144 CVEs — updated 2026-09-18 · vulnfeed
| CVE / ID | Title | Severity | CVSS | EPSS | Source | Date |
|---|---|---|---|---|---|---|
| CVE-2026-90999 | Sentry Seer is vulnerable to a multi-stage trust-boundary violation that allows unauthenticated attacker-controlled tele | CRITICAL | 9.8 | 13%ile | NVD | 2026-09-16 |
| CVE-2026-91738 | Improper input validation in ANGLE in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to potentially exec | CRITICAL | 9.6 | 27%ile | NVD | 2026-09-15 |
| CVE-2026-92860 | A security flaw has been discovered in rcourtman Pulse up to 6.0.4/6.1.0-rc.4. Affected by this issue is the function fm | CRITICAL | 9.4 | 40%ile | NVD | 2026-09-17 |
| CVE-2026-54501 | Browsertrix is a high-fidelity, browser-based crawling service for web archiving that can be self-hosted or used through | CRITICAL | 9.4 | 67%ile | NVD | 2026-09-17 |
| CVE-2026-90961 | The LdapAuth and LinOTPAuth authentication plugins in MISP contain an authentication bypass vulnerability. Both LdapAuth | CRITICAL | 9.3 | 39%ile | NVD | 2026-09-14 |
| CVE-2026-82441 | Description A submitted topology carries two lists of blobstore keys, `dependency_jars` and `dependency_artifacts`, whi | CRITICAL | 9.1 | 36%ile | NVD | 2026-09-14 |
| CVE-2026-53713 | Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway | CRITICAL | 9.1 | 35%ile | NVD | 2026-09-14 |
| CVE-2026-20237 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Identity Services Engine (ISE | CRITICAL | 9.1 | 26%ile | NVD | 2026-09-16 |
| CVE-2026-91932 | Flowise before 3.1.4 contains a validation bypass vulnerability in MCP server configuration allowing authenticated attac | CRITICAL | 9.0 | 56%ile | NVD | 2026-09-15 |
| CVE-2026-43692 | A validation issue was addressed with improved input sanitization. This issue is fixed in macOS Golden Gate 27, macOS Se | HIGH | 8.8 | 43%ile | NVD | 2026-09-14 |
| CVE-2026-65390 | An integer overflow was addressed with improved input validation. This issue is fixed in Safari 26.6.1, iOS 26.6.1 and i | HIGH | 8.8 | 33%ile | NVD | 2026-09-14 |
| CVE-2026-44300 | OpenCost provides cost monitoring for Kubernetes workloads and cloud costs. Prior to 1.121.0, the POST /serviceKey endpo | HIGH | 8.8 | 35%ile | NVD | 2026-09-15 |
| CVE-2026-56974 | In Start of AudioRtpPayloadEncoderNode.cpp, there is a possible out-of-bounds write due to improper input validation. Th | HIGH | 8.8 | 20%ile | NVD | 2026-09-15 |
| CVE-2026-58683 | In IP Multimedia Subsystem, there is a possible out-of-bounds write due to improper input validation. This could lead to | HIGH | 8.8 | 20%ile | NVD | 2026-09-15 |
| CVE-2026-88064 | Backstage is an open framework for building developer portals. Prior to 1.14.6 and from 1.15.0 until 1.15.4, the @backst | HIGH | 8.8 | 49%ile | NVD | 2026-09-16 |
| CVE-2026-12954 | The Mapster WP Maps plugin for WordPress is vulnerable to Arbitrary User Meta Write in all versions up to, and including | HIGH | 8.8 | 39%ile | NVD | 2026-09-18 |
| CVE-2026-81180 | SysReptor is a fully customizable pentest reporting platform. Prior to 2026.61, authenticated users of SysReptor Profess | HIGH | 8.8 | — | NVD | 2026-09-18 |
| CVE-2026-55072 | Pimcore is an Open Source Data & Experience Management Platform. Prior to 2026.1.5, an authenticated user with the objec | HIGH | 8.5 | 31%ile | NVD | 2026-09-14 |
| CVE-2026-93337 | NetworkManager-l2tp contains an improper input validation vulnerability that allows local users with VPN connection crea | HIGH | 8.5 | 4%ile | NVD | 2026-09-17 |
| CVE-2026-58691 | In FsmReleaseKey of fsm.c, there is a possible permission bypass due to improper input validation. This could lead to lo | HIGH | 8.4 | 0%ile | NVD | 2026-09-15 |
| CVE-2026-92903 | Improper input validation in Snowflake CLI versions prior to 3.27.0 allowed unsanitized user-controlled values to be int | HIGH | 8.2 | 4%ile | NVD | 2026-09-17 |
| CVE-2026-57130 | PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.59, src/praisonai-agents/praisonaiagents/tools/ema | HIGH | 8.1 | 28%ile | NVD | 2026-09-14 |
| CVE-2026-59569 | An improper input validation vulnerability in Zscaler Client Connector on Android and ChromeOS allows an attacker to pot | HIGH | 8.1 | 2%ile | NVD | 2026-09-14 |
| CVE-2026-54182 | backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of Laravel packages tha | HIGH | 8.1 | 38%ile | NVD | 2026-09-14 |
| CVE-2026-12355 | IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 | HIGH | 8.1 | 32%ile | NVD | 2026-09-15 |
| CVE-2026-79410 | Improper validation of the quantity parameter in the add-to-cart path of Webkul Bagisto v2.4.9 allows authenticated atta | HIGH | 8.1 | 28%ile | NVD | 2026-09-15 |
| CVE-2026-43688 | A memory corruption issue was addressed with improved input validation. This issue is fixed in iOS 27 and iPadOS 27, mac | HIGH | 7.8 | 5%ile | NVD | 2026-09-14 |
| CVE-2026-0199 | In gf_ta_test_set_config of gf_ta_test.c, there is a possible out-of-bounds write due to improper input validation. This | HIGH | 7.8 | 0%ile | NVD | 2026-09-15 |
| CVE-2026-58744 | In multiple locations, there is a possible escalation of privilege due to improper input validation. This could lead to | HIGH | 7.8 | 0%ile | NVD | 2026-09-15 |
| CVE-2025-39824 | HID: asus: fix UAF via HID_CLAIMED_INPUT validation | HIGH | 7.8 | 6%ile | Microsoft | 2025-09-09 |
| CVE-2026-13210 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.7 before 19.1.8, 19.2 before 19.2.6, and 1 | HIGH | 7.7 | 29%ile | NVD | 2026-09-15 |
| CVE-2026-59570 | On affected versions of Zscaler client connector, a pre-installed peer app can tear down the Zscaler tunnel, force user | HIGH | 7.5 | 1%ile | NVD | 2026-09-14 |
| CVE-2026-54632 | SIPSorcery is a WebRTC, SIP, and VoIP library for C# and .NET. Prior to 10.0.9, RTPChannel.OnRTPPacketReceived and the S | HIGH | 7.5 | 44%ile | NVD | 2026-09-14 |
| CVE-2026-28960 | A denial-of-service issue was addressed with improved validation. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10. | HIGH | 7.5 | 34%ile | NVD | 2026-09-14 |
| CVE-2026-84544 | An integer overflow was addressed with improved input validation. This issue is fixed in macOS Golden Gate 27, macOS Seq | HIGH | 7.5 | 37%ile | NVD | 2026-09-14 |
| CVE-2026-84553 | A resource exhaustion issue was addressed with improved input validation. This issue is fixed in macOS Golden Gate 27, m | HIGH | 7.5 | 44%ile | NVD | 2026-09-14 |
| CVE-2025-66974 | An issue in Prolink 13A Smart Plug Model Version: DS-3202M-UKv3 Wi-Fi and Application Version mEzee 2.6.7 allows attacke | HIGH | 7.5 | 31%ile | NVD | 2026-09-15 |
| CVE-2026-55306 | In Cellular Modem, there is a possible denial of service due to improper input validation. This could lead to remote den | HIGH | 7.5 | 19%ile | NVD | 2026-09-15 |
| CVE-2026-57008 | In Modem, there is a possible information disclosure due to improper input validation. This could lead to remote informa | HIGH | 7.5 | 18%ile | NVD | 2026-09-15 |
| CVE-2026-81875 | HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to versio | HIGH | 7.5 | 49%ile | NVD | 2026-09-16 |
| CVE-2026-81876 | HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to versio | HIGH | 7.5 | 49%ile | NVD | 2026-09-16 |
| CVE-2026-18911 | ManageEngine DataSecurity Plus versions before 6310 are vulnerable to an agent authentication bypass, allowing unenrolle | HIGH | 7.5 | 63%ile | NVD | 2026-09-18 |
| CVE-2026-93567 | HTTP/1 authority-form CONNECT is translated to malformed HTTP/2 CONNECT with Host-controlled :authority | HIGH | 7.5 | — | NVD | 2026-09-18 |
| CVE-2026-93568 | HTTP/2 and HTTP/3 Extended CONNECT requests are downgraded as regular CONNECT requests | HIGH | 7.5 | — | NVD | 2026-09-18 |
| CVE-2026-37460 | Missing input validation in the rfapiRibBi2Ri() function (rfapi_rib.c) of FRRouting (FRR) stable/10.0 to stable/10.6 all | HIGH | 7.5 | 27%ile | Microsoft | 2026-06-09 |
| CVE-2026-84620 | An integer overflow was addressed with improved input validation. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 2 | HIGH | 7.3 | 4%ile | NVD | 2026-09-14 |
| CVE-2026-84548 | An integer overflow was addressed with improved input validation. This issue is fixed in macOS Golden Gate 27, macOS Seq | HIGH | 7.1 | 4%ile | NVD | 2026-09-14 |
| CVE-2026-19655 | On affected platforms running Arista EOS with Dynamic Host Configuration Protocol (DHCP) relay/snooping configured with | HIGH | 7.1 | 9%ile | NVD | 2026-09-15 |
| CVE-2026-91819 | Affected versions of MISP rely on CakePHP request-method override processing in a way that can disable CSRF and form-sec | MEDIUM | 6.9 | 5%ile | NVD | 2026-09-15 |
| CVE-2026-47780 | free5GC is an open-source implementation of the 5G core network. In 4.2.3 and earlier, HandleCreateEeSubscriptions and H | MEDIUM | 6.9 | 34%ile | NVD | 2026-09-15 |
| CVE-2026-73445 | On affected platforms running Arista EOS, an issue with the gRPC Network Security Interface (gNSI) Authz Rotate RPC may | MEDIUM | 6.9 | 26%ile | NVD | 2026-09-16 |
| CVE-2026-61793 | Nuxt OG Image generates OG Images with Vue templates in Nuxt. From 6.0.2 until 6.7.0, nuxt-og-image exposes the unauthen | MEDIUM | 6.9 | 39%ile | NVD | 2026-09-17 |
| CVE-2026-61794 | Capsule is a multi-tenancy and policy-based framework for Kubernetes. From 0.13.0 until 0.13.7, the Tenant update valida | MEDIUM | 6.8 | — | NVD | 2026-09-18 |
| CVE-2026-55317 | In printf of printf.c, there is a possible out-of-bounds write due to improper input validation. This could lead to loca | MEDIUM | 6.7 | 0%ile | NVD | 2026-09-15 |
| CVE-2026-55332 | In multiple locations, there is a possible out-of-bounds write due to improper input validation. This could lead to loca | MEDIUM | 6.7 | 0%ile | NVD | 2026-09-15 |
| CVE-2026-56907 | In VPU, there is a possible shared memory overwrite due to improper input validation. This could lead to local escalatio | MEDIUM | 6.7 | 0%ile | NVD | 2026-09-15 |
| CVE-2026-56932 | In Trusted Execution Environment, there is a possible memory corruption due to improper input validation. This could lea | MEDIUM | 6.7 | 0%ile | NVD | 2026-09-15 |
| CVE-2026-58718 | In smmu_detach_dev_nested of arm-smmu-v3.c, there is a possible escalation of privilege due to improper input validation | MEDIUM | 6.7 | 0%ile | NVD | 2026-09-15 |
| CVE-2026-43788 | An integer overflow was addressed with improved input validation. This issue is fixed in macOS Golden Gate 27. Processin | MEDIUM | 6.6 | 4%ile | NVD | 2026-09-14 |
| CVE-2026-65412 | A null pointer dereference was addressed with improved input validation. This issue is fixed in iOS 26.7 and iPadOS 26.7 | MEDIUM | 6.5 | 39%ile | NVD | 2026-09-14 |
| CVE-2026-84487 | An integer overflow was addressed with improved input validation. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 2 | MEDIUM | 6.5 | 30%ile | NVD | 2026-09-14 |
| CVE-2026-84536 | An integer underflow was addressed with improved input validation. This issue is fixed in macOS Golden Gate 27, macOS Se | MEDIUM | 6.5 | 34%ile | NVD | 2026-09-14 |
| CVE-2026-84538 | A denial-of-service issue was addressed with improved input validation. This issue is fixed in macOS Golden Gate 27, mac | MEDIUM | 6.5 | 32%ile | NVD | 2026-09-14 |
| CVE-2026-84597 | An out-of-bounds read issue was addressed with improved input validation. This issue is fixed in iOS 27 and iPadOS 27, m | MEDIUM | 6.5 | 25%ile | NVD | 2026-09-14 |
| CVE-2026-86879 | A denial-of-service issue was addressed with improved input validation. This issue is fixed in iOS 27 and iPadOS 27. A r | MEDIUM | 6.5 | 31%ile | NVD | 2026-09-14 |
| CVE-2026-86885 | An input validation issue was addressed with improved input validation. This issue is fixed in iOS 27 and iPadOS 27. An | MEDIUM | 6.5 | 7%ile | NVD | 2026-09-14 |
| CVE-2026-86900 | An out-of-bounds read issue was addressed with improved input validation. This issue is fixed in macOS Golden Gate 27. M | MEDIUM | 6.5 | 18%ile | NVD | 2026-09-14 |
| CVE-2026-56831 | Shopper is a Headless e-commerce Admin Panel. Prior to 2.9.0, the /cpanel/discounts administrative interface accepts neg | MEDIUM | 6.5 | 35%ile | NVD | 2026-09-15 |
| CVE-2026-56975 | In Cellular Modem, there is a possible denial of service due to improper input validation. This could lead to remote (pr | MEDIUM | 6.5 | 1%ile | NVD | 2026-09-15 |
| CVE-2026-37458 | Missing input validation in the MP_REACH_NLRI component of FRRouting (FRR) stable/10.0 to stable/10.6 allows authenticat | MEDIUM | 6.5 | 17%ile | Microsoft | 2026-05-12 |
| CVE-2026-19543 | IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2 performs input valid | MEDIUM | 6.2 | 7%ile | NVD | 2026-09-14 |
| CVE-2026-77190 | On affected platforms running Arista EOS, an unauthenticated attacker who is network-adjacent to the switch and able to | MEDIUM | 6.0 | 21%ile | NVD | 2026-09-16 |
| CVE-2026-84554 | An integer overflow was addressed with improved input validation. This issue is fixed in macOS Golden Gate 27, macOS Seq | MEDIUM | 5.9 | 33%ile | NVD | 2026-09-14 |
| CVE-2026-54254 | Cyberdrop-DL is a bulk asynchronous downloader for multiple file hosts. From 8.5.0 until 9.14.0, the Pixeldrain crawler | MEDIUM | 5.9 | 25%ile | NVD | 2026-09-15 |
| CVE-2026-65408 | An integer overflow was addressed with improved input validation. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 2 | MEDIUM | 5.5 | 5%ile | NVD | 2026-09-14 |
| CVE-2026-65413 | An integer overflow was addressed with improved input validation. This issue is fixed in macOS Golden Gate 27, macOS Seq | MEDIUM | 5.5 | 6%ile | NVD | 2026-09-14 |
| CVE-2026-84517 | An integer overflow was addressed with improved input validation. This issue is fixed in macOS Golden Gate 27, macOS Seq | MEDIUM | 5.5 | 6%ile | NVD | 2026-09-14 |
| CVE-2026-84541 | An input validation issue was addressed with improved input validation. This issue is fixed in macOS Golden Gate 27, mac | MEDIUM | 5.5 | 5%ile | NVD | 2026-09-14 |
| CVE-2026-86886 | A path traversal issue was addressed with improved input validation. This issue is fixed in iOS 26.7 and iPadOS 26.7, iO | MEDIUM | 5.5 | 3%ile | NVD | 2026-09-14 |
| CVE-2026-86903 | An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 27 and iPadOS 27, macOS G | MEDIUM | 5.5 | 2%ile | NVD | 2026-09-14 |
| CVE-2026-86924 | A memory corruption issue was addressed with improved input validation. This issue is fixed in iOS 26.7 and iPadOS 26.7, | MEDIUM | 5.5 | 2%ile | NVD | 2026-09-14 |
| CVE-2023-29581 | yasm 1.3.0.55.g101bc has a segmentation violation in the function delete_Token at modules/preprocs/nasm/nasm-pp.c. NOTE: | MEDIUM | 5.5 | 28%ile | Microsoft | 2023-04-11 |
| CVE-2026-84532 | An out-of-bounds read issue was addressed with improved input validation. This issue is fixed in iOS 26.7 and iPadOS 26. | MEDIUM | 5.4 | 22%ile | NVD | 2026-09-14 |
| CVE-2025-36178 | IBM Controller 11.0.0 through 11.0.1 FP7, and 11.1.0 through 11.1.3 FP1 could allow an authenticated user to bypass inpu | MEDIUM | 5.4 | — | NVD | 2026-09-18 |
| CVE-2026-90614 | A weakness has been identified in FedML-AI FedML up to 0.9.6. Affected by this issue is the function S3Storage.read_mode | MEDIUM | 5.3 | 16%ile | NVD | 2026-09-14 |
| CVE-2026-54529 | SQLAdmin is a flexible Admin interface for SQLAlchemy models. Prior to 0.27.1, ModelView.sort_query in sqladmin/models.p | MEDIUM | 5.3 | 32%ile | NVD | 2026-09-14 |
| CVE-2026-86475 | The Appointment Hour Booking WordPress plugin before 1.5.95 does not check every appointment in a booking submission aga | MEDIUM | 5.3 | 17%ile | NVD | 2026-09-16 |
| CVE-2026-92581 | In AVideo through 29.0, Like::__construct() performs counter arithmetic on raw request values before validation, allowin | MEDIUM | 5.3 | 7%ile | NVD | 2026-09-16 |
| CVE-2026-88261 | Improper input validation vulnerability in bizwell xClick allows Stored XSS. This issue affects xClick: R2, R3, and R3. | MEDIUM | 5.1 | 13%ile | NVD | 2026-09-15 |
| CVE-2026-93295 | MISP contains a vulnerability in its background job dispatch mechanism that allows remote code execution as the web user | MEDIUM | 5.1 | 42%ile | NVD | 2026-09-17 |
| CVE-2026-56950 | In validate_ns_buf of mbu_class.rs, there is a possible information disclosure due to improper input validation. This co | MEDIUM | 4.4 | 0%ile | NVD | 2026-09-15 |
| CVE-2026-25684 | A file type attribution issue in Zscaler Internet Access File Type Control evaluation rules may allow improper evaluatio | MEDIUM | 4.4 | — | NVD | 2026-09-18 |
| CVE-2026-84450 | libheif is a HEIF and AVIF file format decoder and encoder. From 1.19.0 until 1.23.3, a crafted image item containing a | MEDIUM | 4.3 | — | NVD | 2026-09-18 |
| CVE-2026-90463 | A flaw was found in the sssd NSS responder. This input validation vulnerability allows a local attacker, by sending spec | MEDIUM | 4.0 | 1%ile | NVD | 2026-09-14 |
| CVE-2026-90575 | A weakness has been identified in PHPGurukul Small CRM 4.0. This impacts the function unserialize of the file /crm/login | LOW | 2.9 | 39%ile | NVD | 2026-09-13 |
| CVE-2026-44778 | Inspektor Gadget is a set of tools and framework for data collection and system inspection on Kubernetes clusters and Li | LOW | 2.9 | 39%ile | NVD | 2026-09-15 |
| CVE-2026-45723 | Omni manages Kubernetes on bare metal, virtual machines, or in a cloud. Prior to 1.6.6 and 1.7.3, managementServer.Creat | LOW | 2.7 | 32%ile | NVD | 2026-09-17 |
| CVE-2026-90490 | A security flaw has been discovered in lenve vhr 1.0-SNAPSHOT. This issue affects some unknown processing of the compone | LOW | 2.1 | 33%ile | NVD | 2026-09-13 |
| CVE-2026-54577 | mport is the MidnightBSD Package Manager. Prior to 2.7.8, the audit command in mport/mport.c computed option-adjusted lo | LOW | 2.0 | 5%ile | NVD | 2026-09-17 |
| CVE-2026-91842 | A vulnerability has been found in OpenBankProject OBP-API up to 1.10.1. This impacts the function KryoInjection.invert o | LOW | 1.2 | 30%ile | NVD | 2026-09-15 |
| CVE-2026-78900 | Chromium: CVE-2026-78900 Improper input validation in Media | UNKNOWN | — | 37%ile | Microsoft | 2026-08-11 |
| CVE-2026-78943 | Chromium: CVE-2026-78943 Improper input validation in Editing | UNKNOWN | — | 17%ile | Microsoft | 2026-08-11 |
| CVE-2026-78963 | Chromium: CVE-2026-78963 Improper input validation in Media | UNKNOWN | — | 38%ile | Microsoft | 2026-08-11 |
| CVE-2026-78976 | Chromium: CVE-2026-78976 Improper input validation in StorageAccessAPI | UNKNOWN | — | 31%ile | Microsoft | 2026-08-11 |
| CVE-2026-78980 | Chromium: CVE-2026-78980 Improper input validation in ReaderMode | UNKNOWN | — | 14%ile | Microsoft | 2026-08-11 |
| CVE-2026-79000 | Chromium: CVE-2026-79000 Improper input validation in DeviceBoundSessionCredentials | UNKNOWN | — | 20%ile | Microsoft | 2026-08-11 |
| CVE-2026-79013 | Chromium: CVE-2026-79013 Improper input validation in Sync | UNKNOWN | — | 40%ile | Microsoft | 2026-08-11 |
| CVE-2026-79015 | Chromium: CVE-2026-79015 Improper input validation in ServiceWorker | UNKNOWN | — | 20%ile | Microsoft | 2026-08-11 |
| CVE-2026-79025 | Chromium: CVE-2026-79025 Improper input validation in Workers | UNKNOWN | — | 11%ile | Microsoft | 2026-08-11 |
| CVE-2026-79032 | Chromium: CVE-2026-79032 Improper input validation in Network | UNKNOWN | — | 23%ile | Microsoft | 2026-08-11 |
| CVE-2026-79065 | Chromium: CVE-2026-79065 Improper input validation in Network | UNKNOWN | — | 25%ile | Microsoft | 2026-08-11 |
| CVE-2026-79066 | Chromium: CVE-2026-79066 Improper input validation in Navigation | UNKNOWN | — | 17%ile | Microsoft | 2026-08-11 |
| CVE-2026-79076 | Chromium: CVE-2026-79076 Improper input validation in Sync | UNKNOWN | — | 28%ile | Microsoft | 2026-08-11 |
| CVE-2026-79106 | Chromium: CVE-2026-79106 Improper input validation in Input | UNKNOWN | — | 18%ile | Microsoft | 2026-08-11 |
| CVE-2026-79109 | Chromium: CVE-2026-79109 Improper input validation in Printing | UNKNOWN | — | 28%ile | Microsoft | 2026-08-11 |
| CVE-2026-79111 | Chromium: CVE-2026-79111 Improper input validation in Dawn | UNKNOWN | — | 31%ile | Microsoft | 2026-08-11 |
| CVE-2026-79121 | Chromium: CVE-2026-79121 Improper input validation in Chromecast | UNKNOWN | — | 28%ile | Microsoft | 2026-08-11 |
| CVE-2026-79123 | Chromium: CVE-2026-79123 Improper input validation in NTP Footer | UNKNOWN | — | 14%ile | Microsoft | 2026-08-11 |
| CVE-2026-79139 | Chromium: CVE-2026-79139 Improper input validation in Media | UNKNOWN | — | 29%ile | Microsoft | 2026-08-11 |
| CVE-2026-79151 | Chromium: CVE-2026-79151 Improper input validation in Safebrowsing | UNKNOWN | — | 14%ile | Microsoft | 2026-08-11 |
| CVE-2026-79182 | Chromium: CVE-2026-79182 Improper input validation in Media | UNKNOWN | — | 23%ile | Microsoft | 2026-08-11 |
| CVE-2026-79192 | Chromium: CVE-2026-79192 Improper input validation in Variations | UNKNOWN | — | 16%ile | Microsoft | 2026-08-11 |
| CVE-2026-79203 | Chromium: CVE-2026-79203 Improper input validation in DevTools | UNKNOWN | — | 16%ile | Microsoft | 2026-08-11 |
| CVE-2026-79214 | Chromium: CVE-2026-79214 Improper input validation in Preload | UNKNOWN | — | 18%ile | Microsoft | 2026-08-11 |
| CVE-2026-79230 | Chromium: CVE-2026-79230 Improper input validation in ANGLE | UNKNOWN | — | 23%ile | Microsoft | 2026-08-11 |
| CVE-2026-79243 | Chromium: CVE-2026-79243 Improper input validation in ReadingList | UNKNOWN | — | 14%ile | Microsoft | 2026-08-11 |
| CVE-2026-79251 | Chromium: CVE-2026-79251 Improper input validation in Network | UNKNOWN | — | 20%ile | Microsoft | 2026-08-11 |
| CVE-2026-79253 | Chromium: CVE-2026-79253 Improper input validation in Network | UNKNOWN | — | 16%ile | Microsoft | 2026-08-11 |
| CVE-2026-79255 | Chromium: CVE-2026-79255 Improper input validation in WebRTC | UNKNOWN | — | 25%ile | Microsoft | 2026-08-11 |
| CVE-2026-79259 | Chromium: CVE-2026-79259 Improper input validation in Safebrowsing | UNKNOWN | — | 14%ile | Microsoft | 2026-08-11 |
| CVE-2026-79260 | Chromium: CVE-2026-79260 Improper input validation in Cookies | UNKNOWN | — | 17%ile | Microsoft | 2026-08-11 |
| CVE-2026-79272 | Chromium: CVE-2026-79272 Improper input validation in FindInPage | UNKNOWN | — | 16%ile | Microsoft | 2026-08-11 |
| CVE-2026-12003 | CPython >3.11 Insecure Input Validation resulting in privilege escalation | UNKNOWN | — | 4%ile | Microsoft | 2026-06-09 |
| CVE-2026-84325 | Chromium: CVE-2026-84325 Improper input validation in DataTransfer | UNKNOWN | — | 17%ile | Microsoft | 2026-09-08 |
| CVE-2026-84357 | Chromium: CVE-2026-84357 Improper input validation in Omnibox | UNKNOWN | — | 7%ile | Microsoft | 2026-09-08 |
| CVE-2026-87469 | Chromium CVE-2026-87469: Improper input validation in Extensions | UNKNOWN | — | 8%ile | Microsoft | 2026-09-08 |
| CVE-2026-87472 | Chromium CVE-2026-87472: Improper input validation in FedCM | UNKNOWN | — | 18%ile | Microsoft | 2026-09-08 |
| CVE-2026-87510 | Chromium CVE-2026-87510: Improper input validation in FileAPI | UNKNOWN | — | 31%ile | Microsoft | 2026-09-08 |
| CVE-2026-87553 | Chromium CVE-2026-87553: Improper input validation in SiteIsolation | UNKNOWN | — | 31%ile | Microsoft | 2026-09-08 |
| CVE-2026-87568 | Chromium CVE-2026-87568: Improper input validation in Chromium | UNKNOWN | — | 5%ile | Microsoft | 2026-09-08 |
| CVE-2026-87573 | Chromium CVE-2026-87573: Improper input validation in Network | UNKNOWN | — | 11%ile | Microsoft | 2026-09-08 |
| CVE-2026-87590 | Chromium CVE-2026-87590: Improper input validation in Passwords | UNKNOWN | — | 23%ile | Microsoft | 2026-09-08 |
| CVE-2026-87599 | Chromium CVE-2026-87599: Improper input validation in Interstitials | UNKNOWN | — | 8%ile | Microsoft | 2026-09-08 |
| CVE-2026-87600 | Chromium CVE-2026-87600: Improper input validation in Safebrowsing | UNKNOWN | — | 20%ile | Microsoft | 2026-09-08 |