Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

42140
Total
3430
Critical
12454
High
12396
Medium
CVE ID Severity Score Description Published
CVE-2026-84347 HIGH 8.8 Use after free in WebRTC in Google Chrome prior to 152.0.7977.75 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted … Sep 02, 2026
CVE-2026-84335 HIGH 8.3 Incorrect authorization in TabStrip in Google Chrome prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to … Sep 02, 2026
CVE-2026-84334 HIGH 8.1 Incorrect authorization in Chromoting in Google Chrome on on Windows prior to 152.0.7977.75 allowed a local attacker to execute arbitrary code outside the sandbox via … Sep 02, 2026
CVE-2026-84333 CRITICAL 9.6 Use after free in Dawn in Google Chrome on on Android prior to 152.0.7977.75 allowed a remote attacker to execute arbitrary code outside the sandbox … Sep 02, 2026
CVE-2026-84332 MEDIUM 6.5 Incorrect authorization in SiteSettings in Google Chrome prior to 152.0.7977.75 allowed a remote attacker to bypass system access restrictions via a crafted HTML page. (Chromium … Sep 02, 2026
CVE-2026-84331 LOW 3.1 Incorrect authorization in Actor in Google Chrome prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process to bypass web origin policy … Sep 02, 2026
CVE-2026-84330 MEDIUM 5.4 UI misrepresentation in FullScreen in Google Chrome on on Android prior to 152.0.7977.75 allowed a remote attacker to spoof address bar via a crafted HTML … Sep 02, 2026
CVE-2026-84329 MEDIUM 5.3 Confused deputy in CredentialProvider in Google Chrome on on Windows prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process to leak … Sep 02, 2026
CVE-2026-84328 LOW 3.1 Missing authorization in FileSystem in Google Chrome prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process to bypass web origin policy … Sep 02, 2026
CVE-2026-84327 MEDIUM 6.5 Incorrect authorization in Autofill in Google Chrome on on Android prior to 152.0.7977.75 allowed a remote attacker leveraging social engineering to obtain sensitive information via … Sep 02, 2026
CVE-2026-84326 HIGH 8.8 Uninitialized resource in V8 in Google Chrome prior to 152.0.7977.75 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML … Sep 02, 2026
CVE-2026-84325 CRITICAL 9.8 Improper input validation in DataTransfer in Google Chrome prior to 152.0.7977.75 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a … Sep 02, 2026
CVE-2026-84324 CRITICAL 9.0 Use after free in Proxy in Google Chrome prior to 152.0.7977.75 allowed a remote attacker to execute arbitrary code outside the sandbox via crafted network … Sep 02, 2026
CVE-2026-84323 MEDIUM 5.3 Missing authorization in FileSystem in Google Chrome prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to … Sep 02, 2026
CVE-2026-81928 HIGH 7.5 Net::DNS versions before 1.57 for Perl allow memory exhaustion via unbounded recursion in sig_data when re-encoding a message with a misplaced TSIG record. sig_data signs … Sep 02, 2026
CVE-2026-84483 MEDIUM 5.3 WWBN AVideo through commit 9c39d8c8 contains an incomplete authentication bypass in encryptPass.json.php that allows unauthenticated attackers to compute valid HMAC tokens using the public site … Sep 01, 2026
CVE-2026-84482 HIGH 8.8 WWBN AVideo through commit 9c39d8c8 contains a cross-site request forgery vulnerability in the get_domain() and isSameDomain() functions that fail to properly validate referer origins. Attackers … Sep 01, 2026
CVE-2026-84481 UNKNOWN WWBN AVideo through 30.0 contains an information disclosure vulnerability in the MobileManager plugin getConfiguration endpoint that returns sensitive configuration data to unauthenticated visitors. Attackers can … Sep 01, 2026
CVE-2026-84480 CRITICAL 9.8 WWBN AVideo fails to validate password recovery token expiration in userRecoverPassSave.json.php, allowing attackers to use expired tokens to reset account passwords indefinitely. Attackers who obtain … Sep 01, 2026
CVE-2026-84479 CRITICAL 9.1 WWBN AVideo (current e01e41ecc and earlier) makes three login-time security controls depend solely on the client-supplied User-Agent header. The isAVideoEncoder()/isAVideoMobileApp() checks match HTTP_USER_AGENT against a … Sep 01, 2026
CVE-2026-84478 HIGH 7.3 WWBN AVideo contains a path traversal vulnerability in the API get_api_login_code endpoint that allows unauthenticated attackers to delete arbitrary .log files by supplying directory traversal … Sep 01, 2026
CVE-2026-84477 MEDIUM 5.4 AVideo Live_schedule::setTitle() and setDescription() store POST input without sanitization, allowing users with streaming permission to inject malicious scripts. Unauthenticated attackers can access remindMe.php to execute … Sep 01, 2026
CVE-2026-84476 HIGH 7.5 WWBN AVideo fails to validate trusted proxies before accepting X-Real-IP and X-Forwarded-For headers, allowing attackers to spoof the client address used by enforceRateLimit(). Attackers can … Sep 01, 2026
CVE-2026-84423 HIGH 7.3 A vulnerability has been found in Casdoor up to 4.0.0. This affects an unknown function of the file controllers/resource.go of the component upload-resource API. Such … Sep 01, 2026
CVE-2026-84208 HIGH 7.5 AVideo through version 29.0 contains an unauthenticated SQL injection vulnerability in the User_Location plugin's regions.json.php and cities.json.php endpoints. The country and region GET parameters are … Sep 01, 2026