Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
54274
Total
4303
Critical
16132
High
15830
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-102878 | HIGH | 8.1 | mcp-chrome-bridge through 1.0.31 contains an origin validation error in the native-server HTTP API that allows attackers to bypass CORS restrictions. Attackers can craft malicious web … | Sep 29, 2026 |
| CVE-2026-102877 | MEDIUM | 4.4 | Fider before 0.38.0 contains a server-side request forgery vulnerability due to a time-of-check time-of-use gap in URL validation for webhooks and custom OAuth provider endpoints. … | Sep 29, 2026 |
| CVE-2026-102876 | HIGH | 8.1 | SurrealDB before 3.3.0 contains an authorization bypass in HTTP session construction where check_auth() verifies credentials against Surreal-Auth-NS and Surreal-Auth-DB headers but constructs sessions using Surreal-NS … | Sep 29, 2026 |
| CVE-2026-102875 | HIGH | 7.8 | VLC media player before 3.0.24 contains a path traversal vulnerability in the skins2 ThemeLoader that fails to validate member names in .vlt skin archives. Attackers … | Sep 29, 2026 |
| CVE-2026-102331 | CRITICAL | 9.6 | Buffer overflow in ANGLE in Google Chrome on on Android prior to 154.0.8037.92 allowed a remote attacker to potentially execute arbitrary code outside the sandbox … | Sep 29, 2026 |
| CVE-2026-102330 | UNKNOWN | — | Incorrect authorization in SiteIsolation in Google Chrome prior to 154.0.8037.92 allowed a remote attacker who had compromised the renderer process to bypass web origin policy … | Sep 29, 2026 |
| CVE-2026-102329 | UNKNOWN | — | Cross-site scripting in WebUI in Google Chrome prior to 154.0.8037.92 allowed a remote attacker to bypass web origin policy into a privileged page via a … | Sep 29, 2026 |
| CVE-2026-102328 | HIGH | 8.8 | Type confusion in V8 in Google Chrome prior to 154.0.8037.92 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML … | Sep 29, 2026 |
| CVE-2026-102327 | HIGH | 7.5 | Incorrect authorization in WebView in Google Chrome on on Android prior to 154.0.8037.92 allowed a remote attacker who had compromised the renderer process to potentially … | Sep 29, 2026 |
| CVE-2026-102326 | HIGH | 8.8 | Type confusion in V8 in Google Chrome prior to 154.0.8037.92 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML … | Sep 29, 2026 |
| CVE-2026-102325 | MEDIUM | 4.3 | Uninitialized resource in Skia in Google Chrome prior to 154.0.8037.92 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (Chromium security … | Sep 29, 2026 |
| CVE-2026-102324 | HIGH | 8.3 | Use after free in PictureInPicture in Google Chrome prior to 154.0.8037.92 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary … | Sep 29, 2026 |
| CVE-2026-102323 | HIGH | 8.8 | Type confusion in V8 in Google Chrome prior to 154.0.8037.92 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML … | Sep 29, 2026 |
| CVE-2026-102321 | HIGH | 8.8 | Type confusion in V8 in Google Chrome prior to 154.0.8037.92 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML … | Sep 29, 2026 |
| CVE-2026-102320 | UNKNOWN | — | Missing authorization in CORS in Google Chrome prior to 154.0.8037.92 allowed a remote attacker who had compromised the renderer process to bypass web origin policy … | Sep 29, 2026 |
| CVE-2026-102319 | LOW | 3.4 | Uninitialized resource in GPU in Google Chrome prior to 154.0.8037.92 allowed a remote attacker who had compromised the renderer process to read memory outside the … | Sep 29, 2026 |
| CVE-2026-102318 | MEDIUM | 4.7 | Out of bounds read in WebGL in Google Chrome prior to 154.0.8037.92 allowed a remote attacker to read memory outside the sandbox via a crafted … | Sep 29, 2026 |
| CVE-2026-102317 | HIGH | 8.6 | Improper privilege management in Mojo in Google Chrome on on Windows prior to 154.0.8037.92 allowed a local attacker to potentially execute arbitrary code outside the … | Sep 29, 2026 |
| CVE-2026-102316 | CRITICAL | 9.6 | Use after free in Views in Google Chrome prior to 154.0.8037.92 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox … | Sep 29, 2026 |
| CVE-2026-102315 | LOW | 3.4 | Uninitialized resource in Media in Google Chrome on on Windows prior to 154.0.8037.92 allowed a remote attacker who had compromised the renderer process to read … | Sep 29, 2026 |
| CVE-2026-102314 | MEDIUM | 5.4 | UI misrepresentation in TabStrip in Google Chrome prior to 154.0.8037.92 allowed a remote attacker to spoof UI elements via a crafted HTML page. (Chromium security … | Sep 29, 2026 |
| CVE-2026-102313 | MEDIUM | 4.7 | Uninitialized resource in ANGLE in Google Chrome on on Windows prior to 154.0.8037.92 allowed a remote attacker to read memory outside the sandbox via a … | Sep 29, 2026 |
| CVE-2026-102312 | UNKNOWN | — | UI misrepresentation in Omnibox in Google Chrome on on Android prior to 154.0.8037.92 allowed a remote attacker to spoof address bar via a crafted HTML … | Sep 29, 2026 |
| CVE-2026-102311 | LOW | 3.4 | Uninitialized resource in GPU in Google Chrome on on Android prior to 154.0.8037.92 allowed a remote attacker who had compromised the renderer process to read … | Sep 29, 2026 |
| CVE-2026-102310 | UNKNOWN | — | Missing authorization in Payments in Google Chrome prior to 154.0.8037.92 allowed a remote attacker who had compromised the renderer process to bypass web origin policy … | Sep 29, 2026 |