Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

54274
Total
4303
Critical
16132
High
15830
Medium
CVE ID Severity Score Description Published
CVE-2026-102829 UNKNOWN — simple-git, an interface for running git commands in any node.js application, enables applications to execute Git operations from JavaScript. Prior to 2.0.1 of the argv-parser … Sep 29, 2026
CVE-2026-102828 UNKNOWN — simple-git, an interface for running git commands in any node.js application, enables applications to execute Git operations from JavaScript. From 3.15.0 until 4.0.1, the default … Sep 29, 2026
CVE-2026-102827 HIGH 8.1 simple-git, an interface for running git commands in any node.js application, enables applications to execute Git operations from JavaScript. Prior to 4.0.0, the default blockUnsafeOperationsPlugin … Sep 29, 2026
CVE-2026-102826 HIGH 8.1 simple-git, an interface for running git commands in any node.js application, enables applications to execute Git operations from JavaScript. Prior to 4.0.0, the default blockUnsafeOperationsPlugin … Sep 29, 2026
CVE-2026-102825 LOW 3.7 Russh is a Rust SSH client and server library. Prior to 0.62.6, the USERAUTH_REQUEST path reached from server::run_stream in russh/src/server/encrypted.rs increments self.common.auth_attempts but never compares … Sep 29, 2026
CVE-2026-102824 MEDIUM 4.3 Russh is a Rust SSH client and server library. Prior to 0.63.0, the hybrid ML-KEM 768 and X25519 implementation in russh/src/kex/hybrid_mlkem.rs accepts an all-zero 32-byte … Sep 29, 2026
CVE-2026-102823 HIGH 7.5 Russh is a Rust SSH client and server library. Prior to 0.63.1, client_read_authenticated in russh/src/client/encrypted.rs forwards CHANNEL_DATA, CHANNEL_EXTENDED_DATA, CHANNEL_EOF, CHANNEL_CLOSE, CHANNEL_OPEN_FAILURE, CHANNEL_SUCCESS, CHANNEL_FAILURE, and CHANNEL_REQUEST … Sep 29, 2026
CVE-2026-102822 LOW 3.7 Russh is a Rust SSH client and server library. Prior to 0.63.1, a connection configured to permit mac=none can negotiate it with a MAC-requiring CTR … Sep 29, 2026
CVE-2026-102821 MEDIUM 6.5 Russh is a Rust SSH client and server library. Prior to 0.63.2, an authenticated remote peer can send SSH_MSG_KEXINIT without the required SSH_MSG_KEX_ECDH_INIT and then … Sep 29, 2026
CVE-2026-102820 MEDIUM 6.2 pageant provides a [PageantStream] type that implements [AsyncRead] and [AsyncWrite] traits and can be used to talk to a running Pageant instance. Prior to pageant … Sep 29, 2026
CVE-2026-102616 HIGH 7.3 A vulnerability was detected in risesoft-y9 WorkFlow-Engine up to 9.6.10. Impacted is the function getByIdAndYear of the file CustomHistoricProcessServiceImpl.java of the component OAuth2 Resource Filter. … Sep 29, 2026
CVE-2026-95385 UNKNOWN — Inappropriate implementation in PlatformIntegration in Google Chrome on on Windows prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to bypass system access restrictions … Sep 29, 2026
CVE-2026-95384 MEDIUM 5.3 Race condition in Transactions Platform in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to potentially leak sensitive information via a crafted HTML page. … Sep 29, 2026
CVE-2026-95382 MEDIUM 6.5 Improper input validation in Auth in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process and leveraged social engineering … Sep 29, 2026
CVE-2026-95381 HIGH 8.3 Improper input validation in Printing in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary … Sep 29, 2026
CVE-2026-95380 HIGH 8.8 Type confusion in V8 in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code inside the sandbox … Sep 29, 2026
CVE-2026-95376 UNKNOWN — Externally controlled reference in DevTools in Google Chrome prior to 154.0.8037.57 allowed an adjacent attacker leveraging social engineering to bypass system access restrictions via crafted … Sep 29, 2026
CVE-2026-95375 UNKNOWN — Incorrect authorization in BrowserTag in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to bypass web origin policy … Sep 29, 2026
CVE-2026-95374 UNKNOWN — Incorrect authorization in Network in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to bypass web origin policy via a crafted HTML page. (Chromium … Sep 29, 2026
CVE-2026-95373 HIGH 8.8 Use after free in DevTools in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to execute arbitrary code inside the sandbox … Sep 29, 2026
CVE-2026-95372 HIGH 8.3 Use after free in Chromecast in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary … Sep 29, 2026
CVE-2026-95371 MEDIUM 5.4 Missing authorization in Views in Google Chrome on on Mac prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process and leveraged … Sep 29, 2026
CVE-2026-95370 UNKNOWN — Inappropriate implementation in NFC in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to bypass system access restrictions via a crafted HTML page. (Chromium … Sep 29, 2026
CVE-2026-95369 HIGH 8.8 Inappropriate implementation in XML in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to potentially execute arbitrary code inside the sandbox via a crafted … Sep 29, 2026
CVE-2026-95368 MEDIUM 4.3 Incorrect authorization in DevTools in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to potentially obtain cross-origin data via a crafted … Sep 29, 2026