Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

54274
Total
4303
Critical
16132
High
15830
Medium
CVE ID Severity Score Description Published
CVE-2026-102878 HIGH 8.1 mcp-chrome-bridge through 1.0.31 contains an origin validation error in the native-server HTTP API that allows attackers to bypass CORS restrictions. Attackers can craft malicious web … Sep 29, 2026
CVE-2026-102877 MEDIUM 4.4 Fider before 0.38.0 contains a server-side request forgery vulnerability due to a time-of-check time-of-use gap in URL validation for webhooks and custom OAuth provider endpoints. … Sep 29, 2026
CVE-2026-102876 HIGH 8.1 SurrealDB before 3.3.0 contains an authorization bypass in HTTP session construction where check_auth() verifies credentials against Surreal-Auth-NS and Surreal-Auth-DB headers but constructs sessions using Surreal-NS … Sep 29, 2026
CVE-2026-102875 HIGH 7.8 VLC media player before 3.0.24 contains a path traversal vulnerability in the skins2 ThemeLoader that fails to validate member names in .vlt skin archives. Attackers … Sep 29, 2026
CVE-2026-102331 CRITICAL 9.6 Buffer overflow in ANGLE in Google Chrome on on Android prior to 154.0.8037.92 allowed a remote attacker to potentially execute arbitrary code outside the sandbox … Sep 29, 2026
CVE-2026-102330 UNKNOWN — Incorrect authorization in SiteIsolation in Google Chrome prior to 154.0.8037.92 allowed a remote attacker who had compromised the renderer process to bypass web origin policy … Sep 29, 2026
CVE-2026-102329 UNKNOWN — Cross-site scripting in WebUI in Google Chrome prior to 154.0.8037.92 allowed a remote attacker to bypass web origin policy into a privileged page via a … Sep 29, 2026
CVE-2026-102328 HIGH 8.8 Type confusion in V8 in Google Chrome prior to 154.0.8037.92 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML … Sep 29, 2026
CVE-2026-102327 HIGH 7.5 Incorrect authorization in WebView in Google Chrome on on Android prior to 154.0.8037.92 allowed a remote attacker who had compromised the renderer process to potentially … Sep 29, 2026
CVE-2026-102326 HIGH 8.8 Type confusion in V8 in Google Chrome prior to 154.0.8037.92 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML … Sep 29, 2026
CVE-2026-102325 MEDIUM 4.3 Uninitialized resource in Skia in Google Chrome prior to 154.0.8037.92 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (Chromium security … Sep 29, 2026
CVE-2026-102324 HIGH 8.3 Use after free in PictureInPicture in Google Chrome prior to 154.0.8037.92 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary … Sep 29, 2026
CVE-2026-102323 HIGH 8.8 Type confusion in V8 in Google Chrome prior to 154.0.8037.92 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML … Sep 29, 2026
CVE-2026-102321 HIGH 8.8 Type confusion in V8 in Google Chrome prior to 154.0.8037.92 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML … Sep 29, 2026
CVE-2026-102320 UNKNOWN — Missing authorization in CORS in Google Chrome prior to 154.0.8037.92 allowed a remote attacker who had compromised the renderer process to bypass web origin policy … Sep 29, 2026
CVE-2026-102319 LOW 3.4 Uninitialized resource in GPU in Google Chrome prior to 154.0.8037.92 allowed a remote attacker who had compromised the renderer process to read memory outside the … Sep 29, 2026
CVE-2026-102318 MEDIUM 4.7 Out of bounds read in WebGL in Google Chrome prior to 154.0.8037.92 allowed a remote attacker to read memory outside the sandbox via a crafted … Sep 29, 2026
CVE-2026-102317 HIGH 8.6 Improper privilege management in Mojo in Google Chrome on on Windows prior to 154.0.8037.92 allowed a local attacker to potentially execute arbitrary code outside the … Sep 29, 2026
CVE-2026-102316 CRITICAL 9.6 Use after free in Views in Google Chrome prior to 154.0.8037.92 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox … Sep 29, 2026
CVE-2026-102315 LOW 3.4 Uninitialized resource in Media in Google Chrome on on Windows prior to 154.0.8037.92 allowed a remote attacker who had compromised the renderer process to read … Sep 29, 2026
CVE-2026-102314 MEDIUM 5.4 UI misrepresentation in TabStrip in Google Chrome prior to 154.0.8037.92 allowed a remote attacker to spoof UI elements via a crafted HTML page. (Chromium security … Sep 29, 2026
CVE-2026-102313 MEDIUM 4.7 Uninitialized resource in ANGLE in Google Chrome on on Windows prior to 154.0.8037.92 allowed a remote attacker to read memory outside the sandbox via a … Sep 29, 2026
CVE-2026-102312 UNKNOWN — UI misrepresentation in Omnibox in Google Chrome on on Android prior to 154.0.8037.92 allowed a remote attacker to spoof address bar via a crafted HTML … Sep 29, 2026
CVE-2026-102311 LOW 3.4 Uninitialized resource in GPU in Google Chrome on on Android prior to 154.0.8037.92 allowed a remote attacker who had compromised the renderer process to read … Sep 29, 2026
CVE-2026-102310 UNKNOWN — Missing authorization in Payments in Google Chrome prior to 154.0.8037.92 allowed a remote attacker who had compromised the renderer process to bypass web origin policy … Sep 29, 2026