Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
3.1 LOW
CVE-2026-85052 — Google Chrome CrashReporting Out-of-Bounds Read

Out of bounds read in CrashReporting in Google Chrome prior to 152.0.7977.82 allowed a remote attacker who had compromised the renderer process to read memory outside the sandbox via a crafted HTML p…

chrome chrome | Remote | Memory Corruption
Sep 03, 2026 Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
8.8 HIGH
CVE-2026-85051 — Google Chrome Compositing Type Confusion

Type confusion in Compositing in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

chrome chrome | Remote | Memory Corruption
Sep 03, 2026 Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
9.6 CRITICAL
CVE-2026-85050 — Google Chrome WebGL Out-of-Bounds Write

Out of bounds write in WebGL in Google Chrome on on Android prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security …

chrome chrome | Remote | Memory Corruption
Sep 03, 2026 Sep 04, 2026
Sep 03, 2026
Sep 04, 2026
8.8 HIGH
CVE-2026-85049 — Google Chrome Skia Use-After-Free Vulnerability

Use after free in Skia in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

chrome chrome | Remote | Memory Corruption
Sep 03, 2026 Sep 04, 2026
Sep 03, 2026
Sep 04, 2026
8.3 HIGH
CVE-2026-85048 — Google Chrome Compositing Use After Free

Use after free in Compositing in Google Chrome prior to 152.0.7977.82 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a crafted HT…

chrome chrome | Remote | Memory Corruption
Sep 03, 2026 Sep 04, 2026
Sep 03, 2026
Sep 04, 2026
9.6 CRITICAL
CVE-2026-85047 — Google Chrome Transactions Platform Improper Input Validation Vulnerability

Improper input validation in Transactions Platform in Google Chrome on on iOS prior to 152.0.7977.82 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted …

chrome chrome | Remote | Injection
Sep 03, 2026 Sep 04, 2026
Sep 03, 2026
Sep 04, 2026
8.8 HIGH
CVE-2026-85046 — Google Chrome V8 Type Confusion Vulnerability

Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

chrome chrome | Remote | Memory Corruption
Sep 03, 2026 Sep 04, 2026
Sep 03, 2026
Sep 04, 2026
7.5 HIGH
CVE-2026-85045 — Google Chrome V8 Race Condition Vulnerability

Race condition in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

chrome chrome | Remote | Race Condition
Sep 03, 2026 Sep 04, 2026
Sep 03, 2026
Sep 04, 2026
0.0 NA
CVE-2026-85044 — Google Chrome Use-After-Free Vulnerability

Use of released resource in Mobile in Google Chrome on on Android prior to 152.0.7977.82 allowed a remote attacker leveraging social engineering to bypass web origin policy via a crafted HTML page. (…

chrome chrome | Misconfiguration
Sep 03, 2026 Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
0.0 NA
CVE-2026-85043 — Google Chrome Network System Access Restriction Bypass

Incomplete cleanup in Network in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to bypass system access restrictions via crafted network traffic. (Chromium security severity: High)

chrome chrome | Misconfiguration
Sep 03, 2026 Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
9.6 CRITICAL
CVE-2026-85042 — Google Chrome DevTools Use-After-Free Vulnerability

Use after free in DevTools in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

chrome chrome | Remote | Memory Corruption
Sep 03, 2026 Sep 04, 2026
Sep 03, 2026
Sep 04, 2026
8.7 HIGH
CVE-2026-82527 — R2R 3.6.6 SQL Injection via Retrieval Search Filter Key

R2R through 3.6.6 contains a SQL injection vulnerability that allows unauthenticated attackers to inject SQL predicates into the chunks search query by manipulating the filter key parameter in the re…

Remote | Injection
Sep 03, 2026 Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
7.1 HIGH
CVE-2026-53728 — Medplum - Improper Validation of Redirect URI in External Auth Callback allows Authorizat…

Medplum is a developer platform that enables development of healthcare apps. Prior to version 5.1.6, the external identity provider callback at GET /auth/external accepts attacker-controlled redirect…

Remote | Authentication
Sep 03, 2026 Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
8.2 HIGH
CVE-2026-44506 — Medplum - Exposure of OAuth client secret via dynamic registration endpoint in self-hoste…

Medplum is a developer platform that enables development of healthcare apps. In Medplum versions 4.1.10 through 5.1.6, the /oauth2/register endpoint could return the client_secret of preconfigured OA…

Remote | Authentication
Sep 03, 2026 Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
6.2 MEDIUM
CVE-2026-19795 — Qiskit SDK is vulnerable when deserializing QPY Files and may overflow the available stac…

IBM Qiskit SDK 2.1.0 through 2.5.1 could allow a local attacker to cause a denial of service due to improper handling of a specially crafted object during deserialization. A malicious QPY payload can…

qiskit_sdk | Denial of Service
Sep 03, 2026 Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
8.7 HIGH
CVE-2026-85396 — rubyzip before 3.4.0 Path Traversal in Zip::Entry#extract via Sibling-Directory Prefix

rubyzip versions before 3.4.0 contain a path traversal vulnerability in Zip::Entry#extract that fails to properly validate extraction paths using prefix comparison without trailing separators. Attack…

Remote | Path Traversal
Sep 03, 2026 Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
7.1 HIGH
CVE-2026-85395 — UnoPim before 2.1.3 Missing Authorization on Integration Management Routes

UnoPim before 2.1.3 fails to include integration store, update, and key-generation routes in its ACL map, allowing any admin user to bypass permission checks. Attackers with minimal admin privileges …

Remote | Authorization
Sep 03, 2026 Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
9.3 CRITICAL
CVE-2026-85394 — python-jose through 3.5.0 Algorithm Confusion via DER-encoded Public Key as HMAC Secret

python-jose through 3.5.0 fails to properly validate asymmetric keys in HMAC initialization, accepting DER-encoded public keys that lack PEM armor or SSH prefixes. Attackers holding the service's pub…

Remote | Cryptography
Sep 03, 2026 Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
8.7 HIGH
CVE-2026-85393 — node-forge through 1.4.0 RSA PKCS#1 v1.5 Signature Forgery via Nested DigestAlgorithm Pad…

node-forge through 1.4.0 fails to validate element count in nested DigestAlgorithm sequences during RSA PKCS#1 v1.5 signature verification. Attackers can embed garbage bytes inside the DigestAlgorith…

forge | Remote | Injection
Sep 03, 2026 Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
5.3 MEDIUM
CVE-2026-85392 — Peppermint through 0.5.5 Authorization Bypass on the User Logout Endpoint

Peppermint through 0.5.5 contains an authorization bypass vulnerability in the GET /api/v1/auth/user/:id/logout endpoint that allows authenticated attackers to delete sessions for any user by supplyi…

Remote | Authorization
Sep 03, 2026 Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
Showing 20 of 12654 Results