VulnSea

Tagged “cve.org”

CVEs tagged cve.org, newest first.

17241 CVEsRSS

CVE-2026-91723Low· 3.1⚖ disputed
2w ago

Race condition in WebAppInstalls in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to spoof UI elements via a crafted HTML page

Race condition in WebAppInstalls in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)

▾ Sunlitgoogle · chromeEPSS 0.17%via NVD
CVE-2026-91722High· 8.8
2w ago

Use after free in Input in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page

Use after free in Input in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

▾ Twilightgoogle · chromeEPSS 0.31%via NVD
CVE-2026-91721High· 8.8
2w ago

Use after free in Internals in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page

Use after free in Internals in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)

▾ Twilightgoogle · chromeEPSS 0.39%via NVD
CVE-2026-91720Medium· 4.7⚖ disputed
2w ago

Uninitialized resource in ANGLE in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to read memory outside the sandbox via a crafted HTML page

Uninitialized resource in ANGLE in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: High)

▾ Sunlitgoogle · chromeEPSS 0.28%via NVD
CVE-2026-91719High· 8.1⚖ disputed
2w ago

Code injection in XML in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to bypass web origin policy via a crafted HTML page

Code injection in XML in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to bypass web origin policy via a crafted HTML page. (Chromium security severity: Low)

▾ Twilightgoogle · chromeEPSS 0.23%via NVD
CVE-2026-91718Critical· 9.6
2w ago

Use after free in Core in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page

Use after free in Core in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

▾ Midnightgoogle · chromeEPSS 0.33%via NVD
CVE-2026-91717Medium· 5.1
2w ago

Missing authorization in Android in Google Chrome on on Android prior to 153.0.8010.47 allowed a local attacker to obtain sensitive information via a co-installed app

Missing authorization in Android in Google Chrome on on Android prior to 153.0.8010.47 allowed a local attacker to obtain sensitive information via a co-installed app. (Chromium security severity: High)

▾ Sunlitgoogle · chromeEPSS 0.09%via NVD
CVE-2026-91716Critical· 9.6
2w ago

Use after free in Auth in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page

Use after free in Auth in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

▾ Midnightgoogle · chromeEPSS 0.31%via NVD
CVE-2026-91715High· 8.8
2w ago

Type confusion in ServiceWorker in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page

Type confusion in ServiceWorker in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

▾ Twilightgoogle · chromeEPSS 0.33%via NVD
CVE-2026-91714Medium· 5.3
2w ago

Observable discrepancy in Fonts in Google Chrome prior to 153.0.8010.47 allowed a remote attacker leveraging social engineering to leak sensitive information via a crafted HTML page

Observable discrepancy in Fonts in Google Chrome prior to 153.0.8010.47 allowed a remote attacker leveraging social engineering to leak sensitive information via a crafted HTML page. (Chromium security severity: Medium)

▾ Sunlitgoogle · chromeEPSS 0.24%via NVD
CVE-2026-91713Medium· 4.2
2w ago

Missing authorization in Browser in Google Chrome prior to 153.0.8010.47 allowed a remote attacker who had compromised the renderer process to spoof UI elements via a crafted HTML page

Missing authorization in Browser in Google Chrome prior to 153.0.8010.47 allowed a remote attacker who had compromised the renderer process to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)

▾ Sunlitgoogle · chromeEPSS 0.19%via NVD
CVE-2026-91712High· 8.3
2w ago

Race condition in Extensions in Google Chrome on on Mac prior to 153.0.8010.47 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page

Race condition in Extensions in Google Chrome on on Mac prior to 153.0.8010.47 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromiu…

▾ Twilightgoogle · chromeEPSS 0.27%via NVD
CVE-2026-91711High· 8.8
2w ago

Out of bounds write in ServiceWorker in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page

Out of bounds write in ServiceWorker in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

▾ Twilightgoogle · chromeEPSS 0.31%via NVD
CVE-2026-91710Critical· 9.6
2w ago

Use after free in WebAppInstalls in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page

Use after free in WebAppInstalls in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

▾ Midnightgoogle · chromeEPSS 0.31%via NVD
CVE-2026-91709High· 8.8
2w ago

Type confusion in ServiceWorker in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page

Type confusion in ServiceWorker in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

▾ Twilightgoogle · chromeEPSS 0.41%via NVD
CVE-2026-91708Low· 3.1⚖ disputed
2w ago

Race condition in Network in Google Chrome prior to 153.0.8010.47 allowed a remote attacker who had compromised the renderer process to obtain cross-origin data via a crafted HTML page

Race condition in Network in Google Chrome prior to 153.0.8010.47 allowed a remote attacker who had compromised the renderer process to obtain cross-origin data via a crafted HTML page. (Chromium security severity: High)

▾ Sunlitgoogle · chromeEPSS 0.16%via NVD
CVE-2026-68491Critical· 9.4
2w ago

An insufficient check allowed for the overwrite of arbitrary files via a symlink.

An insufficient check allowed for the overwrite of arbitrary files via a symlink.

▾ MidnightWebpros · SolusVMEPSS 0.46%via NVD
CVE-2026-66887Critical· 9.6
2w ago

The affected products are missing authorization on state-changing CGIs and session checks are not performed.

The affected products are missing authorization on state-changing CGIs and session checks are not performed.

▾ MidnightDigital Watchdog · VMAX A1 G4 DVREPSS 0.33%via NVD
CVE-2026-66372Medium· 6.8
2w ago

The affected products use insufficiently random values, which allows web session tokens to be predictable, bounding token entropy to the seed space.

The affected products use insufficiently random values, which allows web session tokens to be predictable, bounding token entropy to the seed space.

▾ SunlitDigital Watchdog · VMAX A1 G4 DVREPSS 0.28%via NVD
CVE-2026-61568Critical· 9.6
2w ago

`@zereight/mcp-gitlab` is a Model Context Protocol server for GitLab

`@zereight/mcp-gitlab` is a Model Context Protocol server for GitLab. Versions prior to 2.1.30 expose the Streamable HTTP MCP endpoint without an effective Host or Origin allowlist. A malicious web page can use DNS rebinding to route bro…

▾ Midnightzereight · @zereight/mcp-gitlabEPSS 0.53%via NVD
CVE-2026-61559Critical· 9.6PoC
2w ago

`@zereight/mcp-gitlab` is a Model Context Protocol server for GitLab

`@zereight/mcp-gitlab` is a Model Context Protocol server for GitLab. Starting in version 0.0.1 and prior to version 2.1.27, when the environment variable `ENABLE_DYNAMIC_API_URL=true` is set, the server reads the `X-GitLab-API-URL` HTTP…

▾ Abyssalzereight · gitlab-mcpEPSS 0.43%via NVD
CVE-2026-61554High· 7.5PoC
2w ago

emp3r0r is a C2 designed by Linux users for Linux environments

emp3r0r is a C2 designed by Linux users for Linux environments. Prior to version 4.2.5, the `http_poll` C2 transport accepts attacker-controlled HTTP polling sessions before CBOR `MsgAuth` authentication is completed. A remote unauthenti…

▾ Midnightjm33-m0 · github.com/jm33-m0/emp3r0r/coreEPSS 0.71%via NVD
CVE-2026-19655Medium· 6.5
2w ago

On affected platforms running Arista EOS with Dynamic Host Configuration Protocol (DHCP) relay/snooping configured with the information option (Option 82), or with the DHCP server configured with match criteria based on the information o…

On affected platforms running Arista EOS with Dynamic Host Configuration Protocol (DHCP) relay/snooping configured with the information option (Option 82), or with the DHCP server configured with match criteria based on the information o…

▾ SunlitArista Networks · EOSEPSS 0.19%via NVD
CVE-2026-92237Medium· 6.5
2w ago

Insertion of sensitive information into log file in the slow query logging feature in Devolutions PowerShell Universal 2026.2.5 and earlier allows an authenticated user with log read permission to obtain application tokens, data protecti…

Insertion of sensitive information into log file in the slow query logging feature in Devolutions PowerShell Universal 2026.2.5 and earlier allows an authenticated user with log read permission to obtain application tokens, data protecti…

▾ SunlitDevolutions · PowerShell UniversalEPSS 0.37%via NVD
CVE-2026-81926Medium· 6.1⚖ disputed
2w ago

Concrete CMS 9.4.0 through 9.5.2 did not escape colliding page paths before rendering them in the location panel's duplicate-path confirmation dialog

Concrete CMS 9.4.0 through 9.5.2 did not escape colliding page paths before rendering them in the location panel's duplicate-path confirmation dialog. The panel's check endpoint returned the submitted path unmodified in its JSON response…

▾ Sunlitconcretecms · concrete_cmsEPSS 0.26%via NVD
CVE-2026-54544High· 7.2PoC
2w ago

Fireshare facilitates self-hosted media and link sharing

Fireshare facilitates self-hosted media and link sharing. Prior to version 1.6.16, two API endpoints that trigger outbound HTTP requests are missing the @login_required decorator. An unauthenticated attacker can call POST /api/test-disco…

▾ MidnightShaneIsrael · fireshareEPSS 0.41%via NVD
CVE-2026-18426Medium· 6.5⚖ disputed
2w ago

Concrete CMS 9.0.0 through 9.5.2 did not enforce a block-level edit-permission check on the Express Form block's control-management actions, which relied solely on CSRF token validation

Concrete CMS 9.0.0 through 9.5.2 did not enforce a block-level edit-permission check on the Express Form block's control-management actions, which relied solely on CSRF token validation. Because the token is bound to the user and action …

▾ Sunlitconcretecms · concrete_cmsEPSS 0.21%via NVD
CVE-2026-88065High· 7.5
2w ago

`tts-be` is a backend for a timetable selector that aims to help students better choose their class schedules

`tts-be` is a backend for a timetable selector that aims to help students better choose their class schedules. Versions prior to 2.1.0 have a Broken Access Control vulnerability across several API endpoints (such as `/api/student/{id}/ph…

▾ TwilightNIAEFEUP · tts-beEPSS 0.51%via NVD
CVE-2026-81927Medium· 5.4⚖ disputed
2w ago

Concrete CMS before 9.5.3 contained a stored cross-site scripting vulnerability in SVG file handling

Concrete CMS before 9.5.3 contained a stored cross-site scripting vulnerability in SVG file handling. When SVG processing was set to the non-default "Reject files containing potentially harmful elements" mode (concrete.file_manager.image…

▾ Sunlitconcretecms · concrete_cmsEPSS 0.24%via NVD
CVE-2026-68953Medium· 6.5
2w ago

The affected products are vulnerable to an authentication bypass that allows unauthenticated remote attackers to disclose sensitive device information, including administrator credentials in plaintext, by sending crafted HTTP(S) requests.

The affected products are vulnerable to an authentication bypass that allows unauthenticated remote attackers to disclose sensitive device information, including administrator credentials in plaintext, by sending crafted HTTP(S) requests.

▾ SunlitDigital Watchdog · VMAX A1 G4 DVREPSS 0.56%via NVD
CVEs tagged “cve.org” — page 240 · VulnSea