Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

54256
Total
4300
Critical
16127
High
15827
Medium
CVE ID Severity Score Description Published
CVE-2026-67987 UNKNOWN — crmne/ruby_llm at commit fa6f279847d6d7027814539d9c0dfc3bbdfd2a83 contains polynomial-time regular expression denial-of-service conditions in think-tag response parsing on Ruby 3.1.x. A malicious or anomalous model response containing many … Sep 29, 2026
CVE-2026-61519 HIGH 8.8 Liberu CRM 0.9.1 before 10.0.0 contains a broken access control vulnerability that allows any user holding a pending team invitation to invite additional attacker-controlled accounts … Sep 29, 2026
CVE-2026-53989 MEDIUM 4.7 Dockhand before 1.0.36 contains an open redirect vulnerability in the OIDC initiation endpoint that allows unauthenticated remote attackers to redirect authenticated users to attacker-controlled sites … Sep 29, 2026
CVE-2026-53988 CRITICAL 10.0 Dockhand before 1.0.40 contains an authentication bypass vulnerability in its git webhook endpoints that allows unauthenticated remote attackers to trigger arbitrary stack redeployments by exploiting … Sep 29, 2026
CVE-2026-39117 CRITICAL 9.8 An issue in AltumCode 66Uptime before v.54.0.0 and 66Uptime ping-servers plugin before v.2.0.0 allows a remote attacker to execute arbitrary code via the index.php Sep 29, 2026
CVE-2026-11415 UNKNOWN — Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. Sep 29, 2026
CVE-2026-102879 MEDIUM 5.0 ClaraVerse through 0.3.1 contains server-side request forgery protection bypasses in the download_file and scrape_web agent tools. Authenticated users can bypass hostname validation and IPv6 transition … Sep 29, 2026
CVE-2026-102878 HIGH 8.1 mcp-chrome-bridge through 1.0.31 contains an origin validation error in the native-server HTTP API that allows attackers to bypass CORS restrictions. Attackers can craft malicious web … Sep 29, 2026
CVE-2026-102877 MEDIUM 4.4 Fider before 0.38.0 contains a server-side request forgery vulnerability due to a time-of-check time-of-use gap in URL validation for webhooks and custom OAuth provider endpoints. … Sep 29, 2026
CVE-2026-102876 HIGH 8.1 SurrealDB before 3.3.0 contains an authorization bypass in HTTP session construction where check_auth() verifies credentials against Surreal-Auth-NS and Surreal-Auth-DB headers but constructs sessions using Surreal-NS … Sep 29, 2026
CVE-2026-102875 HIGH 7.8 VLC media player before 3.0.24 contains a path traversal vulnerability in the skins2 ThemeLoader that fails to validate member names in .vlt skin archives. Attackers … Sep 29, 2026
CVE-2026-102331 CRITICAL 9.6 Buffer overflow in ANGLE in Google Chrome on on Android prior to 154.0.8037.92 allowed a remote attacker to potentially execute arbitrary code outside the sandbox … Sep 29, 2026
CVE-2026-102330 UNKNOWN — Incorrect authorization in SiteIsolation in Google Chrome prior to 154.0.8037.92 allowed a remote attacker who had compromised the renderer process to bypass web origin policy … Sep 29, 2026
CVE-2026-102329 UNKNOWN — Cross-site scripting in WebUI in Google Chrome prior to 154.0.8037.92 allowed a remote attacker to bypass web origin policy into a privileged page via a … Sep 29, 2026
CVE-2026-102328 HIGH 8.8 Type confusion in V8 in Google Chrome prior to 154.0.8037.92 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML … Sep 29, 2026
CVE-2026-102327 HIGH 7.5 Incorrect authorization in WebView in Google Chrome on on Android prior to 154.0.8037.92 allowed a remote attacker who had compromised the renderer process to potentially … Sep 29, 2026
CVE-2026-102326 HIGH 8.8 Type confusion in V8 in Google Chrome prior to 154.0.8037.92 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML … Sep 29, 2026
CVE-2026-102325 MEDIUM 4.3 Uninitialized resource in Skia in Google Chrome prior to 154.0.8037.92 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (Chromium security … Sep 29, 2026
CVE-2026-102324 HIGH 8.3 Use after free in PictureInPicture in Google Chrome prior to 154.0.8037.92 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary … Sep 29, 2026
CVE-2026-102323 HIGH 8.8 Type confusion in V8 in Google Chrome prior to 154.0.8037.92 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML … Sep 29, 2026
CVE-2026-102321 HIGH 8.8 Type confusion in V8 in Google Chrome prior to 154.0.8037.92 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML … Sep 29, 2026
CVE-2026-102320 UNKNOWN — Missing authorization in CORS in Google Chrome prior to 154.0.8037.92 allowed a remote attacker who had compromised the renderer process to bypass web origin policy … Sep 29, 2026
CVE-2026-102319 LOW 3.4 Uninitialized resource in GPU in Google Chrome prior to 154.0.8037.92 allowed a remote attacker who had compromised the renderer process to read memory outside the … Sep 29, 2026
CVE-2026-102318 MEDIUM 4.7 Out of bounds read in WebGL in Google Chrome prior to 154.0.8037.92 allowed a remote attacker to read memory outside the sandbox via a crafted … Sep 29, 2026
CVE-2026-102317 HIGH 8.6 Improper privilege management in Mojo in Google Chrome on on Windows prior to 154.0.8037.92 allowed a local attacker to potentially execute arbitrary code outside the … Sep 29, 2026