Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
54256
Total
4300
Critical
16127
High
15827
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-67987 | UNKNOWN | — | crmne/ruby_llm at commit fa6f279847d6d7027814539d9c0dfc3bbdfd2a83 contains polynomial-time regular expression denial-of-service conditions in think-tag response parsing on Ruby 3.1.x. A malicious or anomalous model response containing many … | Sep 29, 2026 |
| CVE-2026-61519 | HIGH | 8.8 | Liberu CRM 0.9.1 before 10.0.0 contains a broken access control vulnerability that allows any user holding a pending team invitation to invite additional attacker-controlled accounts … | Sep 29, 2026 |
| CVE-2026-53989 | MEDIUM | 4.7 | Dockhand before 1.0.36 contains an open redirect vulnerability in the OIDC initiation endpoint that allows unauthenticated remote attackers to redirect authenticated users to attacker-controlled sites … | Sep 29, 2026 |
| CVE-2026-53988 | CRITICAL | 10.0 | Dockhand before 1.0.40 contains an authentication bypass vulnerability in its git webhook endpoints that allows unauthenticated remote attackers to trigger arbitrary stack redeployments by exploiting … | Sep 29, 2026 |
| CVE-2026-39117 | CRITICAL | 9.8 | An issue in AltumCode 66Uptime before v.54.0.0 and 66Uptime ping-servers plugin before v.2.0.0 allows a remote attacker to execute arbitrary code via the index.php | Sep 29, 2026 |
| CVE-2026-11415 | UNKNOWN | — | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | Sep 29, 2026 |
| CVE-2026-102879 | MEDIUM | 5.0 | ClaraVerse through 0.3.1 contains server-side request forgery protection bypasses in the download_file and scrape_web agent tools. Authenticated users can bypass hostname validation and IPv6 transition … | Sep 29, 2026 |
| CVE-2026-102878 | HIGH | 8.1 | mcp-chrome-bridge through 1.0.31 contains an origin validation error in the native-server HTTP API that allows attackers to bypass CORS restrictions. Attackers can craft malicious web … | Sep 29, 2026 |
| CVE-2026-102877 | MEDIUM | 4.4 | Fider before 0.38.0 contains a server-side request forgery vulnerability due to a time-of-check time-of-use gap in URL validation for webhooks and custom OAuth provider endpoints. … | Sep 29, 2026 |
| CVE-2026-102876 | HIGH | 8.1 | SurrealDB before 3.3.0 contains an authorization bypass in HTTP session construction where check_auth() verifies credentials against Surreal-Auth-NS and Surreal-Auth-DB headers but constructs sessions using Surreal-NS … | Sep 29, 2026 |
| CVE-2026-102875 | HIGH | 7.8 | VLC media player before 3.0.24 contains a path traversal vulnerability in the skins2 ThemeLoader that fails to validate member names in .vlt skin archives. Attackers … | Sep 29, 2026 |
| CVE-2026-102331 | CRITICAL | 9.6 | Buffer overflow in ANGLE in Google Chrome on on Android prior to 154.0.8037.92 allowed a remote attacker to potentially execute arbitrary code outside the sandbox … | Sep 29, 2026 |
| CVE-2026-102330 | UNKNOWN | — | Incorrect authorization in SiteIsolation in Google Chrome prior to 154.0.8037.92 allowed a remote attacker who had compromised the renderer process to bypass web origin policy … | Sep 29, 2026 |
| CVE-2026-102329 | UNKNOWN | — | Cross-site scripting in WebUI in Google Chrome prior to 154.0.8037.92 allowed a remote attacker to bypass web origin policy into a privileged page via a … | Sep 29, 2026 |
| CVE-2026-102328 | HIGH | 8.8 | Type confusion in V8 in Google Chrome prior to 154.0.8037.92 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML … | Sep 29, 2026 |
| CVE-2026-102327 | HIGH | 7.5 | Incorrect authorization in WebView in Google Chrome on on Android prior to 154.0.8037.92 allowed a remote attacker who had compromised the renderer process to potentially … | Sep 29, 2026 |
| CVE-2026-102326 | HIGH | 8.8 | Type confusion in V8 in Google Chrome prior to 154.0.8037.92 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML … | Sep 29, 2026 |
| CVE-2026-102325 | MEDIUM | 4.3 | Uninitialized resource in Skia in Google Chrome prior to 154.0.8037.92 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (Chromium security … | Sep 29, 2026 |
| CVE-2026-102324 | HIGH | 8.3 | Use after free in PictureInPicture in Google Chrome prior to 154.0.8037.92 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary … | Sep 29, 2026 |
| CVE-2026-102323 | HIGH | 8.8 | Type confusion in V8 in Google Chrome prior to 154.0.8037.92 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML … | Sep 29, 2026 |
| CVE-2026-102321 | HIGH | 8.8 | Type confusion in V8 in Google Chrome prior to 154.0.8037.92 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML … | Sep 29, 2026 |
| CVE-2026-102320 | UNKNOWN | — | Missing authorization in CORS in Google Chrome prior to 154.0.8037.92 allowed a remote attacker who had compromised the renderer process to bypass web origin policy … | Sep 29, 2026 |
| CVE-2026-102319 | LOW | 3.4 | Uninitialized resource in GPU in Google Chrome prior to 154.0.8037.92 allowed a remote attacker who had compromised the renderer process to read memory outside the … | Sep 29, 2026 |
| CVE-2026-102318 | MEDIUM | 4.7 | Out of bounds read in WebGL in Google Chrome prior to 154.0.8037.92 allowed a remote attacker to read memory outside the sandbox via a crafted … | Sep 29, 2026 |
| CVE-2026-102317 | HIGH | 8.6 | Improper privilege management in Mojo in Google Chrome on on Windows prior to 154.0.8037.92 allowed a local attacker to potentially execute arbitrary code outside the … | Sep 29, 2026 |