CVE catalog
Published CVEs with severity, CVSS and CISA KEV status. For Windows we also carry the part most catalogs leave blank: the update that fixes it, and the build revision that carries the fix.
395,855 CVEs · 1,725 known exploited · 2,982 Windows CVEs with a fix we can name
Newest first.
| CVE | Severity | CVSS | Exploited | Fix | Published | Description |
|---|---|---|---|---|---|---|
| CVE-2026-91735 | High | 8.3 | - | - | 2026-09-15 | Incorrect authorization in WebUI in Google Chrome prior to 153.0.8010.47 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High) |
| CVE-2026-91734 | High | 7.4 | - | - | 2026-09-15 | Incorrect authorization in Core in Google Chrome on on Windows prior to 153.0.8010.47 allowed a local attacker to execute arbitrary code outside the sandbox via a local program. (Chromium security severity: High) |
| CVE-2026-91733 | High | 8.3 | - | - | 2026-09-15 | Improper state validation in Skia in Google Chrome prior to 153.0.8010.47 allowed a remote attacker who had compromised the renderer process to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: High) |
| CVE-2026-91732 | High | 8.1 | - | - | 2026-09-15 | Missing authorization in AppManifest in Google Chrome prior to 153.0.8010.47 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium) |
| CVE-2026-91731 | High | 8.8 | - | - | 2026-09-15 | Type confusion in Compositing in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High) |
| CVE-2026-91730 | Low | 3.1 | - | - | 2026-09-15 | Incomplete cleanup in GetUserMedia in Google Chrome prior to 153.0.8010.47 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to obtain cross-origin data via a crafted HTML page. (Chromium security severity: Medium) |
| CVE-2026-91729 | Critical | 9.6 | - | - | 2026-09-15 | Use after free in DigitalCredentials in Google Chrome prior to 153.0.8010.47 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High) |
| CVE-2026-91728 | Critical | 9.6 | - | - | 2026-09-15 | Integer overflow in V8 in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High) |
| CVE-2026-91727 | High | 8.1 | - | - | 2026-09-15 | Incorrect reference resolution in Extensions in Google Chrome on on Mac prior to 153.0.8010.47 allowed a local attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a local program. (Chromium security severity: High) |
| CVE-2026-91726 | Medium | 4.7 | - | - | 2026-09-15 | Out of bounds read in WebGL in Google Chrome on on Android prior to 153.0.8010.47 allowed a remote attacker to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: Critical) |
| CVE-2026-91725 | Medium | 5.3 | - | - | 2026-09-15 | Observable discrepancy in CSS in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to leak sensitive information via a crafted HTML page. (Chromium security severity: Medium) |
| CVE-2026-91724 | High | 8.3 | - | - | 2026-09-15 | Use after free in Input in Google Chrome prior to 153.0.8010.47 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High) |
| CVE-2026-91723 | Low | 3.1 | - | - | 2026-09-15 | Race condition in WebAppInstalls in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium) |
| CVE-2026-91722 | High | 8.8 | - | - | 2026-09-15 | Use after free in Input in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium) |
| CVE-2026-91721 | High | 8.8 | - | - | 2026-09-15 | Use after free in Internals in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical) |
| CVE-2026-91720 | Medium | 4.7 | - | - | 2026-09-15 | Uninitialized resource in ANGLE in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: High) |
| CVE-2026-91719 | High | 8.1 | - | - | 2026-09-15 | Code injection in XML in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to bypass web origin policy via a crafted HTML page. (Chromium security severity: Low) |
| CVE-2026-91718 | Critical | 9.6 | - | - | 2026-09-15 | Use after free in Core in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High) |
| CVE-2026-91717 | Medium | 5.1 | - | - | 2026-09-15 | Missing authorization in Android in Google Chrome on on Android prior to 153.0.8010.47 allowed a local attacker to obtain sensitive information via a co-installed app. (Chromium security severity: High) |
| CVE-2026-91716 | Critical | 9.6 | - | - | 2026-09-15 | Use after free in Auth in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High) |
| CVE-2026-91715 | High | 8.8 | - | - | 2026-09-15 | Type confusion in ServiceWorker in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High) |
| CVE-2026-91714 | Medium | 5.3 | - | - | 2026-09-15 | Observable discrepancy in Fonts in Google Chrome prior to 153.0.8010.47 allowed a remote attacker leveraging social engineering to leak sensitive information via a crafted HTML page. (Chromium security severity: Medium) |
| CVE-2026-91713 | Medium | 4.2 | - | - | 2026-09-15 | Missing authorization in Browser in Google Chrome prior to 153.0.8010.47 allowed a remote attacker who had compromised the renderer process to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium) |
| CVE-2026-91712 | High | 8.3 | - | - | 2026-09-15 | Race condition in Extensions in Google Chrome on on Mac prior to 153.0.8010.47 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High) |
| CVE-2026-91711 | High | 8.8 | - | - | 2026-09-15 | Out of bounds write in ServiceWorker in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High) |
| CVE-2026-91710 | Critical | 9.6 | - | - | 2026-09-15 | Use after free in WebAppInstalls in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High) |
| CVE-2026-91709 | High | 8.8 | - | - | 2026-09-15 | Type confusion in ServiceWorker in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High) |
| CVE-2026-91708 | Low | 3.1 | - | - | 2026-09-15 | Race condition in Network in Google Chrome prior to 153.0.8010.47 allowed a remote attacker who had compromised the renderer process to obtain cross-origin data via a crafted HTML page. (Chromium security severity: High) |
| CVE-2026-88065 | High | 7.5 | - | - | 2026-09-15 | `tts-be` is a backend for a timetable selector that aims to help students better choose their class schedules. Versions prior to 2.1.0 have a Broken Access Control vulnerability across several API endpoints (such as `/api/student/{id}/photo` and `/api/course_unit/{id}/exchange/metadata`). By chaining these unauthentica... |
| CVE-2026-81927 | Medium | 5.4 | - | - | 2026-09-15 | Concrete CMS before 9.5.3 contained a stored cross-site scripting vulnerability in SVG file handling. When SVG processing was set to the non-default "Reject files containing potentially harmful elements" mode (concrete.file_manager.images.svg_sanitization.action = reject), uploaded SVGs were checked only against a smal... |
| CVE-2026-81926 | Medium | 6.1 | - | - | 2026-09-15 | Concrete CMS 9.4.0 through 9.5.2 did not escape colliding page paths before rendering them in the location panel's duplicate-path confirmation dialog. The panel's check endpoint returned the submitted path unmodified in its JSON response, and client-side JavaScript inserted each value into the dialog as raw HTML, so a... |
| CVE-2026-79994 | - | - | - | - | 2026-09-15 | The guest-to-host Unix-domain socket relay in Docker Sandboxes validates that a socket path is inside an authorized workspace, but later reconnects using the pathname. A malicious guest can replace an intermediate directory with a symlink between validation and connection, causing the host to connect to an arbitrary AF... |
| CVE-2026-68953 | Medium | 6.5 | - | - | 2026-09-15 | The affected products are vulnerable to an authentication bypass that allows unauthenticated remote attackers to disclose sensitive device information, including administrator credentials in plaintext, by sending crafted HTTP(S) requests. |
| CVE-2026-68950 | High | 8.8 | - | - | 2026-09-15 | The affected products use hard-coded credentials, which could allow an attacker to run the ftpd service as root, providing remote root file access where FTP is reachable. |
| CVE-2026-68491 | - | - | - | - | 2026-09-15 | An insufficient check allowed for the overwrite of arbitrary files via a symlink. |
| CVE-2026-68070 | High | 8.8 | - | - | 2026-09-15 | The affected products are missing authentication for a critical function, which could allow an attacker to run as root and pass received bytes directly to a system command. |
| CVE-2026-66890 | Critical | 9.6 | - | - | 2026-09-15 | The affected products use hard-coded credentials, which could allow remote access to files with root privileges where FTP is reachable. |
| CVE-2026-66887 | Critical | 9.6 | - | - | 2026-09-15 | The affected products are missing authorization on state-changing CGIs and session checks are not performed. |
| CVE-2026-66372 | Medium | 6.8 | - | - | 2026-09-15 | The affected products use insufficiently random values, which allows web session tokens to be predictable, bounding token entropy to the seed space. |
| CVE-2026-61568 | Critical | 9.6 | - | - | 2026-09-15 | `@zereight/mcp-gitlab` is a Model Context Protocol server for GitLab. Versions prior to 2.1.30 expose the Streamable HTTP MCP endpoint without an effective Host or Origin allowlist. A malicious web page can use DNS rebinding to route browser requests to a victim's local MCP listener while preserving an attacker-control... |
| CVE-2026-61559 | Critical | 9.6 | - | - | 2026-09-15 | `@zereight/mcp-gitlab` is a Model Context Protocol server for GitLab. Starting in version 0.0.1 and prior to version 2.1.27, when the environment variable `ENABLE_DYNAMIC_API_URL=true` is set, the server reads the `X-GitLab-API-URL` HTTP request header and uses it as the base URL for all outbound GitLab API calls made... |
| CVE-2026-61554 | High | 7.5 | - | - | 2026-09-15 | emp3r0r is a C2 designed by Linux users for Linux environments. Prior to version 4.2.5, the `http_poll` C2 transport accepts attacker-controlled HTTP polling sessions before CBOR `MsgAuth` authentication is completed. A remote unauthenticated attacker can create arbitrary polling sessions and send request bodies that a... |
| CVE-2026-54544 | High | 7.2 | - | - | 2026-09-15 | Fireshare facilitates self-hosted media and link sharing. Prior to version 1.6.16, two API endpoints that trigger outbound HTTP requests are missing the @login_required decorator. An unauthenticated attacker can call POST /api/test-discord-webhook or POST /api/test-webhook and cause the Fireshare server to issue an arb... |
| CVE-2026-54337 | Critical | 9.8 | - | - | 2026-09-15 | Fireshare facilitates self-hosted media and link sharing. Prior to version 1.6.14, an argument Injection in the video upload function allows unauthenticated attacker to write/overwrite system files. Version 1.6.14 fixes the issue. |
| CVE-2026-19655 | Medium | 6.5 | - | - | 2026-09-15 | On affected platforms running Arista EOS with Dynamic Host Configuration Protocol (DHCP) relay/snooping configured with the information option (Option 82), or with the DHCP server configured with match criteria based on the information option, an unauthenticated attacker connected to a client-facing VLAN(s) where the r... |
| CVE-2026-18426 | Medium | 6.5 | - | - | 2026-09-15 | Concrete CMS 9.0.0 through 9.5.2 did not enforce a block-level edit-permission check on the Express Form block's control-management actions, which relied solely on CSRF token validation. Because the token is bound to the user and action rather than to a specific block, page, or form, an authenticated user with edit acc... |
| CVE-2026-92240 | Critical | 9.1 | - | - | 2026-09-15 | A malicious or compromised IMAP server can trigger an out-of-bounds read in the IMAP response parser by sending an untagged '* ID' response, crashing Thunderbird. The affected parsing path is reachable before authentication. This vulnerability was fixed in Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3. |
| CVE-2026-92239 | High | 8.1 | - | - | 2026-09-15 | A maliciously constructed IMAP line could cause an out-of-bounds buffer read. This vulnerability was fixed in Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3. |
| CVE-2026-92238 | Critical | 9.8 | - | - | 2026-09-15 | A maliciously constructed mail header could lead to multiple fields being parsed as one, or potential memory safety violations. This vulnerability was fixed in Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3. |
| CVE-2026-89040 | Critical | 9.8 | - | - | 2026-09-15 | Tencent Mass Service Engine in Cluster (MSEC) allows a remote, unauthenticated attacker to send a crafted POST request including ../ and gain root access on the target device. An attacker who uploads a webshell can execute arbitrary code as root. |
What the Fix column means
A KB means we hold Microsoft's own remediation data for that CVE: the update that fixes it and, where Microsoft publishes one, the build revision that carries the fix. That is the difference between knowing a CVE exists and knowing whether the machine in front of you is still exposed to it.
If you want that answered for a specific machine rather than a specific CVE, paste your build into the patch checker. It walks the supersedence chain, so it can tell you that the update you actually installed covers a fix that shipped in an earlier one.
Where the data comes from
CVE records, CVSS scores and descriptions come from NVD. The exploited flag comes from CISA's KEV catalog. Windows fix data comes from Microsoft's own security update feed. We are not endorsed by or certified by any of them.