Export limit exceeded: 403739 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (43669 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-98353 | 1 Linux | 1 Linux Kernel | 2026-10-07 | 5.5 Medium |
| In the Linux kernel, the following vulnerability has been resolved: RDMA/erdma: Use IRQ-safe XArray helpers for QP and CQ tables Locked QP and CQ lookups from EQ interrupts can deadlock with create-path XArray updates. If an interrupt arrives while the create path holds the plain xa_lock, the lookup spins forever trying to acquire the same lock. Use IRQ-safe XArray helpers for all QP and CQ create-path updates, including the GSI QP store and error paths. Initialize both arrays with XA_FLAGS_LOCK_IRQ so sleeping allocations preserve interrupt state. | ||||
| CVE-2026-87114 | 1 Redhat | 4 Openshift, Openshift Container Platform, Pdrive Lightspeed and 1 more | 2026-10-07 | 7.1 High |
| A flaw was found in kube-compare. When processing a 'container://' reference path, the tool incorrectly executes an untrusted container image's entrypoint instead of merely extracting data from a stopped container. This allows a remote attacker to achieve arbitrary code execution on the operator's workstation. If the Docker daemon requires elevated privileges, the untrusted code may execute with root-mediated daemon privileges, posing a significant security risk. | ||||
| CVE-2026-102122 | 2 Accellion, Kiteworks | 2 Kiteworks, Core | 2026-10-07 | 4.3 Medium |
| Kiteworks did not correctly enforce which roles a shared folder's manager was permitted to assign. In a default configuration, an authenticated user holding the Manager role on a folder could grant the Owner role to themselves or to other members of that folder. | ||||
| CVE-2026-106260 | 1 Google | 1 Chrome | 2026-10-07 | 4.3 Medium |
| Incorrect authorization in DevTools in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low) | ||||
| CVE-2026-106264 | 1 Google | 1 Chrome | 2026-10-07 | 5.4 Medium |
| Missing authorization in Web Authentication (Passkeys & Security Keys) in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to spoof UI elements via a crafted HTML page. (Chromium security severity: Low) | ||||
| CVE-2026-106240 | 1 Google | 1 Chrome | 2026-10-07 | 8.8 High |
| Type confusion in V8 in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High) | ||||
| CVE-2026-106241 | 1 Google | 2 Android, Chrome | 2026-10-07 | 9.6 Critical |
| Incorrect authorization in Search in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium) | ||||
| CVE-2026-106270 | 1 Google | 1 Chrome | 2026-10-07 | 5.4 Medium |
| Incorrect authorization in WebAppInstalls in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to spoof UI elements via a crafted HTML page. (Chromium security severity: Low) | ||||
| CVE-2026-106371 | 1 Google | 2 Android, Chrome | 2026-10-07 | 8.8 High |
| Incorrect authorization in Transactions Platform in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Low) | ||||
| CVE-2026-106372 | 1 Google | 1 Chrome | 2026-10-07 | 9.6 Critical |
| Incorrect authorization in UI in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium) | ||||
| CVE-2026-106374 | 1 Google | 1 Chrome | 2026-10-07 | 8.8 High |
| Type confusion in V8 in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Low) | ||||
| CVE-2026-106293 | 1 Google | 1 Chrome | 2026-10-07 | 8.3 High |
| Type confusion in ANGLE in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High) | ||||
| CVE-2026-106295 | 1 Google | 1 Chrome | 2026-10-07 | 4.2 Medium |
| Incorrect authorization in Unbounded Element in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium) | ||||
| CVE-2026-102407 | 1 Elastic | 1 Elasticsearch | 2026-10-07 | 5.4 Medium |
| Incorrect Authorization (CWE-863) in Elasticsearch can lead to unauthorized data stream modification via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). An authenticated user with sufficient privileges over a single resource could use the Modify Data Streams API to modify a data stream to which they were not otherwise authorized, potentially injecting data into it or affecting its ability to be searched normally. This issue does not allow an attacker to read the contents of a data stream they do not otherwise have access to. | ||||
| CVE-2026-106309 | 2 Apple, Google | 2 Iphone Os, Chrome | 2026-10-07 | 8.8 High |
| Incorrect authorization in Selection in Google Chrome on on iOS prior to 155.0.8059.39 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Low) | ||||
| CVE-2026-106312 | 1 Google | 1 Chrome | 2026-10-07 | 6.5 Medium |
| Missing authorization in SignIn in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted Chrome extension. (Chromium security severity: Low) | ||||
| CVE-2026-106313 | 1 Google | 2 Android, Chrome | 2026-10-07 | 5.1 Medium |
| Incorrect authorization in Browser in Google Chrome on on Android prior to 155.0.8059.39 allowed a local attacker leveraging social engineering to obtain sensitive information via a co-installed app. (Chromium security severity: Medium) | ||||
| CVE-2026-106314 | 1 Google | 1 Chrome | 2026-10-07 | 8.8 High |
| Incorrect authorization in Bluetooth in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium) | ||||
| CVE-2026-106323 | 2 Apple, Google | 2 Iphone Os, Chrome | 2026-10-07 | 9.6 Critical |
| Missing authorization in Chrome for iOS in Google Chrome on on iOS prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High) | ||||
| CVE-2026-106388 | 1 Google | 1 Chrome | 2026-10-07 | 5.3 Medium |
| Missing authorization in DataTransfer in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium) | ||||