Export limit exceeded: 11548 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Export limit exceeded: 389537 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Search

Search Results (389537 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-87447 2026-09-09 N/A
Incorrect authorization in Network in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass web origin policy via a crafted Chrome extension. (Chromium security severity: High)
CVE-2026-87446 2026-09-09 N/A
Incomplete cleanup in Extensions in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted Chrome extension. (Chromium security severity: Medium)
CVE-2026-87450 2026-09-09 N/A
Incorrect authorization in Permissions in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted Chrome extension. (Chromium security severity: Medium)
CVE-2026-87431 2026-09-09 N/A
Missing authorization in Extensions in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to obtain sensitive information via a crafted Chrome extension. (Chromium security severity: Medium)
CVE-2026-87429 2026-09-09 N/A
Missing authorization in ServiceWorker in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Low)
CVE-2026-21042 1 Samsung Mobile 1 Samsung Mobile Devices 2026-09-09 N/A
Out-of-bounds write in libsavsac.so prior to SMR Jul-2026 Release 1 allows remote attackers to execute arbitrary code.
CVE-2026-12855 2026-09-09 8.2 High
Unvalidated memory boundary could result in arbitrary code execution. The vulnerability exists in the code developed specifically for HP projects.
CVE-2026-9216 2026-09-09 3.5 Low
An insufficient input validation vulnerability in the listed NETGEAR RAX series models allows a network-adjacent attacker having network access (such as WiFi credentials) to crash the router's management UI. There is no confidentiality or integrity impact. A crash of the router's management UI does not impact the availability of the router's core services like WiFi network.
CVE-2026-6485 2026-09-09 8.2 High
UEFI BIOS embedded Shell could be used to bypass Secure Boot via shell commands or startup scripts.
CVE-2026-9215 2026-09-09 6.7 Medium
A cross site request forgery (CSRF) vulnerability in the listed NETGEAR models allows an attacker who can leverage social engineering techniques on a router administrator to tamper with router configuration and disrupt router operations with active assistance from the router administrator. There is no confidentiality impact due to this vulnerability.
CVE-2026-19398 1 Asus 2 Fa507nu, Fa507nv 2026-09-09 N/A
An out-of-bounds write in the SmiFlash SMM module of ASUS FA507NU and FA507NV BIOS allows a local  administrator to cause a system crash (BSOD) or BIOS corruption via a crafted software SMI (SW SMI) request with an oversized length value.Refer to the '  Security Update for ASUS FA507NV / FA507NU BIOS   ' section on the ASUS Security Advisory for more information.
CVE-2026-19797 2026-09-09 6.1 Medium
The User Access Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'tab_group_section' parameter in all versions up to, and including, 2.3.18 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
CVE-2026-77187 2026-09-09 6.4 Medium
The My Calendar – Accessible Event Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'before' and 'after' Shortcode Attributes in all versions up to, and including, 3.8.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
CVE-2026-11814 1 Netgear 52 Be9300, Be9300 Firmware, Mr60 and 49 more 2026-09-09 6.8 Medium
A command injection vulnerability in the listed NETGEAR models allows a network-adjacent attacker with the ability to intercept and modify local network traffic (attacker-in-the-middle) to compromise the confidentiality and integrity of the affected device. This issue is limited to certain region-specific SKUs.
CVE-2026-11738 1 Netgear 55 Be9300, Be9300 Firmware, Mr60 and 52 more 2026-09-09 4.4 Medium
Insufficient input validation vulnerability in the listed NETGEAR models allows authenticated administrators connected to the local network to make unauthorized modification to router software and functionality.
CVE-2026-9214 1 Netgear 2 R7000, R7000 Firmware 2026-09-09 4.5 Medium
Insufficient input validation vulnerability in the NETGEAR R7000 models allows authenticated administrators connected to the local network to make unauthorized modification to router software and functionality.
CVE-2026-11739 1 Netgear 54 Mr60, Mr60 Firmware, Mr70 and 51 more 2026-09-09 6.4 Medium
A command injection vulnerability in certain affected NETGEAR Nighthawk devices allows a network-adjacent attacker with the ability to intercept and modify local network traffic (attacker in the middle) to compromise the confidentiality and integrity of the affected device.
CVE-2026-11737 1 Netgear 26 Rax20, Rax20 Firmware, Rax41 and 23 more 2026-09-09 4.5 Medium
Insufficient input validation vulnerability in the listed NETGEAR models allows authenticated administrators connected to the local network to make unauthorized modification to the device software and functionality.
CVE-2026-11733 1 Netgear 22 Rax41, Rax41 Firmware, Rax41v2 and 19 more 2026-09-09 4.9 Medium
A buffer overflow vulnerability in the listed NETGEAR models allows a device administrator to temporarily interrupt the normal operation of the affected device.
CVE-2026-11734 1 Netgear 30 Mr70, Mr70 Firmware, Mr90 and 27 more 2026-09-09 2.7 Low
A buffer overflow vulnerability in the listed NETGEAR models allows an authenticated admin user to cause the affected device to become temporarily unavailable.