa | virtualenv | CWE-93 | virtualenv writes prompt values into pyvenv.cfg without sanitizing line bound… |
| CVE-2026-102371 | 5.7 | — | Canonical | Ubuntu Pro for WSL | CWE-214 | wsl-pro-service: Ubuntu Pro token exposed via process command-line arguments |
| CVE-2026-102711 | 5.7 | — | Eclipse Foundation | `eclipse-threadx/threadx` (module manager / loadable-module loader) | CWE-125 | Two issues in the ThreadX loadable-module loader, reached when a device loads… |
| CVE-2026-102491 | 5.5 | — | mahonelau | kykms | CWE-74 | mahonelau kykms SqlInjectionUtil QueryGenerator.java QueryGenerator.doMultiFi… |
| CVE-2026-102616 | 5.5 | — | risesoft-y9 | WorkFlow-Engine | CWE-74 | risesoft-y9 WorkFlow-Engine OAuth2 Resource Filter CustomHistoricProcessServi… |
| CVE-2026-73599 | 5.4 | — | Dell | Secure Connect Gateway (SCG) Policy Manager | CWE-601 | Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.1… |
| CVE-2026-95279 | 5.4 | — | Chrome | CWE-451 | UI misrepresentation in Omnibox in Google Chrome on on Android prior to 154.0… | |
| CVE-2026-95288 | 5.4 | — | Chrome | CWE-451 | UI misrepresentation in Mobile in Google Chrome on on iOS prior to 154.0.8037… | |
| CVE-2026-95291 | 5.4 | — | Chrome | CWE-451 | UI misrepresentation in SecurityIndicators in Google Chrome on on iOS prior t… | |
| CVE-2026-95294 | 5.4 | — | Chrome | CWE-451 | UI misrepresentation in Browser in Google Chrome prior to 154.0.8037.57 allow… | |
| CVE-2026-95307 | 5.4 | — | Chrome | CWE-451 | UI misrepresentation in ExtensionsMenu in Google Chrome prior to 154.0.8037.5… | |
| CVE-2026-95309 | 5.4 | — | Chrome | CWE-451 | UI misrepresentation in Mobile in Google Chrome on on iOS prior to 154.0.8037… | |
| CVE-2026-95320 | 5.4 | — | Chrome | CWE-862 | Missing authorization in Navigation in Google Chrome prior to 154.0.8037.57 a… | |
| CVE-2026-95321 | 5.4 | — | Chrome | CWE-451 | UI misrepresentation in Payments in Google Chrome on on Android prior to 154.… | |
| CVE-2026-95323 | 5.4 | — | Chrome | CWE-451 | UI misrepresentation in Chromium in Google Chrome on on iOS prior to 154.0.80… | |
| CVE-2026-95337 | 5.4 | — | Chrome | CWE-451 | UI misrepresentation in Messages in Google Chrome on on Android prior to 154.… | |
| CVE-2026-95363 | 5.4 | — | Chrome | CWE-451 | UI misrepresentation in FileSystem in Google Chrome prior to 154.0.8037.57 al… | |
| CVE-2026-95364 | 5.4 | — | Chrome | CWE-20 | Improper input validation in Passwords in Google Chrome prior to 154.0.8037.5… | |
| CVE-2026-95371 | 5.4 | — | Chrome | CWE-862 | Missing authorization in Views in Google Chrome on on Mac prior to 154.0.8037… | |
| CVE-2026-100287 | 5.4 | — | Devolutions | Server | CWE-862 | Missing authorization in the attachment history API in Devolutions Server 202… |
| CVE-2026-102305 | 5.4 | — | Chrome | CWE-451 | UI misrepresentation in SignIn in Google Chrome on on iOS prior to 154.0.8037… | |
| CVE-2026-102314 | 5.4 | — | Chrome | CWE-451 | UI misrepresentation in TabStrip in Google Chrome prior to 154.0.8037.92 allo… | |
| CVE-2026-102904 | 5.4 | — | jupyterlab | jupyterlab | CWE-88 | JupyterLab: Argument injection in JupyterLab extension uninstall exposes serv… |
| CVE-2026-53989 | 5.3 | — | Finsys | dockhand | CWE-601 | Dockhand < 1.0.36 Open Redirect via OIDC Initiation Endpoint |
| CVE-2026-75804 | 5.3 | — | OpenSSL | OpenSSL | CWE-770 | QUIC Connection-Level Flow Control is Not Enforced for Streams |
| CVE-2026-75805 | 5.3 | — | OpenSSL | OpenSSL | CWE-476 | NULL Pointer Dereference in CMP Client Revocation Response Handling |
| CVE-2026-75806 | 5.3 | — | OpenSSL | OpenSSL | CWE-1284 | Unauthenticated and Undersized DTLS 1.2 AEAD Record Causes DoS |
| CVE-2026-78214 | 5.3 | — | Apache Software Foundation | Apache DolphinScheduler | CWE-863 | Apache DolphinScheduler: Actuator Endpoint Authentication Bypass via Percent-… |
| CVE-2026-81841 | 5.3 | — | Grafana | Grafana Enterprise | CWE-862 | Paused shared dashboard access tokens still expose data source configuration |
| CVE-2026-86105 | 5.3 | — | WatchGuard | Fireware OS | CWE-176 | Fireware OS Improper Authorization in Access Portal Reverse Proxy |
| CVE-2026-95360 | 5.3 | — | Chrome | CWE-367 | Race condition in Editing in Google Chrome prior to 154.0.8037.57 allowed a r… | |
| CVE-2026-95367 | 5.3 | — | Chrome | CWE-200 | Information leak in DataTransfer in Google Chrome prior to 154.0.8037.57 allo… | |
| CVE-2026-95384 | 5.3 | — | Chrome | CWE-362 | Race condition in Transactions Platform in Google Chrome prior to 154.0.8037.… | |
| CVE-2026-100295 | 5.3 | — | Anjvision | YSSD-RTMP-H5 | CWE-489 | Active debug code in Anjvision YSSD-RTMP-H5 |
| CVE-2026-102720 | 5.3 | — | Eclipse Foundation | eclipse-threadx/netxduo | CWE-125 | A DHCP server, or anyone on the LAN who answers a DISCOVER first, can make th… |
| CVE-2026-102879 | 5.3 | — | claraverse-space | ClaraVerse | CWE-918 | ClaraVerse through 0.3.1 SSRF Protection Bypass |
| CVE-2026-71973 | 5.2 | — | u-boot | u-boot | CWE-190 | U-Boot before 2026.10-rc4 Integer Overflow in SquashFS Directory Table Alloca… |
| CVE-2026-22101 | 5.1 | — | EVbee | DC-80 | CWE-200 | Sensitive information leak through hidden menu |
| CVE-2026-49243 | 5.1 | — | webmin | webmin | CWE-79 | Webmin: Reflected XSS in the Configuration module |
| CVE-2026-90916 | 5.1 | — | Joomla! Project | Joomla! CMS | CWE-284 | Joomla! Core - [20260906] - Core - Improper ACL checks in content history com… |
| CVE-2026-92223 | 5.1 | — | Joomla! Project | Joomla! CMS | CWE-284 | Joomla! Core - [20260910] - Core - Improper ACL checks for workflow stage cha… |
| CVE-2026-100289 | 5.0 | — | Devolutions | Server | CWE-862 | Missing authorization in the gateway network scan token API in Devolutions Se… |
| CVE-2026-76733 | 4.9 | — | Hewlett Packard Enterprise (HPE) | Instant ON | — | Authenticated Denial-of-Service Vulnerability in HPE Networking Instant On AP… |
| CVE-2026-71189 | 4.8 | — | Toptech Systems | TMS7 | CWE-79 | Toptech TMS7 and TopHAT Cross-site Scripting |
| CVE-2026-76734 | 4.8 | — | Hewlett Packard Enterprise (HPE) | Instant ON | — | Unauthenticated Memory Corruption Vulnerability leads to Denial-of-Service in… |
| CVE-2026-95305 | 4.8 | — | Chrome | CWE-451 | UI misrepresentation in Chromoting in Google Chrome prior to 154.0.8037.57 al… | |
| CVE-2026-95346 | 4.8 | — | Chrome | CWE-451 | UI misrepresentation in Chromoting in Google Chrome prior to 154.0.8037.57 al… | |
| CVE-2026-73595 | 4.7 | — | Dell | Secure Connect Gateway (SCG) Policy Manager | CWE-494 | Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.1… |
| CVE-2026-95293 | 4.7 | — | Chrome | CWE-908 | Uninitialized resource in GPU in Google Chrome prior to 154.0.8037.57 allowed… | |
| CVE-2026-95332 | 4.7 | — | Chrome | CWE-457 | Use of uninitialized variable in Tint in Google Chrome on on Android prior to… | |
| CVE-2026-102307 | 4.7 | — | Chrome | CWE-908 | Uninitialized resource in Dawn in Google Chrome on on Android prior to 154.0.… | |
| CVE-2026-102313 | 4.7 | — | Chrome | CWE-908 | Uninitialized resource in ANGLE in Google Chrome on on Windows prior to 154.0… | |
| CVE-2026-102318 | 4.7 | — | Chrome | CWE-125 | Out of bounds read in WebGL in Google Chrome prior to 154.0.8037.92 allowed a… | |
| CVE-2026-95295 | 4.6 | — | Chrome | CWE-200 | Information leak in Mobile in Google Chrome on on iOS prior to 154.0.8037.57 … | |
| CVE-2026-71897 | 4.3 | — | Apache Software Foundation | Apache DolphinScheduler | CWE-863 | Apache DolphinScheduler: Allows unauthorized workflow operations through batc… |
| CVE-2026-71898 | 4.3 | — | Apache Software Foundation | Apache DolphinScheduler | CWE-863 | Apache DolphinScheduler: Improper Authorization Allows Project Read-Only User… |
| CVE-2026-71974 | 4.3 | — | u-boot | u-boot | CWE-787 | U-Boot before 2026.10-rc3 Out-of-Bounds Write via Android Bootmeth Partition … |
| CVE-2026-76720 | 4.3 | — | Hewlett Packard Enterprise | HPE OneView | CWE-601 | HPE OneView - URL Redirect vulnerability |
| CVE-2026-79348 | 4.3 | — | n/a | n/a | — | KitchenAsty through 0.3.0 contains a broken object level authorization (IDOR)… |
| CVE-2026-81569 | 4.3 | — | Apache Software Foundation | Apache DolphinScheduler | CWE-285 | Apache DolphinScheduler: Improper Authorization in Sub-Workflow Tasks Allows … |
| CVE-2026-81842 | 4.3 | — | Grafana | Grafana Enterprise | CWE-863 | Library panel can be moved into a folder without library panel create permission |
| CVE-2026-93330 | 4.3 | — | Devolutions | Server | CWE-696 | Improper rule enforcement in the PAM Active Directory provider in Devolutions… |
| CVE-2026-95289 | 4.3 | — | Chrome | CWE-863 | Incorrect authorization in Scroll in Google Chrome prior to 154.0.8037.57 all… | |
| CVE-2026-95296 | 4.3 | — | Chrome | CWE-862 | Missing authorization in Core in Google Chrome on on Mac prior to 154.0.8037.… | |
| CVE-2026-95368 | 4.3 | — | Chrome | CWE-863 | Incorrect authorization in DevTools in Google Chrome prior to 154.0.8037.57 a… | |
| CVE-2026-96869 | 4.3 | — | Mozilla | Firefox | CWE-200 | Information disclosure in the Networking component |
| CVE-2026-100766 | 4.3 | — | Mozilla | Firefox | CWE-200 | Information disclosure in the Networking: JAR component |
| CVE-2026-100783 | 4.3 | — | Mozilla | Firefox | CWE-457 | Uninitialized memory in the Audio/Video component |
| CVE-2026-100799 | 4.3 | — | Mozilla | Firefox | CWE-457 | Uninitialized memory in the Graphics: WebGPU component |
| CVE-2026-100802 | 4.3 | — | Mozilla | Firefox | CWE-457 | Uninitialized memory in the Graphics: WebGPU component |
| CVE-2026-100806 | 4.3 | — | Mozilla | Firefox | CWE-457 | Uninitialized memory in the Graphics: WebGPU component |
| CVE-2026-102300 | 4.3 | — | Chrome | CWE-908 | Uninitialized resource in WebGPU in Google Chrome prior to 154.0.8037.92 allo… | |
| CVE-2026-102303 | 4.3 | — | Chrome | CWE-908 | Uninitialized resource in GPU in Google Chrome on on Android prior to 154.0.8… | |
| CVE-2026-102325 | 4.3 | — | Chrome | CWE-908 | Uninitialized resource in Skia in Google Chrome prior to 154.0.8037.92 allowe… | |
| CVE-2026-102824 | 4.3 | — | Eugeny | russh | CWE-327 | Russh: Missing X25519 zero-point validation in hybrid ML-KEM key exchange |
| CVE-2026-76735 | 4.1 | — | Hewlett Packard Enterprise (HPE) | Instant ON | — | Authenticated Local Sensitive Information Disclosure in HPE Networking Instan… |
| CVE-2026-73596 | 3.8 | — | Dell | Secure Connect Gateway (SCG) Policy Manager | CWE-1188 | Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.1… |
| CVE-2026-54872 | 3.7 | — | OpenSSL | OpenSSL | CWE-208 | Timing Side-Channel in Scalar Multiplication for Non-NIST EC Curves |
| CVE-2026-54875 | 3.7 | — | OpenSSL | OpenSSL | CWE-208 | Non-Constant-Time SM2 Scalar Multiplication on ARM64 and RISC-V |
| CVE-2026-77696 | 3.7 | — | OpenSSL | OpenSSL | CWE-208 | Timing Side-Channel in SM2 Signature Generation |
| CVE-2026-102822 | 3.7 | — | Eugeny | russh | CWE-129 | russh: negotiating a MAC-requiring block cipher (CTR/CBC) with mac=none cause… |
| CVE-2026-102825 | 3.7 | — | Eugeny | russh | CWE-307 | Russh: Configured server auth-attempt cap is not enforced in the USERAUTH_REQ… |
| CVE-2026-102601 | 3.5 | — | thephpleague | flysystem | CWE-150 | Flysystem: WhitespacePathNormalizer's control-character (CorruptedPathDetecte… |
| CVE-2026-95308 | 3.4 | — | Chrome | CWE-190 | Integer overflow in Metrics in Google Chrome prior to 154.0.8037.57 allowed a… | |
| CVE-2026-95324 | 3.4 | — | Chrome | CWE-908 | Uninitialized resource in GPU in Google Chrome prior to 154.0.8037.57 allowed… | |
| CVE-2026-95359 | 3.4 | — | Chrome | CWE-908 | Uninitialized resource in GPU in Google Chrome on on Android prior to 154.0.8… | |
| CVE-2026-102311 | 3.4 | — | Chrome | CWE-908 | Uninitialized resource in GPU in Google Chrome on on Android prior to 154.0.8… | |
| CVE-2026-102315 | 3.4 | — | Chrome | CWE-908 | Uninitialized resource in Media in Google Chrome on on Windows prior to 154.0… | |
| CVE-2026-102319 | 3.4 | — | Chrome | CWE-908 | Uninitialized resource in GPU in Google Chrome prior to 154.0.8037.92 allowed… | |
| CVE-2026-76736 | 3.3 | — | Hewlett Packard Enterprise (HPE) | Instant ON | — | Authenticated Local Buffer Overflow Vulnerability leads to Denial-of-Service … |
| CVE-2026-95312 | 3.1 | — | Chrome | CWE-200 | Information leak in Passwords in Google Chrome prior to 154.0.8037.57 allowed… | |
| CVE-2026-95317 | 3.1 | — | Chrome | CWE-863 | Incorrect authorization in MediaCapture in Google Chrome prior to 154.0.8037.… | |
| CVE-2026-73593 | 3.0 | — | Dell | Secure Connect Gateway (SCG) Policy Manager | CWE-489 | Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.1… |
| CVE-2026-76737 | 3.0 | — | Hewlett Packard Enterprise (HPE) | Instant ON | — | Authenticated Local Path Traversal Vulnerability Leads to Denial-of-Service i… |
| CVE-2026-95302 | 2.9 | — | Chrome | CWE-863 | Incorrect authorization in WebAPKs in Google Chrome on on Android prior to 15… | |
| CVE-2026-95316 | 2.9 | — | Chrome | CWE-252 | Unchecked return value in Performance in Google Chrome prior to 154.0.8037.57… | |
| CVE-2026-76738 | 2.7 | — | Hewlett Packard Enterprise (HPE) | Instant ON | — | Authenticated Buffer Overflow Vulnerability in the API Endpoint of HPE Networ… |
| CVE-2026-101267 | 2.7 | — | pretix | pretix | CWE-862 | Revenue information leak |
| CVE-2026-97711 | 2.3 | — | yahoo | serialize-javascript | CWE-79 | Serialize JavaScript: Cross-site scripting (XSS) via unescaped </script> in s… |
| CVE-2026-101269 | 2.3 | — | pretix | pretix | CWE-287 | Incorrect session validation for API-uploaded files |
| CVE-2026-102630 | 2.3 | — | unopim | unopim | CWE-348 | UnoPim 2.0.0 before 2.0.1 and 2.1.0 before 2.1.1 Cache Poisoning via X-Forwar… |
| CVE-2026-69662 | 2.1 | — | Toptech Systems | TMS7 | CWE-95 | Toptech TMS7 and TopHAT Eval Injection |
| CVE-2026-101270 | 2.1 | — | pretix | pretix | CWE-79 | HTML injection |
| CVE-2026-101271 | 2.1 | — | pretix | pretix | CWE-613 | OAuth credentials not disabled when application is disabled |
| CVE-2026-102877 | 2.1 | — | getfider | fider | CWE-918 | Fider before 0.38.0 SSRF via DNS rebinding in webhook validation |
| CVE-2026-102771 | 2.0 | — | Naichen | ThinkCMF | CWE-791 | Naichen ThinkCMF Email Template MailController.php templatePut special elemen… |
| CVE-2026-102620 | 1.9 | — | Freedesktop | Poppler | CWE-189 | Freedesktop Poppler FoFiTrueType.cc cvtSfnts integer overflow |
| CVE-2026-102621 | 1.9 | — | Freedesktop | Poppler | CWE-189 | Freedesktop Poppler SplashClip.cc clipToPath integer overflow |
| CVE-2026-101268 | 1.7 | — | pretix | pretix | CWE-384 | Customer session fixation |
| CVE-2026-101266 | 1.3 | — | pretix | pretix | CWE-20 | Checkout validation bypass |
| CVE-2024-31026 | await | — | n/a | n/a | — | An issue in Greek Universities Network (GUnet) Open eClass Platform v.3.15 al… |
| CVE-2024-31027 | await | — | n/a | n/a | — | Cross Site Scripting vulnerability in Greek Universities Network (GUnet) Open… |
| CVE-2026-35189 | await | — | OpenSSL | OpenSSL | CWE-770 | Excessive Memory Allocation in Relative CRLDP Processing |
| CVE-2026-35191 | await | — | OpenSSL | OpenSSL | CWE-440 | QUIC Unvalidated Amplification Credit may be Over Accounted |
| CVE-2026-42772 | await | — | OpenSSL | OpenSSL | CWE-407 | Potential CPU DoS via O(n^2) Fragment Reassembly in QUIC |
| CVE-2026-54873 | await | — | OpenSSL | OpenSSL | CWE-770 | QUIC STREAM Fragment Metadata DoS |
| CVE-2026-67987 | await | — | n/a | n/a | — | crmne/ruby_llm at commit fa6f279847d6d7027814539d9c0dfc3bbdfd2a83 contains po… |
| CVE-2026-67993 | await | — | n/a | n/a | — | basecamp/upright at commit efe4f2e5254ac6e57e45d2261804cca74dbbca3f contains … |
| CVE-2026-71899 | await | — | Apache Software Foundation | Apache DolphinScheduler | CWE-863 | Apache DolphinScheduler: Missing Authorization in query-dynamic-sub-workflows… |
| CVE-2026-79403 | await | — | n/a | n/a | — | An issue in Kilo Code before v7.4.1 allows a local attacker to execute arbitr… |
| CVE-2026-79417 | await | — | n/a | n/a | — | Improper Access Control in ArgusMonitor.sys in Argotronic eGbR ArgusMonitor 7… |
| CVE-2026-79534 | await | — | n/a | n/a | — | mark3labs mcp-filesystem-server v0.11.1 is vulnerable to Directory Traversal … |
| CVE-2026-79535 | await | — | n/a | n/a | — | mbailey VoiceMode <= 8.10.1 is vulnerable to OS Command Injection. The update… |
| CVE-2026-79536 | await | — | n/a | n/a | — | bytebase dbhub v1.2.0 was discovered to contain a SQL injection vulnerability… |
| CVE-2026-79537 | await | — | n/a | n/a | — | metatool-ai MetaMCP through 2.4.22 contains an insecure direct object referen… |
| CVE-2026-93332 | await | — | Devolutions | Server | CWE-862 | Improper access control in the partial connection API in Devolutions Server 2… |
| CVE-2026-94952 | await | — | n/a | n/a | — | A stack-based buffer overflow vulnerability exists in the web management inte… |
| CVE-2026-94953 | await | — | n/a | n/a | — | A stack-based buffer overflow vulnerability exists in the web management inte… |
| CVE-2026-94954 | await | — | n/a | n/a | — | A stack-based buffer overflow vulnerability exists in the web management inte… |
| CVE-2026-95275 | await | — | Chrome | CWE-706 | Incorrect reference resolution in MediaStream in Google Chrome prior to 154.0… | |
| CVE-2026-95278 | await | — | Chrome | CWE-862 | Missing authorization in WakeLock in Google Chrome prior to 154.0.8037.57 all… | |
| CVE-2026-95284 | await | — | Chrome | CWE-122 | Buffer overflow in ANGLE in Google Chrome on on Android prior to 154.0.8037.5… | |
| CVE-2026-95285 | await | — | Chrome | CWE-862 | Missing authorization in WebView in Google Chrome on on Android prior to 154.… | |
| CVE-2026-95287 | await | — | Chrome | CWE-862 | Missing authorization in Navigation in Google Chrome prior to 154.0.8037.57 a… | |
| CVE-2026-95290 | await | — | Chrome | CWE-862 | Missing authorization in NFC in Google Chrome prior to 154.0.8037.57 allowed … | |
| CVE-2026-95292 | await | — | Chrome | CWE-863 | Incorrect authorization in Safebrowsing in Google Chrome prior to 154.0.8037.… | |
| CVE-2026-95297 | await | — | Chrome | CWE-862 | Missing authorization in Contextual Tasks in Google Chrome prior to 154.0.803… | |
| CVE-2026-95300 | await | — | Chrome | CWE-862 | Missing authorization in DevTools in Google Chrome prior to 154.0.8037.57 all… | |
| CVE-2026-95301 | await | — | Chrome | CWE-862 | Missing authorization in Extensions in Google Chrome prior to 154.0.8037.57 a… | |
| CVE-2026-95303 | await | — | Chrome | CWE-459 | Incomplete cleanup in SmartCard in Google Chrome prior to 154.0.8037.57 allow… | |
| CVE-2026-95314 | await | — | Chrome | CWE-863 | Incorrect authorization in HID in Google Chrome prior to 154.0.8037.57 allowe… | |
| CVE-2026-95326 | await | — | Chrome | CWE-459 | Incomplete cleanup in Bluetooth in Google Chrome prior to 154.0.8037.57 allow… | |
| CVE-2026-95330 | await | — | Chrome | CWE-754 | Improper state validation in Downloads in Google Chrome prior to 154.0.8037.5… | |
| CVE-2026-95340 | await | — | Chrome | CWE-863 | Incorrect authorization in PictureInPicture in Google Chrome prior to 154.0.8… | |
| CVE-2026-95342 | await | — | Chrome | CWE-862 | Missing authorization in V8 in Google Chrome prior to 154.0.8037.57 allowed a… | |
| CVE-2026-95344 | await | — | Chrome | CWE-367 | Race condition in DevTools in Google Chrome prior to 154.0.8037.57 allowed a … | |
| CVE-2026-95352 | await | — | Chrome | CWE-863 | Incorrect authorization in DevTools in Google Chrome prior to 154.0.8037.57 a… | |
| CVE-2026-95358 | await | — | Chrome | CWE-863 | Incorrect authorization in Mobile in Google Chrome on on Android prior to 154… | |
| CVE-2026-95361 | await | — | Chrome | CWE-441 | Confused deputy in DevTools in Google Chrome prior to 154.0.8037.57 allowed a… | |
| CVE-2026-95362 | await | — | Chrome | CWE-352 | Cross-site request forgery in DevTools in Google Chrome prior to 154.0.8037.5… | |
| CVE-2026-95366 | await | — | Chrome | CWE-672 | Use of released resource in Core in Google Chrome prior to 154.0.8037.57 allo… | |
| CVE-2026-95370 | await | — | Chrome | CWE-841 | Inappropriate implementation in NFC in Google Chrome prior to 154.0.8037.57 a… | |
| CVE-2026-95374 | await | — | Chrome | CWE-863 | Incorrect authorization in Network in Google Chrome prior to 154.0.8037.57 al… | |
| CVE-2026-95375 | await | — | Chrome | CWE-863 | Incorrect authorization in BrowserTag in Google Chrome prior to 154.0.8037.57… | |
| CVE-2026-95376 | await | — | Chrome | CWE-610 | Externally controlled reference in DevTools in Google Chrome prior to 154.0.8… | |
| CVE-2026-95385 | await | — | Chrome | CWE-841 | Inappropriate implementation in PlatformIntegration in Google Chrome on on Wi… | |
| CVE-2026-97395 | await | — | Apache Software Foundation | Apache Polaris | — | Apache Polaris: Allows authorized table writers to redirect server-side Icebe… |
| CVE-2026-98164 | await | — | Linux | Linux | — | KVM: x86/mmu: Check write tracking in all address spaces |
| CVE-2026-100238 | await | — | Wikimedia Foundation | Mediawiki - Flow Extension | CWE-79 | Flow colon-separator and flow-guidedtour-optin-welcome-description messages a… |
| CVE-2026-100240 | await | — | Wikimedia Foundation | Mediawiki - TemplateSandbox Extension | CWE-862 | TemplateSandbox does not check read permissions for the page being previewed |
| CVE-2026-100241 | await | — | Wikimedia Foundation | Mediawiki - EventBus Extension | CWE-200 | Private change tags exposed to anonymous users via revision-tags-change events |
| CVE-2026-100242 | await | — | Wikimedia Foundation | Mediawiki - DataTransfer Extension | CWE-400 | DataTransfer depends on phpspreadsheet version vulnerable to CVE-2026-59933 (… |
| CVE-2026-100243 | await | — | Wikimedia Foundation | Mediawiki - WikiSEO Extension | CWE-79 | Stored XSS in WikiSEO author and image properties on action=info |
| CVE-2026-100244 | await | — | Wikimedia Foundation | Mediawiki - CentralAuth Extension | CWE-200 | CentralAuth exposes locally suppressed block information via globaluserinfo A… |
| CVE-2026-100245 | await | — | Wikimedia Foundation | Mediawiki - Wikibase Extension | CWE-79 | Stored XSS on Wikibase Special:SetSiteLink via unescaped system message |
| CVE-2026-100288 | await | — | Devolutions | Server | CWE-312 | Cleartext storage of sensitive information in the database in Devolutions Ser… |
| CVE-2026-100756 | await | — | Mozilla | Firefox | — | Incorrect boundary conditions in the Audio/Video: Playback component |
| CVE-2026-100758 | await | — | Mozilla | Firefox | — | Sandbox escape in the DOM: Navigation component |
| CVE-2026-100759 | await | — | Mozilla | Firefox | — | Uninitialized memory in the Storage: Quota Manager component |
| CVE-2026-100760 | await | — | Mozilla | Firefox | — | Sandbox escape in the Security: Process Sandboxing component |
| CVE-2026-100763 | await | — | Mozilla | Firefox | — | Incorrect boundary conditions in the Graphics: WebGPU component |
| CVE-2026-100771 | await | — | Mozilla | Firefox | — | Undefined behavior in the DOM: Streams component |
| CVE-2026-100775 | await | — | Mozilla | Firefox | — | Sandbox escape in the Graphics component |
| CVE-2026-100781 | await | — | Mozilla | Firefox | — | Sandbox escape due to incorrect boundary conditions in the Graphics: WebRende… |
| CVE-2026-100787 | await | — | Mozilla | Firefox | — | Sandbox escape in the XUL component |
| CVE-2026-100788 | await | — | Mozilla | Firefox | — | Invalid pointer in the JavaScript: WebAssembly component |
| CVE-2026-100792 | await | — | Mozilla | Firefox | — | JIT miscompilation in the JavaScript: WebAssembly component |
| CVE-2026-100793 | await | — | Mozilla | Firefox | — | JIT miscompilation in the JavaScript Engine component |
| CVE-2026-100794 | await | — | Mozilla | Firefox | — | Sandbox escape due to incorrect boundary conditions in the Internationalizati… |
| CVE-2026-100798 | await | — | Mozilla | Firefox | — | Cryptography misuse in Storage: Quota Manager component |
| CVE-2026-100803 | await | — | Mozilla | Firefox | — | Same-origin policy bypass in the WebExtensions component |
| CVE-2026-100808 | await | — | Mozilla | Firefox | — | Mitigation bypass in the DOM: Service Workers component |
| CVE-2026-100809 | await | — | Mozilla | Firefox | — | Same-origin policy bypass in the DevTools component |
| CVE-2026-100810 | await | — | Mozilla | Firefox | — | Other issue in the DevTools component |
| CVE-2026-100816 | await | — | Mozilla | Firefox | — | Site isolation issue in the DOM: Networking component |
| CVE-2026-100817 | await | — | Mozilla | Firefox | — | Other issue in the JavaScript: WebAssembly component |
| CVE-2026-100821 | await | — | Mozilla | Firefox | — | Site isolation issue in the Panning and Zooming component |
| CVE-2026-100822 | await | — | Mozilla | Firefox | — | Spoofing issue in the Networking: HTTP component |
| CVE-2026-100823 | await | — | Mozilla | Firefox | — | Spoofing issue in the Downloads component in Firefox for Android |
| CVE-2026-100828 | await | — | Mozilla | Firefox | — | Mitigation bypass in the Bookmarks & History component |
| CVE-2026-100829 | await | — | Mozilla | Firefox | — | Mitigation bypass in the DOM: Security component |
| CVE-2026-100830 | await | — | Mozilla | Firefox | — | Mitigation bypass in the DOM: Navigation component |
| CVE-2026-102310 | await | — | Chrome | CWE-862 | Missing authorization in Payments in Google Chrome prior to 154.0.8037.92 all… | |
| CVE-2026-102312 | await | — | Chrome | CWE-451 | UI misrepresentation in Omnibox in Google Chrome on on Android prior to 154.0… | |
| CVE-2026-102320 | await | — | Chrome | CWE-862 | Missing authorization in CORS in Google Chrome prior to 154.0.8037.92 allowed… | |
| CVE-2026-102329 | await | — | Chrome | CWE-79 | Cross-site scripting in WebUI in Google Chrome prior to 154.0.8037.92 allowed… | |
| CVE-2026-102330 | await | — | Chrome | CWE-863 | Incorrect authorization in SiteIsolation in Google Chrome prior to 154.0.8037… | |
| CVE-2026-102728 | await | — | Eclipse Foundation | NetX Duo | CWE-126 | Two client-side TLS/DTLS handshake parsers in NetX Secure read fields from a … |
| CVE-2026-102758 | await | — | Eclipse Foundation | NetX Duo | CWE-126 | The `_nx_secure_x509_asn1_tlv_block_parse()` function parses ASN.1 TLV (tag-l… |
| CVE-2026-102796 | await | — | Wikimedia Foundation | Mediawiki - UserPageViewTracker Extension | CWE-89 | Unauthenticated SQL injection in UserPageViewTracker via filterusers and igno… |
| CVE-2026-103044 | await | — | The Wikimedia Foundation | Mediawiki - EasyTimeline extension | CWE-91 | EasyTimeline should not serve image maps as application/xml |
| CVE-2026-103045 | await | — | The Wikimedia Foundation | Mediawiki - Refreshed skin | CWE-79 | XSS in Refreshed skin |
| CVE-2026-103046 | await | — | The Wikimedia Foundation | Mediawiki - WikiLambda Extension | CWE-79 | WikifunctionsFragmentRenderer does unsafe string replacements on user-provide… |
| CVE-2026-103047 | await | — | The Wikimedia Foundation | Mediawiki - CentralAuth extension | CWE-79 | XSS through i18n message in CentralAuth |
| CVE-2026-103048 | await | — | The Wikimedia Foundation | Mediawiki - Collection extension | CWE-601 | Open Redirect in Special:Book |
| CVE-2026-103049 | await | — | The Wikimedia Foundation | Mediawiki - Cargo extension | CWE-79 | XSS in Cargo's Special:CargoQuery page due to unsanitized table headers |
| CVE-2026-103050 | await | — | The Wikimedia Foundation | Mediawiki - MassMessage extension | CWE-79 | Stored i18n XSS in MassMessage |
| CVE-2026-103051 | await | — | The Wikimedia Foundation | Mediawiki - CentralNotice extension | CWE-79 | Stored i18n XSSs in CentralNotice |