Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
54274
Total
4303
Critical
16132
High
15830
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-102829 | UNKNOWN | — | simple-git, an interface for running git commands in any node.js application, enables applications to execute Git operations from JavaScript. Prior to 2.0.1 of the argv-parser … | Sep 29, 2026 |
| CVE-2026-102828 | UNKNOWN | — | simple-git, an interface for running git commands in any node.js application, enables applications to execute Git operations from JavaScript. From 3.15.0 until 4.0.1, the default … | Sep 29, 2026 |
| CVE-2026-102827 | HIGH | 8.1 | simple-git, an interface for running git commands in any node.js application, enables applications to execute Git operations from JavaScript. Prior to 4.0.0, the default blockUnsafeOperationsPlugin … | Sep 29, 2026 |
| CVE-2026-102826 | HIGH | 8.1 | simple-git, an interface for running git commands in any node.js application, enables applications to execute Git operations from JavaScript. Prior to 4.0.0, the default blockUnsafeOperationsPlugin … | Sep 29, 2026 |
| CVE-2026-102825 | LOW | 3.7 | Russh is a Rust SSH client and server library. Prior to 0.62.6, the USERAUTH_REQUEST path reached from server::run_stream in russh/src/server/encrypted.rs increments self.common.auth_attempts but never compares … | Sep 29, 2026 |
| CVE-2026-102824 | MEDIUM | 4.3 | Russh is a Rust SSH client and server library. Prior to 0.63.0, the hybrid ML-KEM 768 and X25519 implementation in russh/src/kex/hybrid_mlkem.rs accepts an all-zero 32-byte … | Sep 29, 2026 |
| CVE-2026-102823 | HIGH | 7.5 | Russh is a Rust SSH client and server library. Prior to 0.63.1, client_read_authenticated in russh/src/client/encrypted.rs forwards CHANNEL_DATA, CHANNEL_EXTENDED_DATA, CHANNEL_EOF, CHANNEL_CLOSE, CHANNEL_OPEN_FAILURE, CHANNEL_SUCCESS, CHANNEL_FAILURE, and CHANNEL_REQUEST … | Sep 29, 2026 |
| CVE-2026-102822 | LOW | 3.7 | Russh is a Rust SSH client and server library. Prior to 0.63.1, a connection configured to permit mac=none can negotiate it with a MAC-requiring CTR … | Sep 29, 2026 |
| CVE-2026-102821 | MEDIUM | 6.5 | Russh is a Rust SSH client and server library. Prior to 0.63.2, an authenticated remote peer can send SSH_MSG_KEXINIT without the required SSH_MSG_KEX_ECDH_INIT and then … | Sep 29, 2026 |
| CVE-2026-102820 | MEDIUM | 6.2 | pageant provides a [PageantStream] type that implements [AsyncRead] and [AsyncWrite] traits and can be used to talk to a running Pageant instance. Prior to pageant … | Sep 29, 2026 |
| CVE-2026-102616 | HIGH | 7.3 | A vulnerability was detected in risesoft-y9 WorkFlow-Engine up to 9.6.10. Impacted is the function getByIdAndYear of the file CustomHistoricProcessServiceImpl.java of the component OAuth2 Resource Filter. … | Sep 29, 2026 |
| CVE-2026-95385 | UNKNOWN | — | Inappropriate implementation in PlatformIntegration in Google Chrome on on Windows prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to bypass system access restrictions … | Sep 29, 2026 |
| CVE-2026-95384 | MEDIUM | 5.3 | Race condition in Transactions Platform in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to potentially leak sensitive information via a crafted HTML page. … | Sep 29, 2026 |
| CVE-2026-95382 | MEDIUM | 6.5 | Improper input validation in Auth in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process and leveraged social engineering … | Sep 29, 2026 |
| CVE-2026-95381 | HIGH | 8.3 | Improper input validation in Printing in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary … | Sep 29, 2026 |
| CVE-2026-95380 | HIGH | 8.8 | Type confusion in V8 in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code inside the sandbox … | Sep 29, 2026 |
| CVE-2026-95376 | UNKNOWN | — | Externally controlled reference in DevTools in Google Chrome prior to 154.0.8037.57 allowed an adjacent attacker leveraging social engineering to bypass system access restrictions via crafted … | Sep 29, 2026 |
| CVE-2026-95375 | UNKNOWN | — | Incorrect authorization in BrowserTag in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to bypass web origin policy … | Sep 29, 2026 |
| CVE-2026-95374 | UNKNOWN | — | Incorrect authorization in Network in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to bypass web origin policy via a crafted HTML page. (Chromium … | Sep 29, 2026 |
| CVE-2026-95373 | HIGH | 8.8 | Use after free in DevTools in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to execute arbitrary code inside the sandbox … | Sep 29, 2026 |
| CVE-2026-95372 | HIGH | 8.3 | Use after free in Chromecast in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary … | Sep 29, 2026 |
| CVE-2026-95371 | MEDIUM | 5.4 | Missing authorization in Views in Google Chrome on on Mac prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process and leveraged … | Sep 29, 2026 |
| CVE-2026-95370 | UNKNOWN | — | Inappropriate implementation in NFC in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to bypass system access restrictions via a crafted HTML page. (Chromium … | Sep 29, 2026 |
| CVE-2026-95369 | HIGH | 8.8 | Inappropriate implementation in XML in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to potentially execute arbitrary code inside the sandbox via a crafted … | Sep 29, 2026 |
| CVE-2026-95368 | MEDIUM | 4.3 | Incorrect authorization in DevTools in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to potentially obtain cross-origin data via a crafted … | Sep 29, 2026 |