Security Box Score — October 6, 2026 — page 2
Edition of October 6, 2026, continued — page 2 of 3. Back to page 1 · page 3
| CVE | CVSS | EPSS %ile | Vendor | Product | CWE | Title |
|---|---|---|---|---|---|---|
| CVE-2026-104031 | 5.5 | 0.6 | Red Hat | Red Hat Enterprise Linux 10 | CWE-772 | Sssd: sssd: denial of service via memory exhaustion in autofs responder |
| CVE-2026-104032 | 5.5 | 0.6 | Red Hat | Red Hat Enterprise Linux 10 | CWE-408 | Sssd: sssd: denial of service via unprivileged autofs cache invalidation |
| CVE-2026-104035 | 5.5 | 0.6 | Red Hat | Red Hat Enterprise Linux 10 | CWE-772 | Sssd: sssd: denial of service via memory exhaustion in kcm responder |
| CVE-2026-104037 | 5.5 | 0.6 | Red Hat | Red Hat Enterprise Linux 10 | CWE-125 | Sssd: sssd: denial of service via packet length underflow in autofs responder |
| CVE-2026-104041 | 5.5 | 0.6 | Red Hat | Red Hat Enterprise Linux 10 | CWE-770 | Sssd: sssd: denial of service via unbounded negative cache growth |
| CVE-2026-104043 | 5.5 | 0.6 | Red Hat | Red Hat Enterprise Linux 10 | CWE-125 | Sssd: sssd: denial of service via undersized packet parsing in nss responder |
| CVE-2026-25302 | 7.1 | 0.4 | Qualcomm, Inc. | Snapdragon | CWE-347 | Improper Verification of Cryptographic Signature in Boot |
| CVE-2026-104036 | 5.8 | 0.4 | Red Hat | Red Hat Enterprise Linux 10 | CWE-787 | Sssd: sssd: denial of service via out-of-bounds write in nfs idmap plugin |
| CVE-2026-104034 | 4.7 | 0.4 | Red Hat | Red Hat Enterprise Linux 10 | CWE-825 | Sssd: sssd: denial of service via use-after-free in kcm ticket renewal |
| CVE-2026-25263 | 6.6 | 0.3 | Qualcomm, Inc. | Snapdragon | CWE-787 | Out of Bounds write in Linux Camera |
| CVE-2026-63688 | 10.0 | — | Dell | Dell Container Storage Modules (CSM) | CWE-306 | Dell Container Storage Modules (CSM), versions prior to v1.18.0, contains a M… |
| CVE-2026-63692 | 10.0 | — | Dell | Container Storage Modules | CWE-306 | Dell Container Storage Modules, versions prior to 1.18.0, contain(s) a Missin… |
| CVE-2026-105857 | 10.0 | — | payloadcms | payload | CWE-94 | Payload: RCE in Payload Form Builder |
| CVE-2026-106102 | 10.0 | — | quasarframework | quasar | CWE-79 | Quasar Framework: Stored/Reflected XSS via unescaped SSR meta tag rendering i… |
| CVE-2026-67269 | 9.9 | — | Dell | Container Storage Modules (CSM) | CWE-269 | Dell Container Storage Modules (CSM) Operator, versions prior to 1.18.0 conta… |
| CVE-2026-79798 | 9.9 | — | Hewlett Packard Enterprise (HPE) | ClearPass Policy Manager (CPPM) | — | Authenticated SQL Injection Vulnerabilities in ClearPass Policy Manager Web-B… |
| CVE-2026-54472 | 9.8 | — | Dell | Container Storage Modules | CWE-798 | Dell Container Storage Modules, versions prior to 1.18.0, contain(s) an Use o… |
| CVE-2026-55330 | 9.8 | — | Android | CWE-416 | In BluetoothCccHandlerCallbackImpl of bluetooth_ccc.cc, there is a possible u… | |
| CVE-2026-61421 | 9.8 | — | Dell | Container Storage Modules | CWE-798 | Dell Container Storage Modules, versions prior to 1.18.0, contain(s) an Use o… |
| CVE-2026-76742 | 9.8 | — | Hewlett Packard Enterprise (HPE) | AOS-Switch (AOS-S) | CWE-269 | Authentication Bypass in the Web Management Interface of AOS-S |
| CVE-2026-76743 | 9.8 | — | Hewlett Packard Enterprise (HPE) | AOS-Switch (AOS-S) | — | Authentication Bypass Vulnerability in the Management Interface of AOS-S |
| CVE-2026-76744 | 9.8 | — | Hewlett Packard Enterprise (HPE) | AOS-Switch (AOS-S) | — | Unauthenticated Buffer Overflow Vulnerabilities lead to Remote Code Execution… |
| CVE-2026-76750 | 9.8 | — | Hewlett Packard Enterprise (HPE) | ClearPass Policy Manager (CPPM) | — | Unauthenticated Deserialization of Untrusted Data allows Remote Code Executio… |
| CVE-2026-76751 | 9.8 | — | Hewlett Packard Enterprise (HPE) | ClearPass Policy Manager (CPPM) | — | Missing Integrity Verification in the OnGuard Agent of ClearPass Policy Manag… |
| CVE-2026-76752 | 9.8 | — | Hewlett Packard Enterprise (HPE) | ClearPass Policy Manager (CPPM) | — | Authentication Bypass Vulnerabilities in HPE Networking ClearPass Policy Mana… |
| CVE-2026-76753 | 9.8 | — | Hewlett Packard Enterprise (HPE) | ClearPass Policy Manager (CPPM) | — | Unauthenticated Format String Vulnerability in HPE Networking ClearPass Polic… |
| CVE-2026-76754 | 9.8 | — | Hewlett Packard Enterprise (HPE) | ClearPass Policy Manager (CPPM) | — | Unauthenticated SQL Injection Vulnerability leads to Remote Code Execution in… |
| CVE-2026-79796 | 9.8 | — | Hewlett Packard Enterprise (HPE) | ClearPass Policy Manager (CPPM) | — | Authentication Bypass Vulnerabilities in ClearPass Policy Manager |
| CVE-2026-79801 | 9.8 | — | Hewlett Packard Enterprise (HPE) | ClearPass Policy Manager (CPPM) | — | Unauthenticated Missing Integrity Verification allows Remote Code Execution i… |
| CVE-2026-79805 | 9.8 | — | Hewlett Packard Enterprise (HPE) | ClearPass Policy Manager (CPPM) | — | Authenticated Path Traversal Vulnerability Leads to Unauthorized File Access … |
| CVE-2026-104334 | 9.8 | — | IBM | Langflow OSS | CWE-94 | Langflow OSS is affected by multiple vulnerabilities |
| CVE-2026-105845 | 9.8 | — | payloadcms | payload | CWE-89 | Payload: SQL Injection in SQLite and Postgres |
| CVE-2026-105859 | 9.8 | — | payloadcms | payload | CWE-639 | Payload: Unauthorized update to collection documents |
| CVE-2026-106446 | 9.8 | — | handlebars-lang | handlebars.js | CWE-94 | Handlebars: JavaScript Injection via AST Type Confusion in compile (Program.b… |
| CVE-2026-67273 | 9.6 | — | Dell | Container Storage Modules | CWE-1336 | Dell Container Storage Modules, versions prior to 1.18.0, contain(s) an Impro… |
| CVE-2026-76745 | 9.6 | — | Hewlett Packard Enterprise (HPE) | AOS-Switch (AOS-S) | — | Unauthenticated Adjacent Memory Corruption Vulnerabilities Leading to Remote … |
| CVE-2026-86360 | 9.6 | — | Dell | System Update | CWE-22 | Dell System Update, versions prior to 2.3.0.0, contains an Improper Limitatio… |
| CVE-2026-91140 | 9.6 | — | Progress Software | Autonomous REST Connector GenAI Agents | CWE-78 | OS command injection in Progress Software Autonomous REST Connector GenAI Agents |
| CVE-2026-102322 | 9.6 | — | Chrome | CWE-863 | Incorrect Authorization in SiteIsolation in Google Chrome prior to 155.0.8059… | |
| CVE-2026-106197 | 9.6 | — | Chrome | CWE-416 | Use after free in Browser in Google Chrome prior to 155.0.8059.39 allowed a r… | |
| CVE-2026-106211 | 9.6 | — | Chrome | CWE-416 | Use after free in TabStrip in Google Chrome prior to 155.0.8059.39 allowed a … | |
| CVE-2026-106227 | 9.6 | — | Chrome | CWE-416 | Use after free in Core in Google Chrome prior to 155.0.8059.39 allowed a remo… | |
| CVE-2026-106234 | 9.6 | — | Chrome | CWE-416 | Use after free in Network in Google Chrome prior to 155.0.8059.39 allowed a r… | |
| CVE-2026-106239 | 9.6 | — | Chrome | CWE-190 | Integer overflow in WebGL in Google Chrome on on Android prior to 155.0.8059.… | |
| CVE-2026-106241 | 9.6 | — | Chrome | CWE-863 | Incorrect authorization in Search in Google Chrome on on Android prior to 155… | |
| CVE-2026-106281 | 9.6 | — | Chrome | CWE-416 | Use after free in Tint in Google Chrome prior to 155.0.8059.39 allowed a remo… | |
| CVE-2026-106298 | 9.6 | — | Chrome | CWE-416 | Use after free in Chrome Tabs in Google Chrome on on Mac prior to 155.0.8059.… | |
| CVE-2026-106323 | 9.6 | — | Chrome | CWE-862 | Missing authorization in Chrome for iOS in Google Chrome on on iOS prior to 1… | |
| CVE-2026-106329 | 9.6 | — | Chrome | CWE-863 | Incorrect authorization in FileSystem in Google Chrome prior to 155.0.8059.39… | |
| CVE-2026-106358 | 9.6 | — | Chrome | CWE-416 | Use after free in Navigation in Google Chrome prior to 155.0.8059.39 allowed … | |
| CVE-2026-106372 | 9.6 | — | Chrome | CWE-863 | Incorrect authorization in UI in Google Chrome prior to 155.0.8059.39 allowed… | |
| CVE-2026-106375 | 9.6 | — | Chrome | CWE-459 | Incomplete cleanup in Dawn in Google Chrome prior to 155.0.8059.39 allowed a … | |
| CVE-2026-106382 | 9.6 | — | Chrome | CWE-416 | Use after free in Chromecast in Google Chrome prior to 155.0.8059.39 allowed … | |
| CVE-2026-106401 | 9.6 | — | Chrome | CWE-787 | Out of bounds write in Media in Google Chrome prior to 155.0.8059.39 allowed … | |
| CVE-2026-106414 | 9.6 | — | Chrome | CWE-20 | Improper input validation in Mobile in Google Chrome on on iOS prior to 155.0… | |
| CVE-2026-106417 | 9.6 | — | Chrome | CWE-190 | Integer overflow in Media in Google Chrome prior to 155.0.8059.39 allowed a r… | |
| CVE-2026-106419 | 9.6 | — | Chrome | CWE-416 | Use after free in ANGLE in Google Chrome on on Android prior to 155.0.8059.39… | |
| CVE-2026-106501 | 9.6 | — | backstage | backstage | CWE-200 | Backstage: Sensitive information exposure in Scaffolder |
| CVE-2026-102162 | 9.4 | — | Arista Networks | Wi-Fi Access Points | CWE-121 | Security Advisory 0193 |
| CVE-2026-76746 | 9.3 | — | Hewlett Packard Enterprise (HPE) | AOS-Switch (AOS-S) | — | Unauthenticated Adjacent Buffer Overflow Vulnerability Leading to Information… |
| CVE-2026-101157 | 9.3 | — | Arista Networks | CloudVision CUE | CWE-79 | Security Advisory 0192 |
| CVE-2026-101158 | 9.3 | — | Arista Networks | CloudVision Portal | CWE-79 | Security Advisory 0185 |
| CVE-2026-102159 | 9.3 | — | Arista Networks | CloudVision CUE | CWE-306 | Security Advisory 0190 |
| CVE-2026-104070 | 9.3 | — | SPIP | SPIP Crayons Plugin | CWE-862 | SPIP Crayons Plugin < 3.5.0 Authorization Bypass RCE |
| CVE-2026-105844 | 9.3 | — | payloadcms | payload | CWE-1321 | Payload: Prototype pollution in Payload Import Export plugin |
| CVE-2026-105851 | 9.3 | — | payloadcms | payload | CWE-284 | Payload: Field access control bypass on auth collections |
| CVE-2026-106037 | 9.3 | — | kvcache-ai | Mooncake | CWE-306 | Mooncake through 0.3.13.post1 Missing Authentication in Store REST Service |
| CVE-2026-82531 | 9.2 | — | smarty-php | smarty | CWE-94 | Smarty before 4.5.8 and 5.x before 5.8.5 PHP Code Injection via extends: Inhe… |
| CVE-2026-105863 | 9.2 | — | payloadcms | payload | CWE-290 | Payload authentication token field handling issue |
| CVE-2026-106445 | 9.2 | — | handlebars-lang | handlebars.js | CWE-184 | Handlebars: JavaScript Injection via Own Property Check Bypass |
| CVE-2026-76747 | 9.1 | — | Hewlett Packard Enterprise (HPE) | AOS-Switch (AOS-S) | — | Unauthenticated Buffer Overflow Vulnerabilities lead to Information Disclosur… |
| CVE-2026-77178 | 9.1 | — | n/a | n/a | CWE-787 | Oracle VM VirtualBox before 7.2.8 allows guest OS users to cause an out-of-bo… |
| CVE-2026-79794 | 9.1 | — | Hewlett Packard Enterprise (HPE) | ClearPass Policy Manager (CPPM) | — | Authenticated SQL Injection Vulnerability in ClearPass Policy Manager Web-bas… |
| CVE-2026-105793 | 9.1 | — | microsoft | UFO | CWE-78 | Microsoft UFO: Authenticated Android shell command injection in Mobile MCP `p… |
| CVE-2026-105794 | 9.1 | — | microsoft | msquic | CWE-295 | MsQuic: Improper Certificate Validation in Microsoft.Native.Quic.MsQuic.OpenSSL |
| CVE-2026-105835 | 9.1 | — | planka | planka | CWE-307 | PLANKA 2.2.0 through 2.2.1 TOTP Brute Force via verify-totp Endpoint |
| CVE-2026-102167 | 9.0 | — | Arista Networks | Wi-Fi Access Points | CWE-121 | Security Advisory 0197 |
| CVE-2026-106448 | 8.9 | — | StableLib | stablelib | CWE-1321 | StableLib: Prototype poisoning via `__proto__` map keys in CBOR decoding |
| CVE-2026-76748 | 8.8 | — | Hewlett Packard Enterprise (HPE) | AOS-Switch (AOS-S) | — | Authenticated Privilege Escalation Vulnerability in the API of AOS-S |
| CVE-2026-79797 | 8.8 | — | Hewlett Packard Enterprise (HPE) | ClearPass Policy Manager (CPPM) | — | Improper Access Control in HPE Networking ClearPass Android Client Application |
| CVE-2026-79799 | 8.8 | — | Hewlett Packard Enterprise (HPE) | ClearPass Policy Manager (CPPM) | — | Unauthenticated Stored Cross-Site Scripting (XSS) Vulnerability in ClearPass … |
| CVE-2026-79800 | 8.8 | — | Hewlett Packard Enterprise (HPE) | ClearPass Policy Manager (CPPM) | — | Authenticated Path Traversal Vulnerability Leads to Remote Code Execution in … |
| CVE-2026-79802 | 8.8 | — | Hewlett Packard Enterprise (HPE) | ClearPass Policy Manager (CPPM) | — | Command Injection Vulnerability in the ClearPass Policy Manager Client Software |
| CVE-2026-79803 | 8.8 | — | Hewlett Packard Enterprise (HPE) | ClearPass Policy Manager (CPPM) | — | Authenticated Command Injection Leading to Privilege Escalation in ClearPass … |
| CVE-2026-85523 | 8.8 | — | Felisify Information Technologies Industry and Trade Inc. | SambaBox | CWE-78 | OS Command Injection in Felisify Informatics' SambaBox |
| CVE-2026-97655 | 8.8 | — | IBM | Langflow OSS | CWE-94 | Langflow OSS is affected by multiple vulnerabilities |
| CVE-2026-97676 | 8.8 | — | IBM | Langflow OSS | CWE-94 | Langflow OSS is affected by multiple vulnerabilities |
| CVE-2026-97678 | 8.8 | — | IBM | Langflow OSS | CWE-693 | Langflow OSS is affected by multiple vulnerabilities |
| CVE-2026-97679 | 8.8 | — | IBM | Langflow OSS | CWE-94 | Langflow OSS is affected by multiple vulnerabilities |
| CVE-2026-101207 | 8.8 | — | Dell | OpenManage Integration | CWE-78 | Dell OpenManage Integration with Microsoft Windows Admin Center, versions pri… |
| CVE-2026-102406 | 8.8 | — | Elastic | Kibana | CWE-639 | Authorization Bypass Through User-Controlled Key in Kibana Leading to Cross-T… |
| CVE-2026-104335 | 8.8 | — | IBM | Langflow OSS | CWE-284 | Langflow OSS is affected by multiple vulnerabilities |
| CVE-2026-105788 | 8.8 | — | microsoft | UFO | CWE-78 | Microsoft UFO: Authenticated Android shell command injection in Mobile MCP ty… |
| CVE-2026-105796 | 8.8 | — | microsoft | kiota | CWE-94 | Kiota: Code injection through doc-comment delimiter reformation in Kiota Java… |
| CVE-2026-105797 | 8.8 | — | microsoft | simplechat | CWE-78 | SimpleChat: Command injection via authorization-gate ordering flaw (arbitrary… |
| CVE-2026-105812 | 8.8 | — | aws | bedrock-agentcore-starter-toolkit | CWE-94 | Code injection via unencoded configuration values during Python code generati… |
| CVE-2026-105850 | 8.8 | — | payloadcms | payload | CWE-837 | Payload: Order confirmation validation issue in Payload Ecommerce |
| CVE-2026-106038 | 8.8 | — | kvcache-ai | Mooncake | CWE-306 | Mooncake Store through 0.3.13.post1 Unauthenticated Object Deletion via Remov… |
| CVE-2026-106040 | 8.8 | — | kvcache-ai | Mooncake | CWE-862 | Mooncake Store through 0.3.13.post1 Missing Authorization via EvictDiskReplic… |
| CVE-2026-106190 | 8.8 | — | Chrome | CWE-416 | Use after free in Media in Google Chrome prior to 155.0.8059.39 allowed a rem… | |
| CVE-2026-106193 | 8.8 | — | Chrome | CWE-416 | Use after free in Parser in Google Chrome prior to 155.0.8059.39 allowed a re… | |
| CVE-2026-106200 | 8.8 | — | Chrome | CWE-416 | Use after free in Track in Google Chrome prior to 155.0.8059.39 allowed a rem… | |
| CVE-2026-106201 | 8.8 | — | Chrome | CWE-362 | Race condition in V8 in Google Chrome prior to 155.0.8059.39 allowed a remote… | |
| CVE-2026-106203 | 8.8 | — | Chrome | CWE-459 | Incomplete cleanup in Autofill in Google Chrome on on iOS prior to 155.0.8059… | |
| CVE-2026-106204 | 8.8 | — | Chrome | CWE-416 | Use after free in PDF in Google Chrome prior to 155.0.8059.39 allowed a remot… | |
| CVE-2026-106207 | 8.8 | — | Chrome | CWE-367 | Race condition in V8 in Google Chrome prior to 155.0.8059.39 allowed a remote… | |
| CVE-2026-106212 | 8.8 | — | Chrome | CWE-863 | Incorrect authorization in Autofill in Google Chrome prior to 155.0.8059.39 a… | |
| CVE-2026-106218 | 8.8 | — | JetBrains | TeamCity | CWE-184 | In JetBrains TeamCity before 2026.1.3 2025.11.7 kotlin DSL sandbox escape lea… |
| CVE-2026-106220 | 8.8 | — | Chrome | CWE-200 | Information leak in Passwords in Google Chrome prior to 155.0.8059.39 allowed… | |
| CVE-2026-106225 | 8.8 | — | Chrome | CWE-862 | Missing authorization in Autofill in Google Chrome prior to 155.0.8059.39 all… | |
| CVE-2026-106235 | 8.8 | — | Chrome | CWE-416 | Use after free in WebAudio in Google Chrome prior to 155.0.8059.39 allowed a … | |
| CVE-2026-106240 | 8.8 | — | Chrome | CWE-843 | Type confusion in V8 in Google Chrome prior to 155.0.8059.39 allowed a remote… | |
| CVE-2026-106248 | 8.8 | — | Chrome | CWE-416 | Use after free in Bindings in Google Chrome prior to 155.0.8059.39 allowed a … | |
| CVE-2026-106249 | 8.8 | — | Chrome | CWE-863 | Incorrect authorization in Autofill in Google Chrome on on Android prior to 1… | |
| CVE-2026-106252 | 8.8 | — | Chrome | CWE-697 | Incorrect comparison in Fonts in Google Chrome prior to 155.0.8059.39 allowed… | |
| CVE-2026-106255 | 8.8 | — | Chrome | CWE-362 | Race condition in V8 in Google Chrome prior to 155.0.8059.39 allowed a remote… | |
| CVE-2026-106256 | 8.8 | — | Chrome | CWE-200 | Information leak in Passwords in Google Chrome on on Android prior to 155.0.8… | |
| CVE-2026-106257 | 8.8 | — | Chrome | CWE-416 | Use after free in HTML in Google Chrome prior to 155.0.8059.39 allowed a remo… | |
| CVE-2026-106268 | 8.8 | — | Chrome | CWE-416 | Use after free in WebRTC in Google Chrome prior to 155.0.8059.39 allowed a re… | |
| CVE-2026-106269 | 8.8 | — | Chrome | CWE-416 | Use after free in CSS in Google Chrome prior to 155.0.8059.39 allowed a remot… | |
| CVE-2026-106274 | 8.8 | — | Chrome | CWE-706 | Incorrect reference resolution in Browser in Google Chrome on on Mac prior to… | |
| CVE-2026-106278 | 8.8 | — | Chrome | CWE-416 | Use after free in Select in Google Chrome prior to 155.0.8059.39 allowed a re… | |
| CVE-2026-106283 | 8.8 | — | Chrome | CWE-416 | Use after free in Streaming in Google Chrome prior to 155.0.8059.39 allowed a… | |
| CVE-2026-106291 | 8.8 | — | Chrome | CWE-416 | Use after free in GarbageCollection in Google Chrome prior to 155.0.8059.39 a… | |
| CVE-2026-106308 | 8.8 | — | Chrome | CWE-706 | Incorrect reference resolution in Autofill in Google Chrome on on Android pri… | |
| CVE-2026-106309 | 8.8 | — | Chrome | CWE-863 | Incorrect authorization in Selection in Google Chrome on on iOS prior to 155.… | |
| CVE-2026-106314 | 8.8 | — | Chrome | CWE-863 | Incorrect authorization in Bluetooth in Google Chrome prior to 155.0.8059.39 … | |
| CVE-2026-106315 | 8.8 | — | Chrome | CWE-416 | Use after free in Modularization in Google Chrome prior to 155.0.8059.39 allo… | |
| CVE-2026-106318 | 8.8 | — | Chrome | CWE-416 | Use after free in Media in Google Chrome prior to 155.0.8059.39 allowed a rem… | |
| CVE-2026-106334 | 8.8 | — | Chrome | CWE-200 | Information leak in Payments in Google Chrome prior to 155.0.8059.39 allowed … | |
| CVE-2026-106335 | 8.8 | — | Chrome | CWE-416 | Use after free in Media in Google Chrome prior to 155.0.8059.39 allowed a rem… | |
| CVE-2026-106341 | 8.8 | — | Chrome | CWE-843 | Type confusion in V8 in Google Chrome prior to 155.0.8059.39 allowed a remote… | |
| CVE-2026-106342 | 8.8 | — | Chrome | CWE-200 | Information leak in Autofill in Google Chrome prior to 155.0.8059.39 allowed … | |
| CVE-2026-106346 | 8.8 | — | Chrome | CWE-754 | Improper state validation in DevTools in Google Chrome prior to 155.0.8059.39… | |
| CVE-2026-106347 | 8.8 | — | Chrome | CWE-416 | Use after free in Track in Google Chrome prior to 155.0.8059.39 allowed a rem… | |
| CVE-2026-106349 | 8.8 | — | Chrome | CWE-416 | Use after free in V8 in Google Chrome prior to 155.0.8059.39 allowed a remote… | |
| CVE-2026-106350 | 8.8 | — | Chrome | CWE-863 | Incorrect authorization in Browser in Google Chrome prior to 155.0.8059.39 al… | |
| CVE-2026-106352 | 8.8 | — | Chrome | CWE-863 | Incorrect authorization in WebProtect in Google Chrome prior to 155.0.8059.39… | |
| CVE-2026-106357 | 8.8 | — | Chrome | CWE-416 | Use after free in WebRTC in Google Chrome prior to 155.0.8059.39 allowed a re… | |
| CVE-2026-106371 | 8.8 | — | Chrome | CWE-863 | Incorrect authorization in Transactions Platform in Google Chrome on on Andro… | |
| CVE-2026-106373 | 8.8 | — | Chrome | CWE-416 | Use after free in Fonts in Google Chrome on on Windows prior to 155.0.8059.39… | |
| CVE-2026-106374 | 8.8 | — | Chrome | CWE-843 | Type confusion in V8 in Google Chrome prior to 155.0.8059.39 allowed a remote… | |
| CVE-2026-106383 | 8.8 | — | Chrome | CWE-416 | Use after free in Media in Google Chrome prior to 155.0.8059.39 allowed a rem… | |
| CVE-2026-106387 | 8.8 | — | Chrome | CWE-862 | Missing authorization in Mobile in Google Chrome on on iOS prior to 155.0.805… | |
| CVE-2026-106411 | 8.8 | — | Chrome | CWE-416 | Use after free in Parser in Google Chrome prior to 155.0.8059.39 allowed a re… | |
| CVE-2026-106421 | 8.8 | — | Chrome | CWE-416 | Use after free in PDF in Google Chrome prior to 155.0.8059.39 allowed a remot… | |
| CVE-2026-106423 | 8.8 | — | Chrome | CWE-416 | Use after free in Media in Google Chrome prior to 155.0.8059.39 allowed a rem… | |
| CVE-2026-106443 | 8.8 | — | Kozea | WeasyPrint | CWE-20 | WeasyPrint: EPS images reach the Ghostscript interpreter resulting in RCE |
| CVE-2026-96890 | 8.7 | — | GitHub | Enterprise Server | CWE-918 | Server-Side Request Forgery vulnerability was identified in GitHub Enterprise… |
| CVE-2026-102161 | 8.7 | — | Arista Networks | CloudVision CUE | CWE-290 | Security Advisory 0190 |
| CVE-2026-102163 | 8.7 | — | Arista Networks | Wi-Fi Access Points | CWE-787 | Security Advisory 0195 |
| CVE-2026-105798 | 8.7 | — | microsoft | simplechat | CWE-79 | SimpleChat: Stored XSS via group document filename in inline onclick handler |
| CVE-2026-105854 | 8.7 | — | payloadcms | payload | CWE-400 | Payload: ReDoS in Multipart Content-Type Validation |
| CVE-2026-105862 | 8.7 | — | payloadcms | payload | CWE-79 | Payload: Bypassed sanitization of user uploaded SVGs |
| CVE-2026-105985 | 8.7 | — | craftcms | cms | CWE-1336 | Authenticated RCE via render-components Entry Type overrides |
| CVE-2026-106104 | 8.7 | — | quasarframework | quasar | CWE-1333 | Quasar Framework: Super-linear regex backtracking on User-Agent lets one requ… |
| CVE-2026-106447 | 8.7 | — | StableLib | stablelib | CWE-674 | StableLib: Stack exhaustion denial of service via deeply nested CBOR arrays, … |
| CVE-2026-101154 | 8.6 | — | Arista Networks | CloudVision Portal | CWE-22 | Security Advisory 0189 |
| CVE-2026-101155 | 8.6 | — | Arista Networks | CloudVision Portal | CWE-22 | Security Advisory 0189 |
| CVE-2026-102160 | 8.6 | — | Arista Networks | CloudVision CUE | CWE-78 | Security Advisory 0190 |
| CVE-2026-104069 | 8.6 | — | danielbrendel | hortusfox-web | CWE-434 | HortusFox < 6.2 Remote Code Execution via Theme Import |
| CVE-2026-105806 | 8.6 | — | payloadcms | payload | CWE-862 | Payload: Improper access control for MCP API keys |
| CVE-2026-105856 | 8.6 | — | payloadcms | payload | CWE-89 | Payload: SQL injection in SQLite/Postgres |
| CVE-2026-105868 | 8.6 | — | payloadcms | payload | CWE-434 | Payload: Uploaded XML files could execute same-origin JavaScript |
| CVE-2026-106186 | 8.6 | — | Chrome | CWE-427 | Uncontrolled search path element in CredentialProvider in Google Chrome on on… | |
| CVE-2026-105837 | 8.5 | — | sezero | libmikmod | CWE-190 | libmikmod before 3.3.14 Heap Buffer Overflow via DSM Loader Integer Overflow |
| CVE-2026-105839 | 8.5 | — | sezero | libmikmod | CWE-190 | libmikmod before 3.3.14 Heap Buffer Overflow via OKT Loader OKT_doPBOD |
| CVE-2026-106439 | 8.5 | — | hydra-ecosystem | hydra | CWE-470 | Hydra: Mutable instantiate policy sets allow target blocklist bypass |
| CVE-2026-106459 | 8.5 | — | backstage | backstage | CWE-200 | Backstage: Improper input validation in Sentry scaffolder actions |
| CVE-2026-106486 | 8.5 | — | backstage | backstage | CWE-22 | Backstage: Improper filesystem validation in Bitbucket pull-request scaffolde… |
| CVE-2026-106500 | 8.5 | — | backstage | backstage | CWE-59 | Backstage: Improper task state validation in Scaffolder backend |
| CVE-2026-106547 | 8.5 | — | The HDF Group | HDF5 | CWE-122 | HDF5 heap buffer overflow in H5VM_array_fill via crafted fill-value metadata |
| CVE-2026-105801 | 8.4 | — | openapi-generators | openapi-python-client | CWE-94 | openapi-python-client: Malicious OpenAPI Documents can cause Arbitrary Code G… |
| CVE-2026-106105 | 8.4 | — | quasarframework | quasar | CWE-732 | Quasar Framework: Development TLS private keys are cached with overly permiss… |
| CVE-2026-106512 | 8.4 | — | MISP | sachertortephp | CWE-20 | MISP sachertortephp - CakeResponse::download() HTTP Response Splitting via Un… |
| CVE-2026-97680 | 8.3 | — | IBM | Langflow OSS | CWE-284 | Langflow OSS is affected by multiple vulnerabilities |
| CVE-2026-106107 | 8.3 | — | quasarframework | quasar | CWE-79 | Quasar Framework: App Vite SSR and SSG nonce attributes are not safely constr… |
| CVE-2026-106191 | 8.3 | — | Chrome | CWE-862 | Missing authorization in Actor in Google Chrome prior to 155.0.8059.39 allowe… | |
| CVE-2026-106194 | 8.3 | — | Chrome | CWE-862 | Missing authorization in WebAppInstalls in Google Chrome prior to 155.0.8059.… | |
| CVE-2026-106228 | 8.3 | — | Chrome | CWE-441 | Confused deputy in Google Lens in Google Chrome prior to 155.0.8059.39 allowe… | |
| CVE-2026-106233 | 8.3 | — | Chrome | CWE-416 | Use after free in Metrics in Google Chrome prior to 155.0.8059.39 allowed a r… | |
| CVE-2026-106238 | 8.3 | — | Chrome | CWE-362 | Race condition in Fonts in Google Chrome prior to 155.0.8059.39 allowed a rem… | |
| CVE-2026-106247 | 8.3 | — | Chrome | CWE-122 | Buffer overflow in ANGLE in Google Chrome prior to 155.0.8059.39 allowed a re… | |
| CVE-2026-106292 | 8.3 | — | Chrome | CWE-122 | Buffer overflow in Fonts in Google Chrome prior to 155.0.8059.39 allowed a re… | |
| CVE-2026-106293 | 8.3 | — | Chrome | CWE-843 | Type confusion in ANGLE in Google Chrome prior to 155.0.8059.39 allowed a rem… | |
| CVE-2026-106377 | 8.3 | — | Chrome | CWE-362 | Race condition in Fonts in Google Chrome prior to 155.0.8059.39 allowed a rem… | |
| CVE-2026-106378 | 8.3 | — | Chrome | CWE-250 | Privilege elevation in Sandbox in Google Chrome on on Mac prior to 155.0.8059… | |
| CVE-2026-106393 | 8.3 | — | Chrome | CWE-416 | Use after free in Storage in Google Chrome prior to 155.0.8059.39 allowed a r… | |
| CVE-2026-106409 | 8.3 | — | Chrome | CWE-706 | Incorrect reference resolution in WebAppInstalls in Google Chrome on on Mac p… | |
| CVE-2026-106412 | 8.3 | — | Chrome | CWE-367 | Race condition in Core in Google Chrome on on Mac prior to 155.0.8059.39 allo… | |
| CVE-2026-106426 | 8.3 | — | Chrome | CWE-362 | Race condition in Fonts in Google Chrome prior to 155.0.8059.39 allowed a rem… | |
| CVE-2026-67270 | 8.2 | — | Dell | Container Storage Modules (CSM) | CWE-295 | Dell Container Storage Modules (CSM) versions prior to 1.18.0, contains an Im… |
| CVE-2026-86361 | 8.2 | — | Dell | System Update | CWE-732 | Dell System Update, versions prior to 2.3.0.0, contains an Incorrect Permissi… |
| CVE-2026-86362 | 8.2 | — | Dell | System Update | CWE-284 | Dell System Update, versions prior to 2.3.0.0, contains an Improper Access Co… |
| CVE-2026-94114 | 8.2 | — | Apache Software Foundation | Apache Commons BCEL | CWE-386 | Apache Commons BCEL: Nested Code/Record attributes drive unbounded parse-time… |
| CVE-2026-97674 | 8.1 | — | IBM | Langflow OSS | CWE-94 | Langflow OSS is affected by multiple vulnerabilities |
| CVE-2026-103360 | 8.1 | — | IBM | Langflow OSS | CWE-22 | Langflow OSS is affected by multiple vulnerabilities |
| CVE-2026-105858 | 8.1 | — | payloadcms | payload | CWE-94 | Payload: Remote Code Execution through first-register |
| CVE-2026-105865 | 8.1 | — | payloadcms | payload | CWE-22 | Payload: Incomplete validation during the upload file lifecycle |
| CVE-2026-106488 | 8.1 | — | backstage | backstage | CWE-287 | Backstage: Improper authentication in the OIDC provider |
| CVE-2026-106503 | 8.1 | — | backstage | backstage | CWE-178 | Backstage: Scaffolder action input authorization bypass |
| CVE-2026-65142 | 7.8 | — | NVIDIA | Model-Optimizer | CWE-502 | NVIDIA Model-Optimizer contains a vulnerability where an attacker may cause d… |
| CVE-2026-79806 | 7.8 | — | Hewlett Packard Enterprise (HPE) | ClearPass Policy Manager (CPPM) | — | Authenticated Local Privilege Escalation in ClearPass Policy Manager OnGuard … |
| CVE-2026-79807 | 7.8 | — | Hewlett Packard Enterprise (HPE) | ClearPass Policy Manager (CPPM) | — | Authenticated Local Missing Integrity Verification Vulnerability leads to Loc… |
| CVE-2026-79808 | 7.8 | — | Hewlett Packard Enterprise (HPE) | ClearPass Policy Manager (CPPM) | — | Local Authenticated Buffer Overflow Vulnerability in the ClearPass Policy Man… |
| CVE-2026-101258 | 7.8 | — | Red Hat | Red Hat Enterprise Linux 10 | CWE-787 | Ghostscript: ghostscript: -dsafer sandbox bypass via type 5 shading oob write… |
| CVE-2026-106062 | 7.8 | — | Red Hat | Red Hat Enterprise Linux 10 | CWE-119 | Gimp: gimp: heap buffer overflow in dds loader on crafted directdraw surface … |
| CVE-2026-106440 | 7.8 | — | hydra-ecosystem | hydra | CWE-470 | Hydra: Optuna custom_search_space can resolve and execute untrusted callables… |
| CVE-2026-106441 | 7.8 | — | hydra-ecosystem | hydra | CWE-94 | Hydra logging configuration permits unsafe callable resolution |
| CVE-2026-106442 | 7.8 | — | hydra-ecosystem | hydra | CWE-184 | Hydra instantiate target blacklist bypasses permit code execution |
| CVE-2026-43598 | 7.7 | — | AMD | AMD Instinct™ MI210 | CWE-822 | Improper input validation in the AMD ROCm Communication Collectives Library (… |
| CVE-2026-61411 | 7.7 | — | Dell | Container Storage Modules | CWE-532 | Dell Container Storage Modules, versions prior to 1.18.0, contain(s) an Inser… |
| CVE-2026-76105 | 7.7 | — | Dell | Container Storage Modules | CWE-330 | Dell Container Storage Modules, versions prior to 1.18.0 contain(s) an Use of… |
| CVE-2026-101027 | 7.7 | — | Gitea | Gitea | — | Gitea migration SSRF through ALLOWED_DOMAINS address check bypass |
| CVE-2026-101331 | 7.7 | — | IBM | Langflow OSS | CWE-522 | Langflow OSS is affected by multiple vulnerabilities |
| CVE-2026-102165 | 7.7 | — | Arista Networks | Wi-Fi Access Points | CWE-121 | Security Advisory 0198 |
| CVE-2026-105840 | 7.7 | — | Uwe Ohse | lrzsz | CWE-22 | lrzsz before 0.13.0 Path Traversal via lrz Restricted Mode checkpath() |
| CVE-2026-105841 | 7.7 | — | Uwe Ohse | lrzsz | CWE-78 | lrzsz before 0.13.0 OS Command Injection via lrz Pipe Mode |
| CVE-2026-105849 | 7.7 | — | payloadcms | payload | CWE-201 | Payload: API key disclosure through ordinary document reads |
| CVE-2026-106455 | 7.7 | — | backstage | backstage | CWE-918 | Backstage: Improper validation of MkDocs plugin configuration in TechDocs |
| CVE-2026-106498 | 7.7 | — | backstage | backstage | CWE-863 | Backstage: Improper URL validation in catalog entity placeholder resolution |
| CVE-2026-106505 | 7.7 | — | backstage | backstage | CWE-426 | Backstage: Bypass of MkDocs configuration sanitizer in TechDocs backend |
| CVE-2026-106509 | 7.7 | — | backstage | backstage | CWE-94 | Backstage: Improper validation of MkDocs theme configuration in TechDocs |
| CVE-2026-63697 | 7.6 | — | Dell | System Update | CWE-295 | Dell System Update, versions prior to 2.3.0.0, contains an Improper Certifica… |
| CVE-2026-101152 | 7.6 | — | Arista Networks | CloudVision Portal | CWE-601 | Security Advisory 0187 |
| CVE-2026-105855 | 7.6 | — | payloadcms | payload | CWE-284 | Payload: Field-level password update restrictions were not enforced |
| CVE-2026-106492 | 7.6 | — | backstage | backstage | CWE-269 | Backstage: Improper preservation of access restrictions during service creden… |
| CVE-2026-95140 | 7.5 | — | n/a | n/a | CWE-22 | kkFileView v5.0.0 through v5.0.2 contains a directory traversal vulnerability… |
| CVE-2026-103831 | 7.5 | — | TrueLayer | TrueLayer Magento 2 Plugin | CWE-502 | Insecure deserialization in the TrueLayer Magento 2 plugin |
| CVE-2026-104850 | 7.5 | — | modelcontextprotocol | typescript-sdk | CWE-345 | MCP TypeScript SDK: OAuth client could send credentials to an authorization s… |
| CVE-2026-105791 | 7.5 | — | microsoft | UFO | CWE-88 | Microsoft UFO: Arbitrary code execution in `run_shell` via `explorer.exe` arg… |
| CVE-2026-106110 | 7.5 | — | SixLabors | ImageSharp | CWE-787 | ImageSharp: TIFF CCITT T4 encoder can write past its compressed output buffer |
| CVE-2026-106112 | 7.5 | — | SixLabors | ImageSharp | CWE-787 | ImageSharp: ICC LUT16 output channel count can write beyond Vector4 |
| CVE-2026-106113 | 7.5 | — | SixLabors | ImageSharp | CWE-787 | ImageSharp: HistogramEqualization uses an unvalidated luminance as an uncheck… |
| CVE-2026-106115 | 7.5 | — | SixLabors | ImageSharp | CWE-787 | ImageSharp: TIFF CCITT T6 encoder writes beyond an undersized output buffer |
| CVE-2026-106117 | 7.5 | — | SixLabors | ImageSharp | CWE-787 | ImageSharp: CCITT fax decompression (T4/Modified Huffman): unbounded WriteBit… |
| CVE-2026-106118 | 7.5 | — | SixLabors | ImageSharp | CWE-787 | ImageSharp: Tiled fax TIFF: tile buffer sized by TileWidth but fax decompress… |
| CVE-2026-82162 | 7.4 | — | Dell | Command | Configure (DCC) | CWE-175 | Dell Command | Configure (DCC), versions prior to 5.2.3.35, contain an Improp… |
| CVE-2026-106279 | 7.4 | — | Chrome | CWE-706 | Incorrect reference resolution in Passwords in Google Chrome on on iOS prior … | |
| CVE-2026-71168 | 7.3 | — | Dell | System Update | CWE-22 | Dell System Update, versions prior to 2.3.0.0, contains an Improper Limitatio… |
| CVE-2026-79809 | 7.3 | — | Hewlett Packard Enterprise (HPE) | ClearPass Policy Manager (CPPM) | — | Unauthenticated Path Traversal in ClearPass Policy Manager API Endpoint Leads… |
| CVE-2026-106451 | 7.3 | — | yawkat | lz4-java | CWE-367 | yawkat LZ4 Java: Native library extraction to a shared temporary directory is… |
| CVE-2026-79810 | 7.2 | — | Hewlett Packard Enterprise (HPE) | ClearPass Policy Manager (CPPM) | — | Authenticated Remote Code Execution Vulnerabilities in HPE Networking ClearPa… |
| CVE-2026-79811 | 7.2 | — | Hewlett Packard Enterprise (HPE) | ClearPass Policy Manager (CPPM) | — | Authenticated SQL Injection allows Remote Code Execution in ClearPass Policy … |
| CVE-2026-101153 | 7.2 | — | Arista Networks | CloudVision Portal | CWE-22 | Security Advisory 0188 |
| CVE-2026-103007 | 7.2 | — | Elastic | Elasticsearch | CWE-863 | Incorrect Authorization in Elasticsearch Leading to Privilege Escalation |
| CVE-2026-105861 | 7.2 | — | payloadcms | payload | CWE-200 | Payload external upload trust validation issue |
| CVE-2026-26287 | 7.1 | — | external-secrets | external-secrets | CWE-696 | External Secrets Operator: label enforcement bypass in webhook generator enab… |
| CVE-2026-70411 | 7.1 | — | Dell | Container Storage Modules (CSM) | CWE-306 | Dell Container Storage Modules (CSM), versions prior to 1.18.0, contains a Mi… |
| CVE-2026-83550 | 7.1 | — | Red Hat | Multicluster Global Hub | CWE-489 | Postgres-exporter: net/http/pprof exposed on metrics listener |
| CVE-2026-102155 | 7.1 | — | Arista Networks | CloudVision CUE | CWE-611 | Security Advisory 0190 |
| CVE-2026-102158 | 7.1 | — | Arista Networks | CloudVision CUE | CWE-74 | Security Advisory 0190 |
| CVE-2026-102168 | 7.1 | — | Arista Networks | Wi-Fi Access Points | CWE-191 | Security Advisory 0194 |
| CVE-2026-102169 | 7.1 | — | Arista Networks | Wi-Fi Access Points | CWE-476 | Security Advisory 0194 |
| CVE-2026-103009 | 7.1 | — | Elastic | Elasticsearch | CWE-639 | Authorization Bypass Through User-Controlled Key in Elasticsearch Leading to … |
| CVE-2026-104944 | 7.1 | — | TP-Link Systems Inc. | Tapo C500 v2.0 | CWE-823 | Unauthenticated TDP Function Pointer Dispatch Denial of Service in TP-Link Ta… |
| CVE-2026-105811 | 7.1 | — | aws | qnabot-on-aws | CWE-639 | Authorization bypass through a user-controlled key in the Amazon Q Business L… |
| CVE-2026-105834 | 7.1 | — | rundeck | rundeck | CWE-22 | Rundeck before 6.2.0 Arbitrary File Read via File Resource Model Source |
| CVE-2026-105847 | 7.1 | — | payloadcms | payload | CWE-200 | Payload: Polymorphic join queries could disclose hidden fields |
| CVE-2026-105853 | 7.1 | — | payloadcms | payload | CWE-200 | Payload: Token refresh and password reset responses may expose restricted use… |
| CVE-2026-105860 | 7.1 | — | payloadcms | payload | CWE-862 | Payload: Tenant authorization bypass in Multi-Tenant Plugin |
| CVE-2026-105867 | 7.1 | — | payloadcms | payload | CWE-639 | Payload: Client uploads could overwrite S3 objects |
| CVE-2026-106100 | 7.1 | — | payloadcms | payload | CWE-639 | Payload: Field-level write access bypass in Payload on MongoDB |
| CVE-2026-106103 | 7.1 | — | quasarframework | quasar | CWE-22 | Quasar Framework: Path Traversal / Arbitrary File Write via crafted Icon Geni… |
| CVE-2026-106106 | 7.1 | — | quasarframework | quasar | CWE-79 | Quasar Framework: SSR/SSG dev error page discloses the full shell environment… |
| CVE-2026-56906 | 7.0 | — | Android | CWE-362 | In ep_free of eventpoll.c, there is a possible use-after-free due to a race c… | |
| CVE-2026-84854 | 7.0 | — | wibu-systems-ag | wibukey | CWE-787 | Out of Bound Write on WibuKey for Windows |
| CVE-2025-8352 | 6.9 | — | ESET spol. s.r.o | ESET PROTECT On-Prem | CWE-770 | Denial-of-service vulnerability in ESET PROTECT On-Prem |
| CVE-2026-66666 | 6.9 | — | Automattic | WordPress | CWE-201 | WordPress Core <= 7.1.2 - Unauthenticated Sensitive Data Exposure of Comments… |
| CVE-2026-77050 | 6.9 | — | djangoproject | Django | CWE-789 | Potential denial-of-service vulnerability in get_supported_language_variant() |
| CVE-2026-84429 | 6.9 | — | djangoproject | Django | CWE-407 | Potential denial-of-service vulnerability in HTTP header parsing |
| CVE-2026-87890 | 6.9 | — | djangoproject | Django | CWE-918 | Potential request forgery via spatial lookup byte values |
| CVE-2026-102156 | 6.9 | — | Arista Networks | CloudVision CUE | CWE-74 | Security Advisory 0191 |
| CVE-2026-104073 | 6.9 | — | netbox-community | netbox | CWE-79 | NetBox 2.9.5 < 4.7.0 Session Hijacking via Custom Links |
| CVE-2026-105805 | 6.9 | — | payloadcms | payload | CWE-200 | Payload: Sort queries could expose protected field information |
| CVE-2026-105852 | 6.9 | — | payloadcms | payload | CWE-862 | Payload relationship-query authorization bypass |
| CVE-2026-105866 | 6.9 | — | payloadcms | payload | CWE-307 | Payload: Unauthenticated account-lockout denial of service |
| CVE-2026-106039 | 6.9 | — | kvcache-ai | Mooncake | CWE-862 | Mooncake Store through 0.3.13.post1 Missing Authorization in Replication Task… |
| CVE-2026-106041 | 6.9 | — | kvcache-ai | Mooncake | CWE-862 | Mooncake Store through 0.3.13.post1 Missing Authorization via NotifyOffloadSu… |
| CVE-2026-106513 | 6.9 | — | MISP | MISP | CWE-284 | MISP: Site-Admin Can Repoint Redis Workers to Attacker-Controlled Server via … |
| CVE-2026-19029 | 6.8 | — | The HDF Group | HDF5 | CWE-125 | HDF5 scale-offset filter heap buffer over-read via crafted chunk |
| CVE-2026-56936 | 6.8 | — | Android | CWE-119 | In wacom_hid_set_device_mode of wacom_sys.c, there is a possible out-of-bound… | |
| CVE-2026-104048 | 6.8 | — | Red Hat | Red Hat Enterprise Linux 10 | CWE-1025 | Sssd: sssd: authorization bypass via cross-domain username collision in hbac … |
| CVE-2026-104945 | 6.8 | — | TP-Link Systems Inc. | Tapo C500 v2.0 | CWE-121 | Authenticated ONVIF PTZ Out-of-Bounds Stack Write Denial of Service in TP-Lin… |
| CVE-2026-105485 | 6.8 | — | Devolutions | Server | CWE-294 | Authentication bypass OAuth device authorization flow in Devolutions Server 2… |
| CVE-2026-105838 | 6.8 | — | sezero | libmikmod | CWE-125 | libmikmod before 3.3.14 Heap Out-of-Bounds Read via IT Module Loader |
| CVE-2026-106457 | 6.8 | — | backstage | backstage | CWE-287 | Backstage: Insufficient audience validation in the Cloudflare Access auth pro… |
| CVE-2026-106460 | 6.8 | — | backstage | backstage | CWE-287 | Backstage: Explicit negative email verification can be ignored during shared … |
| CVE-2026-56952 | 6.7 | — | Android | CWE-862 | In platform_msg_handler_init of default_msg_handlers.c, there is a possible p… | |
| CVE-2026-79813 | 6.7 | — | Hewlett Packard Enterprise (HPE) | ClearPass Policy Manager (CPPM) | — | Local Privilege Escalation in ClearPass Client Software |
| CVE-2026-79814 | 6.7 | — | Hewlett Packard Enterprise (HPE) | ClearPass Policy Manager (CPPM) | — | Local Arbitrary File Write Leading to Local Privilege Escalation in ClearPass… |
| CVE-2026-63689 | 6.5 | — | Dell | Container Storage Modules | CWE-532 | Dell Container Storage Modules, versions prior to 1.18.0, contain(s) an Inser… |
| CVE-2026-76741 | 6.5 | — | Hewlett Packard Enterprise (HPE) | AOS-Switch (AOS-S) | — | Authenticated Buffer Overflow Vulnerabilities lead to Denial-of-Service in AOS-S |
| CVE-2026-76749 | 6.5 | — | Hewlett Packard Enterprise (HPE) | AOS-Switch (AOS-S) | — | Unauthenticated Sensitive Information Disclosure in AOS-S |
| CVE-2026-79815 | 6.5 | — | Hewlett Packard Enterprise (HPE) | ClearPass Policy Manager (CPPM) | — | Authenticated Command Injection Vulnerability in the ClearPass Policy Manager… |
| CVE-2026-101329 | 6.5 | — | IBM | Langflow OSS | CWE-284 | Langflow OSS is affected by multiple vulnerabilities |
| CVE-2026-102404 | 6.5 | — | Elastic | Elasticsearch | CWE-400 | Uncontrolled Resource Consumption in Elasticsearch Leading to Denial of Service |
| CVE-2026-102409 | 6.5 | — | Elastic | Elasticsearch | CWE-674 | Uncontrolled Recursion in Elasticsearch Leading to Denial of Service |
| CVE-2026-102411 | 6.5 | — | Elastic | Elasticsearch | CWE-770 | Allocation of Resources Without Limits or Throttling in Elasticsearch Leading… |
| CVE-2026-102412 | 6.5 | — | Elastic | Kibana | CWE-863 | Incorrect Authorization in Kibana Leading to Sensitive Information Disclosure |
| CVE-2026-103005 | 6.5 | — | Elastic | Elasticsearch | CWE-789 | Memory Allocation with Excessive Size Value in Elasticsearch Leading to Denia… |
| CVE-2026-103006 | 6.5 | — | Elastic | Elasticsearch | CWE-674 | Uncontrolled Recursion in Elasticsearch Leading to Denial of Service |
| CVE-2026-103008 | 6.5 | — | Elastic | Elasticsearch | CWE-674 | Uncontrolled Recursion in Elasticsearch Leading to Denial of Service |
| CVE-2026-105792 | 6.5 | — | microsoft | UFO | CWE-833 | Microsoft UFO: Authenticated task-result request can deadlock UFO server sess… |
| CVE-2026-106219 | 6.5 | — | JetBrains | TeamCity | CWE-73 | In JetBrains TeamCity before 2026.2.1 missing validation of Git submodule URL… |
| CVE-2026-106312 | 6.5 | — | Chrome | CWE-862 | Missing authorization in SignIn in Google Chrome prior to 155.0.8059.39 allow… | |
| CVE-2026-106458 | 6.5 | — | backstage | backstage | CWE-863 | Backstage: Inconsistent repository filtering in Bitbucket Server catalog even… |
| CVE-2026-106489 | 6.5 | — | backstage | backstage | CWE-22 | Backstage: Improper authorization enforcement for TechDocs static content |
| CVE-2026-106490 | 6.5 | — | backstage | backstage | CWE-22 | Backstage: Improper input validation in TechDocs static content requests |
| CVE-2026-106504 | 6.5 | — | backstage | backstage | CWE-532 | Backstage: Sensitive information exposure in scaffolder task logs |
| CVE-2026-106585 | 6.5 | — | OpenBSD | OpenSSH | CWE-409 | In sshd and ssh in OpenSSH before 10.6, there is no check for whether the max… |
| CVE-2026-105790 | 6.4 | — | microsoft | UFO | CWE-918 | Microsoft UFO: Authenticated Galaxy device registration can bypass WebSocket … |
| CVE-2026-105848 | 6.4 | — | payloadcms | payload | CWE-749 | Payload: Insufficient Access Control in Stripe REST Proxy |
| CVE-2026-106462 | 6.4 | — | backstage | backstage | CWE-441 | Backstage: Scaffolder credential handling may allow unintended GitHub authent… |
| CVE-2026-106491 | 6.4 | — | backstage | backstage | CWE-20 | Backstage: Improper input validation in proxy-backend |
| CVE-2026-79816 | 6.3 | — | Hewlett Packard Enterprise (HPE) | ClearPass Policy Manager (CPPM) | — | Unauthenticated DOM-Based Cross-Site Scripting (XSS) Vulnerability in the Cle… |
| CVE-2026-106026 | 6.3 | — | H. Peter Anvin | tftp-hpa | CWE-125 | tftp-hpa 5.4 before 6.0 Out-of-Bounds Read via tftpd Remap Jump Rule |
| CVE-2026-106063 | 6.3 | — | Red Hat | Red Hat Enterprise Linux 10 | CWE-119 | Gimp: gimp: heap buffer overflow in dicom export on oversized image dimensions |
| CVE-2026-101156 | 6.2 | — | Arista Networks | CloudVision CUE | CWE-79 | Security Advisory 0192 |
| CVE-2026-102413 | 6.2 | — | Elastic | Elastic Agent and Elastic Defend | CWE-248 | Uncaught Exception in Elastic Endpoint Leading to Denial of Service |
| CVE-2026-103778 | 6.2 | — | Dell | Command | Configure (DCC) | CWE-321 | Dell Command | Configure (DCC), versions prior to 5.2.3.35 contain a Use of H… |
| CVE-2026-104046 | 6.2 | — | Red Hat | Red Hat Enterprise Linux 10 | CWE-770 | Sssd: sssd: denial of service via incomplete identity provider authentication… |
| CVE-2026-12380 | 6.1 | — | Akıllı Ticaret Software Technologies Ltd. Co. | E-Commerce Pack | CWE-79 | Reflected XSS in Akıllı Ticaret's E-Commerce Pack |
| CVE-2026-63691 | 6.1 | — | Dell | Container Storage Modules | CWE-862 | Dell Container Storage Modules, versions prior to 1.18.0, contain(s) a Missin… |
| CVE-2026-79812 | 6.1 | — | Hewlett Packard Enterprise (HPE) | ClearPass Policy Manager (CPPM) | — | Authenticated Local Denial-of-Service Vulnerability in the OnGuard Agent of C… |
| CVE-2026-105842 | 6.1 | — | Uwe Ohse | lrzsz | CWE-122 | lrzsz before 0.13.0 Heap Buffer Overflow via lrz procheader() Pathname |
| CVE-2026-105846 | 6.1 | — | payloadcms | payload | CWE-601 | Payload: Untrusted redirect URL parameter exploit |
| CVE-2026-102157 | 6.0 | — | Arista Networks | CloudVision CUE | CWE-639 | Security Advisory 0190 |
| CVE-2026-103620 | 6.0 | — | GitHub | Enterprise Server | CWE-862 | Missing authorization in GitHub Enterprise Server allowed repository writers … |
| CVE-2026-106119 | 6.0 | — | langchain-ai | langchainjs | CWE-943 | LangChain: MongoDBChatMessageHistory query injection can allow cross-session … |
| CVE-2026-106120 | 6.0 | — | harttle | liquidjs | CWE-200 | LiquidJS: ownPropertyOnly bypass for inherited array indices in first/last/jo… |
| CVE-2026-106122 | 6.0 | — | rabbitmq | rabbitmq-java-client | CWE-172 | RabbitMQ: Malformed UTF-8 in shortstr properties permanently disables RPC con… |
| CVE-2026-106111 | 5.9 | — | SixLabors | ImageSharp | CWE-226 | ImageSharp: EXR ZIP decoder can expose stale allocator data after a short inf… |
| CVE-2026-106183 | 5.9 | — | Chrome | CWE-862 | Missing authorization in Chromoting in Google Chrome on on Windows prior to 1… | |
| CVE-2026-106206 | 5.9 | — | Chrome | CWE-20 | Improper input validation in Mobile in Google Chrome on on iOS prior to 155.0… | |
| CVE-2026-106222 | 5.9 | — | Chrome | CWE-863 | Incorrect authorization in Sync in Google Chrome prior to 155.0.8059.39 allow… | |
| CVE-2026-106328 | 5.9 | — | Chrome | CWE-863 | Incorrect authorization in PDF in Google Chrome on on Android prior to 155.0.… | |
| CVE-2026-105804 | 5.7 | — | payloadcms | payload | CWE-916 | Payload: Password hashes use insufficient PBKDF2 iterations |
| CVE-2026-106032 | 5.7 | — | aws | bedrock-agentcore-starter-toolkit | CWE-918 | Server-side request forgery and local file read via unrestricted external Ope… |
| CVE-2026-106123 | 5.7 | — | rabbitmq | rabbitmq-java-client | CWE-509 | RabbitMQ Java client: plaintext broker credentials leaked in exception messag… |
| CVE-2026-65122 | 5.5 | — | NVIDIA | TensorRT | CWE-125 | NVIDIA TensorRT contains a vulnerability where an attacker can cause an out o… |
| CVE-2026-70414 | 5.5 | — | Dell | Command | Configure (DCC) | CWE-256 | Dell Command | Configure (DCC), versions prior to 5.2.3.35, contain a Plainte… |
| CVE-2026-76061 | 5.5 | — | — | cri-o | CWE-59 | Cri-o: cri-o: bind_mount_prefix intermediate-symlink prefix bypass |
| CVE-2026-79817 | 5.5 | — | Hewlett Packard Enterprise (HPE) | ClearPass Policy Manager (CPPM) | — | Local Disclosure of Sensitive Information in HPE Networking ClearPass Policy … |
| CVE-2026-105918 | 5.5 | — | Kusalkasilva | Learning-Management-System | CWE-74 | Kusalkasilva Learning-Management-System Login Endpoint login.php mysql_error … |
| CVE-2026-105919 | 5.5 | — | Kusalkasilva | Learning-Management-System | CWE-74 | Kusalkasilva Learning-Management-System Administrator Login Endpoint login.ph… |
| CVE-2026-105920 | 5.5 | — | Kusalkasilva | Learning-Management-System | CWE-74 | Kusalkasilva Learning-Management-System Student Registration Endpoint student… |
| CVE-2026-63690 | 5.4 | — | Dell | Container Storage Modules | CWE-306 | Dell Container Storage Modules, versions prior to 1.18.0, contain(s) a Missin… |
| CVE-2026-89182 | 5.4 | — | Gitea | Gitea | CWE-863 | Gitea push-to-create bypass of FORCE_PRIVATE policy |
| CVE-2026-102407 | 5.4 | — | Elastic | Elasticsearch | CWE-863 | Incorrect Authorization in Elasticsearch Leading to Unauthorized Data Stream … |
| CVE-2026-105789 | 5.4 | — | microsoft | UFO | CWE-88 | Microsoft UFO: Arbitrary file write in the Linux MCP `execute_command` tool |
| CVE-2026-106033 | 5.4 | — | Red Hat | Red Hat Ansible Automation Platform 2 | CWE-79 | Ansible: ansible-ui: ansible ui dom xss in /redirect next parameter |
| CVE-2026-106179 | 5.4 | — | Chrome | CWE-451 | UI misrepresentation in WebAppInstalls in Google Chrome prior to 155.0.8059.3… | |
| CVE-2026-106182 | 5.4 | — | Chrome | CWE-451 | UI misrepresentation in Paint in Google Chrome prior to 155.0.8059.39 allowed… | |
| CVE-2026-106209 | 5.4 | — | Chrome | CWE-451 | UI misrepresentation in Mobile in Google Chrome on on iOS prior to 155.0.8059… | |
| CVE-2026-106229 | 5.4 | — | Chrome | CWE-451 | UI misrepresentation in FileSystem in Google Chrome prior to 155.0.8059.39 al… | |
| CVE-2026-106232 | 5.4 | — | Chrome | CWE-451 | UI misrepresentation in Browser in Google Chrome prior to 155.0.8059.39 allow… | |
| CVE-2026-106236 | 5.4 | — | Chrome | CWE-451 | UI misrepresentation in Chromoting in Google Chrome on on Windows prior to 15… | |
| CVE-2026-106246 | 5.4 | — | Chrome | CWE-863 | Incorrect authorization in Browser in Google Chrome prior to 155.0.8059.39 al… | |
| CVE-2026-106251 | 5.4 | — | Chrome | CWE-451 | UI misrepresentation in Chromoting in Google Chrome on on Mac prior to 155.0.… | |
| CVE-2026-106264 | 5.4 | — | Chrome | CWE-862 | Missing authorization in Web Authentication (Passkeys & Security Keys) in Goo… | |
| CVE-2026-106265 | 5.4 | — | Chrome | CWE-451 | UI misrepresentation in File in Google Chrome prior to 155.0.8059.39 allowed … | |
| CVE-2026-106270 | 5.4 | — | Chrome | CWE-863 | Incorrect authorization in WebAppInstalls in Google Chrome prior to 155.0.805… | |
| CVE-2026-106272 | 5.4 | — | Chrome | CWE-451 | UI misrepresentation in Chromoting in Google Chrome on on Windows prior to 15… | |
| CVE-2026-106276 | 5.4 | — | Chrome | CWE-451 | UI misrepresentation in Payments in Google Chrome prior to 155.0.8059.39 allo… | |
| CVE-2026-106282 | 5.4 | — | Chrome | CWE-451 | UI misrepresentation in WebOTP in Google Chrome prior to 155.0.8059.39 allowe… | |
| CVE-2026-106285 | 5.4 | — | Chrome | CWE-451 | UI misrepresentation in WebAppInstalls in Google Chrome prior to 155.0.8059.3… | |
| CVE-2026-106302 | 5.4 | — | Chrome | CWE-451 | UI misrepresentation in PermissionElement in Google Chrome prior to 155.0.805… | |
| CVE-2026-106305 | 5.4 | — | Chrome | CWE-451 | UI misrepresentation in Mobile in Google Chrome on on Android prior to 155.0.… | |
| CVE-2026-106311 | 5.4 | — | Chrome | CWE-1021 | Clickjacking in PermissionElement in Google Chrome prior to 155.0.8059.39 all… | |
| CVE-2026-106316 | 5.4 | — | Chrome | CWE-451 | UI misrepresentation in Chromoting in Google Chrome on on Mac prior to 155.0.… | |
| CVE-2026-106317 | 5.4 | — | Chrome | CWE-451 | UI misrepresentation in FullScreen in Google Chrome on on Android prior to 15… | |
| CVE-2026-106333 | 5.4 | — | Chrome | CWE-863 | Incorrect authorization in Input in Google Chrome prior to 155.0.8059.39 allo… | |
| CVE-2026-106337 | 5.4 | — | Chrome | CWE-451 | UI misrepresentation in UI in Google Chrome on on Android prior to 155.0.8059… | |
| CVE-2026-106338 | 5.4 | — | Chrome | CWE-451 | UI misrepresentation in PictureInPicture in Google Chrome on on Android prior… | |
| CVE-2026-106343 | 5.4 | — | Chrome | CWE-754 | Improper state validation in Autofill AI in Google Chrome on on Android prior… | |
| CVE-2026-106356 | 5.4 | — | Chrome | CWE-1021 | Clickjacking in EVP in Google Chrome prior to 155.0.8059.39 allowed a remote … | |
| CVE-2026-106368 | 5.4 | — | Chrome | CWE-451 | UI misrepresentation in UI in Google Chrome on on Android prior to 155.0.8059… | |
| CVE-2026-106380 | 5.4 | — | Chrome | CWE-451 | UI misrepresentation in UI in Google Chrome prior to 155.0.8059.39 allowed a … | |
| CVE-2026-106400 | 5.4 | — | Chrome | CWE-1021 | Clickjacking in Messages in Google Chrome on on Android prior to 155.0.8059.3… | |
| CVE-2026-106406 | 5.4 | — | Chrome | CWE-862 | Missing authorization in Mobile in Google Chrome on on iOS prior to 155.0.805… | |
| CVE-2026-106416 | 5.4 | — | Chrome | CWE-94 | Code injection in Extensions in Google Chrome prior to 155.0.8059.39 allowed … | |
| CVE-2026-106420 | 5.4 | — | Chrome | CWE-682 | Incorrect calculation in API in Google Chrome on on Windows prior to 155.0.80… | |
| CVE-2026-106463 | 5.4 | — | backstage | backstage | CWE-863 | Backstage: Improper authorization in GitLab organizational user ingestion |
| CVE-2025-15591 | 5.3 | — | OpenText | Content Management | CWE-79 | Cross-Site Scripting (XSS) vulnerability identified in OpenText™ Content Mana… |
| CVE-2026-79818 | 5.3 | — | Hewlett Packard Enterprise (HPE) | ClearPass Policy Manager (CPPM) | — | Authentication Bypass in the API Interface Allows Unauthorized Information Di… |
| CVE-2026-82924 | 5.3 | — | Pusula Communication, IT, and Internet Industry and Trade Co. Ltd. | Expert Mail | CWE-799 | PII Enumeration via Missing Rate Limiting in Pusula Communication's Expert Mail |
| CVE-2026-87975 | 5.3 | — | djangoproject | Django | CWE-639 | Privilege abuse in model formsets with editable primary keys |
| CVE-2026-101151 | 5.3 | — | Arista Networks | CloudVision Portal | CWE-601 | Security Advisory 0187 |
| CVE-2026-104047 | 5.3 | — | Red Hat | Red Hat Enterprise Linux 10 | CWE-140 | Sssd: sssd: information disclosure via query injection in entra id lookups |
| CVE-2026-105239 | 5.3 | — | Apache Software Foundation | Apache log4net | CWE-158 | Apache log4net: NUL character truncates EventLogAppender records |
| CVE-2026-105240 | 5.3 | — | Apache Software Foundation | Apache log4net | CWE-158 | Apache log4net: NUL character truncates OutputDebugStringAppender records |
| CVE-2026-105241 | 5.3 | — | Apache Software Foundation | Apache log4net | CWE-176 | Apache log4net: Unencodable content discards a whole SmtpPickupDirAppender batch |
| CVE-2026-105242 | 5.3 | — | Apache Software Foundation | Apache log4net | CWE-755 | Apache log4net: Request validation failure drops the event in the aspnet-requ… |
| CVE-2026-105243 | 5.3 | — | Apache Software Foundation | Apache log4net | CWE-778 | Apache log4net: Oversize EventLogAppender record silently discarded |
| CVE-2026-105244 | 5.3 | — | Apache Software Foundation | Apache log4net | CWE-116 | Apache log4net: RemoteSyslogAppender silently deletes non-ASCII content |
| CVE-2026-105836 | 5.3 | — | Webkul | QloApps | CWE-639 | QloApps through 1.7.0 Authorization Bypass via ajaxProcessBulkUpdateRooms |
| CVE-2026-105864 | 5.3 | — | payloadcms | payload | CWE-863 | Payload: Cross-tenant create in @payloadcms/plugin-multi-tenant |
| CVE-2026-106114 | 5.3 | — | SixLabors | ImageSharp | CWE-789 | ImageSharp: ICC CLUT parsing allocates from unvalidated channel and grid dime… |
| CVE-2026-106116 | 5.3 | — | SixLabors | ImageSharp | CWE-835 | ImageSharp: BigTIFF IFD count can keep a decoder thread in a non-progressing … |
| CVE-2026-106181 | 5.3 | — | Chrome | CWE-706 | Incorrect reference resolution in DevTools in Google Chrome prior to 155.0.80… | |
| CVE-2026-106214 | 5.3 | — | Chrome | CWE-200 | Information leak in Proxy in Google Chrome on on Windows prior to 155.0.8059.… | |
| CVE-2026-106230 | 5.3 | — | Chrome | CWE-706 | Incorrect reference resolution in Offline in Google Chrome on on Android prio… | |
| CVE-2026-106243 | 5.3 | — | Chrome | CWE-459 | Incomplete cleanup in Proxy Auth in Google Chrome prior to 155.0.8059.39 allo… | |
| CVE-2026-106303 | 5.3 | — | Chrome | CWE-203 | Observable discrepancy in Autofill AI in Google Chrome prior to 155.0.8059.39… | |
| CVE-2026-106351 | 5.3 | — | Chrome | CWE-203 | Observable discrepancy in Safebrowsing in Google Chrome on on iOS prior to 15… | |
| CVE-2026-106355 | 5.3 | — | Chrome | CWE-862 | Missing authorization in Media in Google Chrome on on Windows prior to 155.0.… | |
| CVE-2026-106364 | 5.3 | — | Chrome | CWE-863 | Incorrect authorization in Omnibox in Google Chrome prior to 155.0.8059.39 al… | |
| CVE-2026-106388 | 5.3 | — | Chrome | CWE-862 | Missing authorization in DataTransfer in Google Chrome prior to 155.0.8059.39… | |
| CVE-2026-106450 | 5.3 | — | yawkat | lz4-java | CWE-770 | yawkat LZ4 Java: LZ4FrameInputStream reallocates block buffers for every fram… |
| CVE-2026-106452 | 5.3 | — | yawkat | lz4-java | CWE-789 | yawkat LZ4 Java: LZ4BlockInputStream allocates an unvalidated compressed leng… |
| CVE-2026-106453 | 5.3 | — | yawkat | lz4-java | CWE-789 | yawkat LZ4 Java: LZ4DecompressorWithLength allocates the unvalidated size fro… |
| CVE-2026-106502 | 5.3 | — | backstage | backstage | CWE-532 | Backstage: Sensitive information may be exposed in Scaffolder task failure ev… |
| CVE-2026-106506 | 5.3 | — | backstage | backstage | CWE-202 | Backstage: Improper input validation in scaffolder task list ordering |
| CVE-2026-106507 | 5.3 | — | backstage | backstage | CWE-59 | Backstage: TechDocs arbitrary file read via mkdocs snippets |
| CVE-2026-106508 | 5.3 | — | backstage | backstage | CWE-22 | Backstage: Potential file exposure through local TechDocs publisher |
| CVE-2026-34498 | 5.1 | — | Johnson Controls | Illustra Standard - L4L China | CWE-20 | L4L |
| CVE-2026-101149 | 5.1 | — | Arista Networks | CloudVision Portal | CWE-918 | Security Advisory 0186 |
| CVE-2026-101150 | 5.1 | — | Arista Networks | CloudVision Portal | CWE-918 | Security Advisory 0186 |
| CVE-2026-105950 | 5.1 | — | getformwork | formwork | CWE-79 | getformwork URI Sanitizer DomSanitizer.php sanitizeNodeAttribute cross site s… |
| CVE-2026-106254 | 5.1 | — | Chrome | CWE-200 | Information leak in Mobile in Google Chrome on on Android prior to 155.0.8059… | |
| CVE-2026-106313 | 5.1 | — | Chrome | CWE-863 | Incorrect authorization in Browser in Google Chrome on on Android prior to 15… | |
| CVE-2026-95153 | 4.9 | — | n/a | n/a | CWE-200 | An issue in Bludit CMS 3.22.0 allows a remote attacker to obtain sensitive in… |
| CVE-2026-106121 | 4.9 | — | rabbitmq | rabbitmq-java-client | CWE-835 | RabbitMQ: JSONReader in the default JSON-RPC mapper never terminates on trunc… |
| CVE-2026-106499 | 4.9 | — | backstage | backstage | CWE-532 | Backstage: Secret-derived values may be exposed in scaffolder task logs |
| CVE-2026-106402 | 4.8 | — | Chrome | CWE-863 | Incorrect authorization in Extensions in Google Chrome prior to 155.0.8059.39… | |
| CVE-2026-106456 | 4.8 | — | backstage | backstage | CWE-863 | Backstage: Inconsistent credential enforcement for overlapping proxy routes |
| CVE-2026-88252 | 4.7 | — | Red Hat | Red Hat Enterprise Linux 10 | CWE-835 | Sssd: sssd: denial of service via responder connection retry loop during file… |
| CVE-2026-104045 | 4.7 | — | Red Hat | Red Hat Enterprise Linux 10 | CWE-772 | Sssd: sssd: denial of service via race condition in autofs responder |
| CVE-2026-106444 | 4.7 | — | handlebars-lang | handlebars.js | CWE-116 | Handlebars: JavaScript Injection via Unsafe Inline Embedding of Precompiled T… |
| CVE-2026-106192 | 4.6 | — | Chrome | CWE-200 | Information leak in Mobile in Google Chrome on on iOS prior to 155.0.8059.39 … | |
| CVE-2026-106340 | 4.6 | — | Chrome | CWE-862 | Missing authorization in CredentialProvider in Google Chrome on on Windows pr… | |
| CVE-2026-0198 | 4.4 | — | Android | CWE-862 | In is_pd_allowed of gem_msg.c, there is a possible permission bypass due to a… | |
| CVE-2026-55307 | 4.4 | — | Android | CWE-269 | In kdn_set_sysregs_prot of hwcrypto-kdn.c, there is a possible information di… | |
| CVE-2026-106494 | 4.4 | — | backstage | backstage | CWE-22 | Backstage: Improper input validation in cloud storage URL readers |
| CVE-2026-96400 | 4.3 | — | Gitea | Gitea | CWE-918 | Gitea migration SSRF to reserved addresses through ALLOWED_DOMAINS |
| CVE-2026-102408 | 4.3 | — | Elastic | Elasticsearch | CWE-1333 | Inefficient Regular Expression Complexity in Elasticsearch Leading to Denial … |
| CVE-2026-102410 | 4.3 | — | Elastic | Kibana | CWE-862 | Missing Authorization in Kibana Leading to Information Disclosure |
| CVE-2026-106184 | 4.3 | — | Chrome | CWE-908 | Uninitialized resource in Media in Google Chrome prior to 155.0.8059.39 allow… | |
| CVE-2026-106213 | 4.3 | — | Chrome | CWE-362 | Race condition in WebAudio in Google Chrome prior to 155.0.8059.39 allowed a … | |
| CVE-2026-106217 | 4.3 | — | Chrome | CWE-862 | Missing authorization in Google Lens in Google Chrome prior to 155.0.8059.39 … | |
| CVE-2026-106245 | 4.3 | — | Chrome | CWE-908 | Uninitialized resource in ANGLE in Google Chrome prior to 155.0.8059.39 allow… | |
| CVE-2026-106253 | 4.3 | — | Chrome | CWE-863 | Incorrect authorization in Extensions in Google Chrome prior to 155.0.8059.39… | |
| CVE-2026-106260 | 4.3 | — | Chrome | CWE-863 | Incorrect authorization in DevTools in Google Chrome prior to 155.0.8059.39 a… | |
| CVE-2026-106277 | 4.3 | — | Chrome | CWE-200 | Information leak in Animation in Google Chrome prior to 155.0.8059.39 allowed… | |
| CVE-2026-106321 | 4.3 | — | Chrome | CWE-200 | Information leak in Editing in Google Chrome prior to 155.0.8059.39 allowed a… | |
| CVE-2026-106325 | 4.3 | — | Chrome | CWE-706 | Incorrect reference resolution in Core in Google Chrome prior to 155.0.8059.3… | |
| CVE-2026-106330 | 4.3 | — | Chrome | CWE-200 | Information leak in Paint in Google Chrome prior to 155.0.8059.39 allowed a r… | |
| CVE-2026-106332 | 4.3 | — | Chrome | CWE-190 | Integer overflow in Compositing in Google Chrome prior to 155.0.8059.39 allow… | |
| CVE-2026-106336 | 4.3 | — | Chrome | CWE-203 | Observable discrepancy in Paint in Google Chrome prior to 155.0.8059.39 allow… | |
| CVE-2026-106354 | 4.3 | — | Chrome | CWE-668 | Improper resource exposure in Extensions in Google Chrome prior to 155.0.8059… | |
| CVE-2026-106360 | 4.3 | — | Chrome | CWE-200 | Information leak in Payments in Google Chrome prior to 155.0.8059.39 allowed … | |
| CVE-2026-106379 | 4.3 | — | Chrome | CWE-908 | Uninitialized resource in Skia in Google Chrome prior to 155.0.8059.39 allowe… | |
| CVE-2026-106390 | 4.3 | — | Chrome | CWE-684 | Incorrect provision of specified functionality in SanitizerAPI in Google Chro… | |
| CVE-2026-106392 | 4.3 | — | Chrome | CWE-200 | Information leak in WebAudio in Google Chrome prior to 155.0.8059.39 allowed … | |
| CVE-2026-106394 | 4.3 | — | Chrome | CWE-459 | Incomplete cleanup in Glic in Google Chrome prior to 155.0.8059.39 allowed a … | |
| CVE-2026-106398 | 4.3 | — | Chrome | CWE-863 | Incorrect authorization in Media in Google Chrome prior to 155.0.8059.39 allo… | |
| CVE-2026-106415 | 4.3 | — | Chrome | CWE-200 | Information leak in Enterprise in Google Chrome prior to 155.0.8059.39 allowe… | |
| CVE-2026-106454 | 4.3 | — | twisted | twisted | CWE-1333 | Twisted: IMAP wildcardToRegexp() ReDoS |
| CVE-2026-106461 | 4.3 | — | backstage | backstage | CWE-863 | Backstage: Incorrect authorization in scaffolder task listing |
| CVE-2026-106497 | 4.3 | — | backstage | backstage | CWE-178 | Backstage: Inconsistent catalog property permission evaluation |
| CVE-2026-106187 | 4.2 | — | Chrome | CWE-862 | Missing authorization in Permissions in Google Chrome prior to 155.0.8059.39 … | |
| CVE-2026-106226 | 4.2 | — | Chrome | CWE-20 | Improper input validation in Compositing in Google Chrome prior to 155.0.8059… | |
| CVE-2026-106262 | 4.2 | — | Chrome | CWE-459 | Incomplete cleanup in GetUserMedia in Google Chrome prior to 155.0.8059.39 al… | |
| CVE-2026-106295 | 4.2 | — | Chrome | CWE-863 | Incorrect authorization in Unbounded Element in Google Chrome prior to 155.0.… | |
| CVE-2026-106320 | 4.2 | — | Chrome | CWE-672 | Use of released resource in UI in Google Chrome prior to 155.0.8059.39 allowe… | |
| CVE-2026-106345 | 4.2 | — | Chrome | CWE-672 | Use of released resource in Session in Google Chrome prior to 155.0.8059.39 a… | |
| CVE-2026-106391 | 4.2 | — | Chrome | CWE-863 | Incorrect authorization in WebShare in Google Chrome on on Android prior to 1… | |
| CVE-2026-106410 | 4.2 | — | Chrome | CWE-862 | Missing authorization in Permissions in Google Chrome prior to 155.0.8059.39 … | |
| CVE-2026-106413 | 4.2 | — | Chrome | CWE-367 | Race condition in Browser in Google Chrome prior to 155.0.8059.39 allowed a r… | |
| CVE-2026-106552 | 4.2 | — | OpenBSD | OpenSSH | CWE-23 | In sftp in OpenSSH before 10.6, a server can trigger directory traversal (cau… |
| CVE-2026-106109 | 4.1 | — | quasarframework | quasar | CWE-22 | Quasar Framework: App Vite build cleanup can recursively remove unsafe config… |
| CVE-2026-105800 | 3.7 | — | i18next | i18next-http-backend | CWE-74 | i18next-http-backend incomplete URL validation permits SSRF |
| CVE-2026-106449 | 3.7 | — | yawkat | lz4-java | CWE-674 | yawkat LZ4 Java: LZ4BlockInputStream with stopOnEmptyBlock=false recurses onc… |
| CVE-2026-106582 | 3.7 | — | OpenBSD | OpenSSH | CWE-514 | In sshd and ssh in OpenSSH before 10.6, an LZ77 dictionary coder can be used … |
| CVE-2026-106587 | 3.6 | — | OpenBSD | OpenSSH | CWE-843 | In sshd in OpenSSH before 10.6, the value "none" for a configuration option i… |
| CVE-2026-56596 | 3.5 | — | HCL Software | HCL BigFix Service Management | CWE-20 | HCL BigFix Service Management is affected by multiple security vulnerabilities. |
| CVE-2026-106487 | 3.5 | — | backstage | backstage | CWE-441 | Backstage: Unsupported catalog cluster authentication mode in kubernetes backend |
| CVE-2026-105795 | 3.1 | — | microsoft | kiota | CWE-22 | Kiota: Unsafe oauth_card_path references in Kiota-generated API plugin manifests |
| CVE-2026-106101 | 3.1 | — | quasarframework | quasar | CWE-843 | Quasar Framework: DOM Clobbering in Quasar openURL() SafariViewController Int… |
| CVE-2026-106180 | 3.1 | — | Chrome | CWE-203 | Observable discrepancy in Animation in Google Chrome prior to 155.0.8059.39 a… | |
| CVE-2026-106210 | 3.1 | — | Chrome | CWE-203 | Observable discrepancy in Scroll in Google Chrome prior to 155.0.8059.39 allo… | |
| CVE-2026-106224 | 3.1 | — | Chrome | CWE-862 | Missing authorization in Google Lens in Google Chrome prior to 155.0.8059.39 … | |
| CVE-2026-106339 | 3.1 | — | Chrome | CWE-672 | Use of released resource in Core in Google Chrome prior to 155.0.8059.39 allo… | |
| CVE-2026-106496 | 3.1 | — | backstage | backstage | CWE-22 | Backstage: Inconsistent enforcement of allowed location types during catalog … |
| CVE-2026-106588 | 3.1 | — | OpenBSD | OpenSSH | CWE-653 | In sshd in OpenSSH through 10.6, use of the macOS 27 (or later) SDK has the s… |
| CVE-2026-106493 | 3.0 | — | backstage | backstage | CWE-22 | Backstage: Cloud storage catalog locations may cross configured storage bound… |
| CVE-2026-106589 | 2.9 | — | OpenBSD | OpenSSH | CWE-272 | In sshd in OpenSSH through 10.6, in certain environments such as QNX 6 and SC… |
| CVE-2026-106583 | 2.5 | — | OpenBSD | OpenSSH | CWE-99 | In ssh in OpenSSH before 10.6, a $ or \ character can occur in a command-line… |
| CVE-2026-106584 | 2.5 | — | OpenBSD | OpenSSH | CWE-193 | In ssh-keygen in OpenSSH before 10.6, certificates could have incorrect expir… |
| CVE-2026-106586 | 2.5 | — | OpenBSD | OpenSSH | CWE-670 | In sshd in OpenSSH before 10.6, the restrict keyword (in authorized_keys) was… |
| CVE-2026-102164 | 2.3 | — | Arista Networks | Wi-Fi Access Points | CWE-125 | Security Advisory 0196 |
| CVE-2026-105111 | 2.3 | — | Apache Software Foundation | Apache Commons BCEL | CWE-79 | Apache Commons BCEL: Class2HTML emits unescaped class strings, enabling store… |
| CVE-2026-105799 | 2.3 | — | langchain-ai | langchainjs | CWE-943 | LangChain: RediSearch Filter Injection via Unescaped Tag/Text Values |
| CVE-2026-106553 | 2.2 | — | OpenBSD | OpenSSH | CWE-669 | In sshd in OpenSSH before 10.6, credentials can incorrectly persist after fai… |
| CVE-2026-106555 | 2.2 | — | OpenBSD | OpenSSH | CWE-669 | In sshd in OpenSSH before 10.6, GSSAPIAuthentication authentication state can… |
| CVE-2026-105921 | 2.1 | — | Kusalkasilva | Learning-Management-System | CWE-74 | Kusalkasilva Learning-Management-System search_class.php sql injection |
| CVE-2026-105922 | 2.1 | — | vllm-project | vLLM | CWE-404 | vllm-project vLLM Penalty utils.py get_token_bin_counts_and_mask denial of se… |
| CVE-2026-105957 | 2.1 | — | SourceCodester | Performance Indicator System | CWE-74 | SourceCodester Performance Indicator System view_product.php sql injection |
| CVE-2026-75818 | 1.8 | — | GNU | Aspell | CWE-122 | Heap Buffer Overflow in GNU Aspell's prezip utility |
| CVE-2026-75819 | 1.8 | — | GNU | Aspell | CWE-125 | Out-of-bounds Read in GNU Aspell |
| CVE-2026-75820 | 1.8 | — | GNU | Aspell | CWE-190 | Integer Truncation Leading to Heap Corruption in GNU Aspell |
| CVE-2025-45871 | await | — | n/a | n/a | — | LogicalDOC Enterprise up to and for 9.1.1 is vulnerable to blind SQL injectio… |
| CVE-2025-71383 | await | — | n/a | n/a | — | Dbit WIFI4 N300 1.0.0 devices allow the management interface to be crashed vi… |
| CVE-2025-71384 | await | — | n/a | n/a | — | Dbit WIFI4 N300 1.0.0 devices allows administrators (from the local Wi-Fi net… |
| CVE-2026-9226 | await | — | Devolutions | Server | CWE-294 | Authentication bypass in the Azure AD external login flow in Devolutions Serv… |
| CVE-2026-70357 | await | — | Gitea | Gitea | CWE-918 | Gitea repository migration SSRF through DNS rebinding |
| CVE-2026-73278 | await | — | Gitea | Gitea | CWE-287 | Gitea WebAuthn bypass during OAuth and OIDC sign-in |
| CVE-2026-79960 | await | — | Gitea | Gitea | CWE-863 | Gitea deploy key pushes acting as the repository owner |
| CVE-2026-80048 | await | — | Red Hat | Red Hat Enterprise Linux 10 | CWE-770 | Sssd: sssd-kcm: local denial of service via excessive memory preallocation |
| CVE-2026-86684 | await | — | Gitea | Gitea | CWE-863 | Gitea push mirror local path check uses the repository owner |
| CVE-2026-89430 | await | — | Gitea | Gitea | CWE-367 | Gitea push mirror SSRF and forced writes to internal Git hosts |
| CVE-2026-94205 | await | — | Gitea | Gitea | CWE-441 | Gitea fork workflow approval bypass through maintainer-triggered events |
| CVE-2026-95106 | await | — | Gitea | Gitea | — | Gitea review and execution mismatch through duplicate tree entries |
| CVE-2026-95112 | await | — | Gitea | Gitea | — | Gitea issue reference parsing CPU exhaustion |
| CVE-2026-96399 | await | — | Gitea | Gitea | CWE-125 | Gitea denial of service through external issue tracker patterns |
| CVE-2026-96404 | await | — | Gitea | Gitea | — | Gitea installer authentication bypass for existing accounts |
| CVE-2026-96580 | await | — | Gitea | Gitea | CWE-400 | Gitea Actions memory exhaustion through large static matrices |
| CVE-2026-96589 | await | — | Gitea | Gitea | CWE-672 | Gitea private repository access retained after rejected transfer |
| CVE-2026-96594 | await | — | Gitea | Gitea | CWE-79 | Gitea repository media API stored XSS |
| CVE-2026-97208 | await | — | Gitea | Gitea | CWE-863 | Gitea push mirror API bypass of DISABLE_NEW_PUSH policy |
| CVE-2026-97626 | await | — | Gitea | Gitea | CWE-200 | Gitea profile feed disclosure bypassing user visibility |
| CVE-2026-101023 | await | — | Gitea | Gitea | — | Gitea OAuth2 refresh token grant accepts access tokens |
| CVE-2026-101029 | await | — | Gitea | Gitea | CWE-209 | Gitea migration and pull mirror SSRF through multi-answer DNS |
| CVE-2026-103059 | await | — | Gitea | Gitea | — | Gitea built-in SSH server authentication bypass through key case folding |
| CVE-2026-103504 | await | — | Gitea | Gitea | CWE-272 | Gitea API team demotion not applied to unit permissions |
| CVE-2026-103667 | await | — | Gitea | Gitea | CWE-79 | Gitea container registry stored XSS through blob media type |
| CVE-2026-103670 | await | — | Gitea | Gitea | — | Gitea trusted workflow cancellation by unapproved fork runs |
| CVE-2026-104626 | await | — | Gitea | Gitea | CWE-841 | Gitea fork workflow job revival through later approval |
| CVE-2026-104632 | await | — | Gitea | Gitea | — | Gitea fork workflow approval bypass through cancel and rerun |
| CVE-2026-104633 | await | — | Gitea | Gitea | CWE-400 | Gitea migration memory exhaustion from zero page size |
| CVE-2026-104636 | await | — | Gitea | Gitea | CWE-918 | Gitea SSRF through Git HTTP redirects in mirrors and fetches |
| CVE-2026-105267 | await | — | Gitea | Gitea | CWE-732 | Gitea tag delete route deletes releases without release permission |
| CVE-2026-105268 | await | — | Gitea | Gitea | CWE-639 | Gitea issue attachment API allows changing comment attachments |
| CVE-2026-105488 | await | — | Devolutions | Server | CWE-862 | Missing authorization in the global vault in Devolutions Server 2026.3.7.0 an… |
| CVE-2026-106016 | await | — | Mozilla | Firefox | — | Mitigation bypass in the File Handling component |
| CVE-2026-106185 | await | — | Chrome | CWE-20 | Improper input validation in Viz in Google Chrome prior to 155.0.8059.39 allo… | |
| CVE-2026-106188 | await | — | Chrome | CWE-441 | Confused deputy in SignIn in Google Chrome on on Android prior to 155.0.8059.… | |
| CVE-2026-106189 | await | — | Chrome | CWE-94 | Code injection in ReaderMode in Google Chrome on on iOS prior to 155.0.8059.3… | |
| CVE-2026-106195 | await | — | Chrome | CWE-863 | Incorrect authorization in Chromoting in Google Chrome on on Mac prior to 155… | |
| CVE-2026-106196 | await | — | Chrome | CWE-862 | Missing authorization in Navigation in Google Chrome on on iOS prior to 155.0… | |
| CVE-2026-106198 | await | — | Chrome | CWE-862 | Missing authorization in FileSystem in Google Chrome prior to 155.0.8059.39 a… | |
| CVE-2026-106199 | await | — | Chrome | CWE-863 | Incorrect authorization in Actor in Google Chrome on on Android prior to 155.… | |
| CVE-2026-106202 | await | — | Chrome | CWE-908 | Uninitialized resource in ANGLE in Google Chrome on on Windows prior to 155.0… | |
| CVE-2026-106205 | await | — | Chrome | CWE-862 | Missing authorization in Passwords in Google Chrome on on Android prior to 15… | |
| CVE-2026-106208 | await | — | Chrome | CWE-862 | Missing authorization in API in Google Chrome prior to 155.0.8059.39 allowed … | |
| CVE-2026-106215 | await | — | Chrome | CWE-908 | Uninitialized resource in ANGLE in Google Chrome on on Windows prior to 155.0… | |
| CVE-2026-106216 | await | — | Chrome | CWE-352 | Cross-site request forgery in ReadingList in Google Chrome on on Android prio… | |
| CVE-2026-106221 | await | — | Chrome | CWE-441 | Confused deputy in WebAPKs in Google Chrome on on Android prior to 155.0.8059… | |
| CVE-2026-106223 | await | — | Chrome | CWE-908 | Uninitialized resource in GPU in Google Chrome on on Android prior to 155.0.8… | |
| CVE-2026-106231 | await | — | Chrome | CWE-908 | Uninitialized resource in Dawn in Google Chrome on on Mac prior to 155.0.8059… | |
| CVE-2026-106237 | await | — | Chrome | CWE-200 | Information leak in Permissions in Google Chrome prior to 155.0.8059.39 allow… | |
| CVE-2026-106242 | await | — | Chrome | CWE-200 | Information leak in Omnibox in Google Chrome on on Android prior to 155.0.805… | |
| CVE-2026-106244 | await | — | Chrome | CWE-863 | Incorrect authorization in Permissions in Google Chrome prior to 155.0.8059.3… | |
| CVE-2026-106250 | await | — | Chrome | CWE-862 | Missing authorization in Actor in Google Chrome prior to 155.0.8059.39 allowe… | |
| CVE-2026-106258 | await | — | Chrome | CWE-908 | Uninitialized resource in ANGLE in Google Chrome on on Windows prior to 155.0… | |
| CVE-2026-106259 | await | — | Chrome | CWE-863 | Incorrect authorization in PermissionElement in Google Chrome prior to 155.0.… | |
| CVE-2026-106261 | await | — | Chrome | CWE-908 | Uninitialized resource in Video in Google Chrome prior to 155.0.8059.39 allow… | |
| CVE-2026-106263 | await | — | Chrome | CWE-20 | Improper input validation in SignIn in Google Chrome prior to 155.0.8059.39 a… | |
| CVE-2026-106266 | await | — | Chrome | CWE-441 | Confused deputy in Contextual Tasks in Google Chrome prior to 155.0.8059.39 a… | |
| CVE-2026-106267 | await | — | Chrome | CWE-862 | Missing authorization in Network in Google Chrome prior to 155.0.8059.39 allo… | |
| CVE-2026-106271 | await | — | Chrome | CWE-862 | Missing authorization in Workers in Google Chrome prior to 155.0.8059.39 allo… | |
| CVE-2026-106273 | await | — | Chrome | CWE-908 | Uninitialized resource in Video in Google Chrome prior to 155.0.8059.39 allow… | |
| CVE-2026-106275 | await | — | Chrome | CWE-908 | Uninitialized resource in GPU in Google Chrome on on Android prior to 155.0.8… | |
| CVE-2026-106280 | await | — | Chrome | CWE-863 | Incorrect authorization in PermissionElement in Google Chrome prior to 155.0.… | |
| CVE-2026-106284 | await | — | Chrome | CWE-125 | Out of bounds read in Printing in Google Chrome on on Windows prior to 155.0.… | |
| CVE-2026-106286 | await | — | Chrome | CWE-441 | Confused deputy in Omnibox in Google Chrome prior to 155.0.8059.39 allowed a … | |
| CVE-2026-106287 | await | — | Chrome | CWE-221 | Information loss in CORS in Google Chrome prior to 155.0.8059.39 allowed a re… | |
| CVE-2026-106288 | await | — | Chrome | CWE-862 | Missing authorization in Browser in Google Chrome prior to 155.0.8059.39 allo… | |
| CVE-2026-106289 | await | — | Chrome | CWE-862 | Missing authorization in FedCM in Google Chrome prior to 155.0.8059.39 allowe… | |
| CVE-2026-106290 | await | — | Chrome | CWE-908 | Uninitialized resource in GPU in Google Chrome on on Android prior to 155.0.8… | |
| CVE-2026-106294 | await | — | Chrome | CWE-459 | Incomplete cleanup in Chromoting in Google Chrome on on Mac prior to 155.0.80… | |
| CVE-2026-106296 | await | — | Chrome | CWE-269 | Improper privilege management in UI in Google Chrome on on Mac prior to 155.0… | |
| CVE-2026-106297 | await | — | Chrome | CWE-863 | Incorrect authorization in Scheduling in Google Chrome prior to 155.0.8059.39… | |
| CVE-2026-106299 | await | — | Chrome | CWE-20 | Improper input validation in WebAudio in Google Chrome prior to 155.0.8059.39… | |
| CVE-2026-106300 | await | — | Chrome | CWE-367 | Race condition in CacheStorage in Google Chrome prior to 155.0.8059.39 allowe… | |
| CVE-2026-106301 | await | — | Chrome | CWE-441 | Confused deputy in Contextual Tasks in Google Chrome prior to 155.0.8059.39 a… | |
| CVE-2026-106304 | await | — | Chrome | CWE-125 | Out of bounds read in ANGLE in Google Chrome prior to 155.0.8059.39 allowed a… | |
| CVE-2026-106306 | await | — | Chrome | CWE-863 | Incorrect authorization in DevTools in Google Chrome prior to 155.0.8059.39 a… | |
| CVE-2026-106307 | await | — | Chrome | CWE-863 | Incorrect authorization in Network in Google Chrome prior to 155.0.8059.39 al… | |
| CVE-2026-106310 | await | — | Chrome | CWE-672 | Use of released resource in FontAccess in Google Chrome prior to 155.0.8059.3… | |
| CVE-2026-106322 | await | — | Chrome | CWE-601 | Open redirect in AppManifest in Google Chrome prior to 155.0.8059.39 allowed … | |
| CVE-2026-106324 | await | — | Chrome | CWE-863 | Incorrect authorization in WebAppInstalls in Google Chrome on on Android prio… | |
| CVE-2026-106326 | await | — | Chrome | CWE-441 | Confused deputy in UI in Google Chrome on on Android prior to 155.0.8059.39 a… | |
| CVE-2026-106327 | await | — | Chrome | CWE-863 | Incorrect authorization in Core in Google Chrome prior to 155.0.8059.39 allow… | |
| CVE-2026-106331 | await | — | Chrome | CWE-20 | Improper input validation in Extensions in Google Chrome prior to 155.0.8059.… | |
| CVE-2026-106344 | await | — | Chrome | CWE-862 | Missing authorization in Permissions in Google Chrome prior to 155.0.8059.39 … | |
| CVE-2026-106348 | await | — | Chrome | CWE-200 | Information leak in Animation in Google Chrome prior to 155.0.8059.39 allowed… | |
| CVE-2026-106353 | await | — | Chrome | CWE-20 | Improper input validation in Mobile in Google Chrome on on iOS prior to 155.0… | |
| CVE-2026-106359 | await | — | Chrome | CWE-441 | Confused deputy in DeviceBoundSessionCredentials in Google Chrome prior to 15… | |
| CVE-2026-106361 | await | — | Chrome | CWE-684 | Incorrect provision of specified functionality in Mobile in Google Chrome on … | |
| CVE-2026-106362 | await | — | Chrome | CWE-862 | Missing authorization in DevTools in Google Chrome prior to 155.0.8059.39 all… | |
| CVE-2026-106363 | await | — | Chrome | CWE-862 | Missing authorization in FullScreen in Google Chrome prior to 155.0.8059.39 a… | |
| CVE-2026-106365 | await | — | Chrome | CWE-862 | Missing authorization in Animation in Google Chrome prior to 155.0.8059.39 al… | |
| CVE-2026-106366 | await | — | Chrome | CWE-459 | Incomplete cleanup in CustomTabs in Google Chrome on on Android prior to 155.… | |
| CVE-2026-106367 | await | — | Chrome | CWE-862 | Missing authorization in Mobile in Google Chrome on on Android prior to 155.0… | |
| CVE-2026-106369 | await | — | Chrome | CWE-862 | Missing authorization in Translate in Google Chrome prior to 155.0.8059.39 al… | |
| CVE-2026-106370 | await | — | Chrome | CWE-908 | Uninitialized resource in GPU in Google Chrome on on Android prior to 155.0.8… | |
| CVE-2026-106376 | await | — | Chrome | CWE-908 | Uninitialized resource in ANGLE in Google Chrome on on Windows prior to 155.0… | |
| CVE-2026-106381 | await | — | Chrome | CWE-863 | Incorrect authorization in Passwords in Google Chrome on on iOS prior to 155.… |