Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
54274
Total
4303
Critical
16132
High
15830
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-95292 | MEDIUM | 4.8 | Incorrect authorization in Safebrowsing in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to bypass system access restrictions via crafted network traffic. (Chromium security … | Sep 29, 2026 |
| CVE-2026-95291 | MEDIUM | 5.4 | UI misrepresentation in SecurityIndicators in Google Chrome on on iOS prior to 154.0.8037.57 allowed a remote attacker to spoof address bar via a crafted HTML … | Sep 29, 2026 |
| CVE-2026-95290 | UNKNOWN | — | Missing authorization in NFC in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to bypass system access restrictions … | Sep 29, 2026 |
| CVE-2026-95289 | MEDIUM | 4.3 | Incorrect authorization in Scroll in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to obtain cross-origin data via a crafted HTML … | Sep 29, 2026 |
| CVE-2026-95288 | MEDIUM | 5.4 | UI misrepresentation in Mobile in Google Chrome on on iOS prior to 154.0.8037.57 allowed a remote attacker to spoof UI elements via a crafted HTML … | Sep 29, 2026 |
| CVE-2026-95287 | MEDIUM | 5.4 | Missing authorization in Navigation in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to bypass site isolation via … | Sep 29, 2026 |
| CVE-2026-95286 | HIGH | 8.8 | Type confusion in Bindings in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML … | Sep 29, 2026 |
| CVE-2026-95285 | UNKNOWN | — | Missing authorization in WebView in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to bypass … | Sep 29, 2026 |
| CVE-2026-95284 | UNKNOWN | — | Buffer overflow in ANGLE in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code outside the sandbox via … | Sep 29, 2026 |
| CVE-2026-95283 | CRITICAL | 9.6 | Buffer overflow in Tint in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker to potentially execute arbitrary code outside the sandbox … | Sep 29, 2026 |
| CVE-2026-95282 | HIGH | 8.8 | Use after free in Platform in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted … | Sep 29, 2026 |
| CVE-2026-95281 | CRITICAL | 9.6 | Buffer overflow in ANGLE in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code outside the sandbox via … | Sep 29, 2026 |
| CVE-2026-95280 | HIGH | 7.5 | Race condition in V8 in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML … | Sep 29, 2026 |
| CVE-2026-95279 | MEDIUM | 5.4 | UI misrepresentation in Omnibox in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker to spoof address bar via a crafted HTML … | Sep 29, 2026 |
| CVE-2026-95278 | UNKNOWN | — | Missing authorization in WakeLock in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to bypass system access restrictions … | Sep 29, 2026 |
| CVE-2026-95277 | CRITICAL | 9.6 | Use after free in Views in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a … | Sep 29, 2026 |
| CVE-2026-95276 | HIGH | 8.3 | Improper input validation in Themes in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary … | Sep 29, 2026 |
| CVE-2026-95275 | UNKNOWN | — | Incorrect reference resolution in MediaStream in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to bypass web origin policy into a privileged page via … | Sep 29, 2026 |
| CVE-2026-95274 | HIGH | 8.3 | Improper output encoding in DevTools in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary … | Sep 29, 2026 |
| CVE-2026-94954 | UNKNOWN | — | A stack-based buffer overflow vulnerability exists in the web management interface of TOTOLINK N150RT (NTR150) firmware V3.4.0-B20201030. It is reachable through the route /boafrm/formFilter (access-control … | Sep 29, 2026 |
| CVE-2026-84842 | HIGH | 8.1 | IBM Guardium Data Protection 12.2 is vulnerable to path traversal and arbitrary file deletion in the Datasource REST component. An authenticated remote attacker could exploit … | Sep 29, 2026 |
| CVE-2026-84440 | HIGH | 7.5 | IBM Guardium Data Protection 12.2 is vulnerable to command injection in the SNMP alert notification functionality. An authenticated attacker who can influence policy alert text … | Sep 29, 2026 |
| CVE-2026-84436 | CRITICAL | 9.1 | IBM Guardium Data Protection 12.2 is vulnerable to command injection in the certificate export CLI functionality, allowing a privileged authenticated CLI user to execute arbitrary … | Sep 29, 2026 |
| CVE-2026-84422 | HIGH | 7.2 | IBM Guardium Data Protection 12.2 is vulnerable to command injection in the CLI certificate SMIME recipient deletion functionality, allowing an authenticated privileged CLI user to … | Sep 29, 2026 |
| CVE-2026-84421 | HIGH | 8.8 | IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to improper validation of paths during … | Sep 29, 2026 |