Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
54274
Total
4303
Critical
16132
High
15830
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-102309 | CRITICAL | 9.6 | Use after free in FullScreen in Google Chrome prior to 154.0.8037.92 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted … | Sep 29, 2026 |
| CVE-2026-102308 | CRITICAL | 9.6 | Use after free in Views in Google Chrome prior to 154.0.8037.92 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox … | Sep 29, 2026 |
| CVE-2026-102307 | MEDIUM | 4.7 | Uninitialized resource in Dawn in Google Chrome on on Android prior to 154.0.8037.92 allowed a remote attacker to read memory outside the sandbox via a … | Sep 29, 2026 |
| CVE-2026-102306 | CRITICAL | 9.6 | Use after free in Bluetooth in Google Chrome prior to 154.0.8037.92 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a … | Sep 29, 2026 |
| CVE-2026-102305 | MEDIUM | 5.4 | UI misrepresentation in SignIn in Google Chrome on on iOS prior to 154.0.8037.92 allowed a remote attacker to spoof UI elements via a crafted HTML … | Sep 29, 2026 |
| CVE-2026-102304 | CRITICAL | 9.6 | Use after free in Passwords in Google Chrome prior to 154.0.8037.92 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted … | Sep 29, 2026 |
| CVE-2026-102303 | MEDIUM | 4.3 | Uninitialized resource in GPU in Google Chrome on on Android prior to 154.0.8037.92 allowed a remote attacker to obtain cross-origin data via a crafted HTML … | Sep 29, 2026 |
| CVE-2026-102302 | HIGH | 8.8 | Buffer overflow in V8 in Google Chrome prior to 154.0.8037.92 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML … | Sep 29, 2026 |
| CVE-2026-102301 | HIGH | 8.3 | Out of bounds write in GPU in Google Chrome prior to 154.0.8037.92 allowed a remote attacker who had compromised the renderer process to potentially execute … | Sep 29, 2026 |
| CVE-2026-102300 | MEDIUM | 4.3 | Uninitialized resource in WebGPU in Google Chrome prior to 154.0.8037.92 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (Chromium security … | Sep 29, 2026 |
| CVE-2026-102299 | HIGH | 8.8 | Type confusion in V8 in Google Chrome prior to 154.0.8037.92 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML … | Sep 29, 2026 |
| CVE-2026-102252 | UNKNOWN | — | A path traversal vulnerability (CWE-22) in the embedded VMDK filesystem extractor in Google OSV-SCALIBR versions 0.3.6 through 0.5.0 allows an attacker who controls the scan … | Sep 29, 2026 |
| CVE-2026-100299 | MEDIUM | 6.8 | In Anjvision YSSD‑RTMP‑H5 firmware version 3.3.2.4, the device includes a legacy password hash on the serial console that relies on a weak DES‑based encryption. | Sep 29, 2026 |
| CVE-2026-100298 | HIGH | 8.8 | In Anjvision YSSD‑RTMP‑H5 firmware version 3.3.2.4, two user‑information endpoints can reveal sensitive device and account details under conditions that are not intended for normal operation. | Sep 29, 2026 |
| CVE-2026-100297 | MEDIUM | 5.3 | In Anjvision YSSD‑RTMP‑H5 firmware version 3.3.2.4, an unauthenticated network check function can be triggered to probe arbitrary hosts from the device’s internal network. This may … | Sep 29, 2026 |
| CVE-2026-100296 | HIGH | 8.1 | In Anjvision YSSD-RTMP-H5 firmware version 3.3.2.4, an empty-body POST to /setUserConfig, dispatched through the web server's SOAP-RPC handler, silently downgrades the administrator password to the … | Sep 29, 2026 |
| CVE-2026-100295 | MEDIUM | 6.3 | In Anjvision YSSD‑RTMP‑H5 firmware version 3.3.2.4, an internal debug interface can be enabled through an undocumented pathway, exposing functions not intended for normal operation. When … | Sep 29, 2026 |
| CVE-2026-100294 | HIGH | 7.5 | In Anjvision YSSD‑RTMP‑H5 firmware version 3.3.2.4, the firmware embeds hardcoded cloud‑API credentials that are shared across deployed devices. Anyone obtaining the public firmware package can … | Sep 29, 2026 |
| CVE-2026-100293 | HIGH | 8.8 | In Anjvision YSSD‑RTMP‑H5 firmware version 3.3.2.4, both the local and cloud update mechanisms apply new firmware without any cryptographic verification, relying only on basic hashing. … | Sep 29, 2026 |
| CVE-2026-100292 | HIGH | 8.8 | In Anjvision YSSD‑RTMP‑H5 firmware version 3.3.2.4, a hidden debug interface can be enabled through an authenticated request, allowing additional commands to be sent to a … | Sep 29, 2026 |
| CVE-2026-100291 | CRITICAL | 9.8 | In Anjvision YSSD‑RTMP‑H5 firmware version 3.3.2.4, several ONVIF service endpoints process management requests without enforcing required authentication. This could allow an unauthorized attacker to access … | Sep 29, 2026 |
| CVE-2024-31027 | UNKNOWN | — | Cross Site Scripting vulnerability in Greek Universities Network (GUnet) Open eClass Platform v.3.15 allows a remote attacker to execute arbitrary code via the last name, … | Sep 29, 2026 |
| CVE-2024-31026 | UNKNOWN | — | An issue in Greek Universities Network (GUnet) Open eClass Platform v.3.15 allows a remote attacker to execute arbitrary code via the chat input field in … | Sep 29, 2026 |
| CVE-2026-102831 | HIGH | 8.1 | JupyterLab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. From JupyterLab 4.5.0 until 4.5.11 and 4.6.4, from Notebook … | Sep 29, 2026 |
| CVE-2026-102830 | MEDIUM | 6.8 | JupyterLab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. From JupyterLab 3.0.0 until 4.5.11 and 4.6.4, and in … | Sep 29, 2026 |