VulnSea

Tagged “nvd”

CVEs tagged nvd, newest first.

32063 CVEsRSS

CVE-2026-87025Medium· 5.4
4w ago

Tanium addressed an improper access controls vulnerability in Comply.

Tanium addressed an improper access controls vulnerability in Comply.

▾ Sunlittanium · complyEPSS 0.29%via NVD
CVE-2026-87019Medium· 4.3
4w ago

Tanium addressed an improper access controls vulnerability in Comply.

Tanium addressed an improper access controls vulnerability in Comply.

▾ Sunlittanium · complyEPSS 0.26%via NVD
CVE-2026-14892Medium· 4.3
4w ago

Tanium addressed an improper access controls vulnerability in Tanium Server.

Tanium addressed an improper access controls vulnerability in Tanium Server.

▾ SunlitTanium · Tanium ServerEPSS 0.19%via NVD
CVE-2026-14505Medium· 6.6
4w ago

Tanium addressed a path traversal vulnerability in Tanium Data Service.

Tanium addressed a path traversal vulnerability in Tanium Data Service.

▾ SunlitTanium · Tanium Data ServiceEPSS 0.31%via NVD
CVE-2026-87084High· 7.7
4w ago

Tanium addressed a server-side request forgery vulnerability in Enforce.

Tanium addressed a server-side request forgery vulnerability in Enforce.

▾ Twilighttanium · enforceEPSS 0.34%via NVD
CVE-2026-87073Medium· 6.5
4w ago

Tanium addressed an improper access controls vulnerability in Comply.

Tanium addressed an improper access controls vulnerability in Comply.

▾ Sunlittanium · complyEPSS 0.30%via NVD
CVE-2026-87048Medium· 5.4
4w ago

Tanium addressed an improper access controls vulnerability in Comply.

Tanium addressed an improper access controls vulnerability in Comply.

▾ Sunlittanium · complyEPSS 0.29%via NVD
CVE-2026-87036High· 8.1
4w ago

Tanium addressed an improper access controls vulnerability in Comply.

Tanium addressed an improper access controls vulnerability in Comply.

▾ Twilighttanium · complyEPSS 0.38%via NVD
CVE-2026-87034High· 8.3
4w ago

Tanium addressed a SQL injection vulnerability in Comply.

Tanium addressed a SQL injection vulnerability in Comply.

▾ Twilighttanium · complyEPSS 0.33%via NVD
CVE-2026-87023High· 8.5
4w ago

Tanium addressed a path traversal vulnerability in Comply.

Tanium addressed a path traversal vulnerability in Comply.

▾ Twilighttanium · complyEPSS 0.46%via NVD
CVE-2026-76801High· 8.8
4w ago

The FireBox – WooCommerce Popup Builder, Exit Intent Popup, Email Optin & Cart Abandonment plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 3.1.10 via the value function

The FireBox – WooCommerce Popup Builder, Exit Intent Popup, Email Optin & Cart Abandonment plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 3.1.10 via the value function. This is due to a …

▾ Twilightfireplugins · FireBox – WooCommerce Popup Builder, Exit Intent Popup, Email Optin & Cart AbandonmentEPSS 0.94%via NVD
CVE-2026-13359High· 7.2
4w ago

The Contact Form to DB by BestWebSoft – Messages Database Plugin For WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via cntctfrm_contact_dropdown Parameter in all versions up to, and including, 1.7.5 due to i…

The Contact Form to DB by BestWebSoft – Messages Database Plugin For WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via cntctfrm_contact_dropdown Parameter in all versions up to, and including, 1.7.5 due to i…

▾ Twilightbestweblayout · Contact Form to DB by BestWebSoft – Messages Database Plugin For WordPressEPSS 0.24%via NVD
CVE-2026-12956Medium· 5.3
4w ago

The WP Event Solution (Eventin) plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 4.1.22 via the create_item() handler for the /wp-json/eventin/v2/orders REST endpoint

The WP Event Solution (Eventin) plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 4.1.22 via the create_item() handler for the /wp-json/eventin/v2/orders REST endpoint. The endpoint's create_it…

▾ Sunlitarraytics · Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerceEPSS 0.24%via NVD
CVE-2026-13709Medium· 6.4
4w ago

The Graphina – Charts and Graphs For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'iq_tree_tree_chart_template' Widget Setting in all versions up to, and including, 3.1.11 due to insufficient input sani…

The Graphina – Charts and Graphs For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'iq_tree_tree_chart_template' Widget Setting in all versions up to, and including, 3.1.11 due to insufficient input sani…

▾ Sunlitiqonicdesign · Graphina – Charts and Graphs For ElementorEPSS 0.19%via NVD
CVE-2026-87724Medium· 6.5
4w ago

Tor before 0.4.9.12 interprets the CC_RESPONSE extension even when CC_REQUEST was not sent, which allows remote attackers to cause a denial of service (crash) because of corrupted congestion-control state

Tor before 0.4.9.12 interprets the CC_RESPONSE extension even when CC_REQUEST was not sent, which allows remote attackers to cause a denial of service (crash) because of corrupted congestion-control state. This is TROVE-2026-032.

▾ Sunlittorprject · TorEPSS 0.43%via NVD
CVE-2026-87083Medium· 5.5
4w ago

A weakness has been identified in tile-ai tilelang up to 0.1.14

A weakness has been identified in tile-ai tilelang up to 0.1.14. This impacts the function KernelCache._load_kernel_from_disk of the file tilelang/cache/kernel_cache.py of the component Kernel Cache. Executing a manipulation can lead to …

▾ Sunlittile-ai · tilelangEPSS 0.34%via NVD
CVE-2026-87633High· 8.6
4w ago

Use after free in Views in Google Chrome prior to 153.0.8010.36 allowed a local attacker to execute arbitrary code outside the sandbox via UI Interaction

Use after free in Views in Google Chrome prior to 153.0.8010.36 allowed a local attacker to execute arbitrary code outside the sandbox via UI Interaction. (Chromium security severity: High)

▾ Twilightgoogle · chromeEPSS 0.15%via NVD
CVE-2026-87628High· 8.3
4w ago

Use after free in Cast in Google Chrome prior to 153.0.8010.36 allowed an adjacent attacker to potentially execute arbitrary code outside the sandbox via crafted network traffic

Use after free in Cast in Google Chrome prior to 153.0.8010.36 allowed an adjacent attacker to potentially execute arbitrary code outside the sandbox via crafted network traffic. (Chromium security severity: Critical)

▾ Twilightgoogle · chromeEPSS 0.19%via NVD
CVE-2026-87585High· 8.8
4w ago

Double free in PDFium in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code inside the sandbox via a crafted PDF file

Double free in PDFium in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code inside the sandbox via a crafted PDF file. (Chromium security severity: High)

▾ Twilightgoogle · chromeEPSS 0.38%via NVD
CVE-2026-87578High· 8.3
4w ago

Use after free in Receiver in Google Chrome prior to 153.0.8010.36 allowed an adjacent attacker to execute arbitrary code outside the sandbox via crafted network traffic

Use after free in Receiver in Google Chrome prior to 153.0.8010.36 allowed an adjacent attacker to execute arbitrary code outside the sandbox via crafted network traffic. (Chromium security severity: High)

▾ Twilightgoogle · chromeEPSS 0.19%via NVD
CVE-2026-87569High· 8.8
4w ago

Missing authorization in Views in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page

Missing authorization in Views in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: High)

▾ Twilightgoogle · chromeEPSS 0.34%via NVD
CVE-2026-87527Critical· 9.6
4w ago

Buffer overflow in WebGL in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page

Buffer overflow in WebGL in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)

▾ Midnightgoogle · chromeEPSS 0.51%via NVD
CVE-2026-87525Low· 2.7⚖ disputed
4w ago

Out of bounds read in Chromoting in Google Chrome on on Windows prior to 153.0.8010.36 allowed a local attacker to read memory outside the sandbox via a local program

Out of bounds read in Chromoting in Google Chrome on on Windows prior to 153.0.8010.36 allowed a local attacker to read memory outside the sandbox via a local program. (Chromium security severity: High)

▾ Sunlitgoogle · chromeEPSS 0.11%via NVD
CVE-2026-87524High· 8.3
4w ago

Use after free in Core in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page

Use after free in Core in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium …

▾ Twilightgoogle · chromeEPSS 0.40%via NVD
CVE-2026-87517Low· 3.1
4w ago

Race condition in Mobile in Google Chrome on on iOS prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass web origin policy via a crafted HTML page

Race condition in Mobile in Google Chrome on on iOS prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass web origin policy via a crafted HTML page. (Chromium security severity: High)

▾ Sunlitgoogle · chromeEPSS 0.19%via NVD
CVE-2026-87512Critical· 9.6
4w ago

Use after free in ANGLE in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page

Use after free in ANGLE in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

▾ Midnightgoogle · chromeEPSS 0.46%via NVD
CVE-2026-87488Critical· 9.6
4w ago

Use after free in WebGL in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page

Use after free in WebGL in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)

▾ Midnightgoogle · chromeEPSS 0.46%via NVD
CVE-2026-87464Critical· 9.6
4w ago

Use after free in WebGL in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page

Use after free in WebGL in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)

▾ Midnightgoogle · chromeEPSS 0.58%via NVD
CVE-2026-87447Medium· 6.5
4w ago

Incorrect authorization in Network in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass web origin policy via a crafted Chrome extension

Incorrect authorization in Network in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass web origin policy via a crafted Chrome extension. (Chromium security severity: High)

▾ Sunlitgoogle · chromeEPSS 0.26%via NVD
CVE-2026-87444High· 8.8
4w ago

Memory corruption in Codecs in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page

Memory corruption in Codecs in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

▾ Twilightgoogle · chromeEPSS 0.41%via NVD
CVEs tagged “nvd” — page 435 · VulnSea