CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Google
1Chrome
Sep 10, 2026
Sep 9, 2026
N/A· v4
8.3 HIGH· v3
N/A· v2
Insufficient policy enforcement in Extensions in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to potentially execute arbitrary c...Show more
Insufficient policy enforcement in Extensions in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)Show less
1Google
1Chrome
Sep 10, 2026
Sep 9, 2026
N/A· v4
9.6 CRITICAL· v3
N/A· v2
Use after free in Payments in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
1Google
1Chrome
Sep 10, 2026
Sep 9, 2026
N/A· v4
9.6 CRITICAL· v3
N/A· v2
Improper quantity validation in Tint in Google Chrome on on Mac prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security sever...Show more
Improper quantity validation in Tint in Google Chrome on on Mac prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)Show less
1Google
1Chrome
Sep 10, 2026
Sep 9, 2026
N/A· v4
8.1 HIGH· v3
N/A· v2
Race condition in Updater in Google Chrome on on Windows prior to 153.0.8010.36 allowed a local attacker to potentially execute arbitrary code outside the sandbox via a local program. (Chromium security severity: High)
1Google
1Chrome
Sep 10, 2026
Sep 9, 2026
N/A· v4
8.8 HIGH· v3
N/A· v2
Use after free in Platform in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
1Google
1Chrome
Sep 10, 2026
Sep 9, 2026
N/A· v4
8.1 HIGH· v3
N/A· v2
Race condition in Updater in Google Chrome on on Windows prior to 153.0.8010.36 allowed a local attacker to execute arbitrary code outside the sandbox via a local program. (Chromium security severity: Medium)
1Google
1Chrome
Sep 10, 2026
Sep 9, 2026
N/A· v4
9.6 CRITICAL· v3
N/A· v2
Use after free in Aura in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
1Google
1Chrome
Sep 10, 2026
Sep 9, 2026
N/A· v4
9.6 CRITICAL· v3
N/A· v2
Use after free in DevTools in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Low)
1Google
1Chrome
Sep 10, 2026
Sep 9, 2026
N/A· v4
8.8 HIGH· v3
N/A· v2
Memory corruption in Codecs in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
1Google
1Chrome
Sep 10, 2026
Sep 9, 2026
N/A· v4
8.8 HIGH· v3
N/A· v2
Out of bounds read in Media in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
1Google
1Chrome
Sep 10, 2026
Sep 9, 2026
N/A· v4
9.6 CRITICAL· v3
N/A· v2
Out of bounds write in WebGL in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)
1Google
1Chrome
Sep 10, 2026
Sep 9, 2026
N/A· v4
8.8 HIGH· v3
N/A· v2
Buffer overflow in WebRTC in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Low)
-
-
Sep 10, 2026
Sep 8, 2026
8.5 HIGH· v4
N/A· v3
N/A· v2
A stack-based buffer overflow vulnerability exists in the httpd component of RE210 AC750 due to improper bounds checking in the splitString function when processing an uploaded configuration file. An authenticated attack...Show more
A stack-based buffer overflow vulnerability exists in the httpd component of RE210 AC750 due to improper bounds checking in the splitString function when processing an uploaded configuration file. An authenticated attacker on the local network can upload a crafted configuration file to trigger the overflow, leading to remote code execution. Successful exploitation may allow unauthorized access to sensitive information, modification of device configuration and network behavior, or disruption of device availability.Show less
-
-
Sep 10, 2026
Sep 9, 2026
N/A· v4
9.8 CRITICAL· v3
N/A· v2
A heap-based buffer overflow in VPN certificate ASN.1 decoding may allow an unauthenticated remote attacker to execute arbitrary code on Check Point Quantum Security Management and Quantum Security Gateway systems.
-
-
Sep 10, 2026
Sep 9, 2026
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Improper certificate trust validation during VPN negotiation in Check Point Quantum Security Gateway may allow an unauthenticated remote attacker to execute arbitrary code on the Gateway.
-
-
Sep 10, 2026
Sep 8, 2026
N/A· v4
8.1 HIGH· v3
N/A· v2
A improper validation of certificate with host mismatch vulnerability in Fortinet FortiOS 7.6.1 through 7.6.6, FortiProxy 7.6.2 through 7.6.6 may allow attacker to information disclosure via <insert attack vector here>
-
-
Sep 10, 2026
Sep 8, 2026
N/A· v4
3.1 LOW· v3
N/A· v2
A url redirection to untrusted site ('open redirect') vulnerability in Fortinet FortiSIEM 7.5.0 through 7.5.1, FortiSIEM 7.4.1 through 7.4.2 may allow attacker to execute unauthorized code or commands via <insert attack...Show more
A url redirection to untrusted site ('open redirect') vulnerability in Fortinet FortiSIEM 7.5.0 through 7.5.1, FortiSIEM 7.4.1 through 7.4.2 may allow attacker to execute unauthorized code or commands via <insert attack vector here>Show less
-
-
Sep 10, 2026
Sep 8, 2026
N/A· v4
5.4 MEDIUM· v3
N/A· v2
A improper access control vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.6, FortiSOAR PaaS 7.5.0 through 7.5.3, FortiSOAR PaaS 7.4 all versions, FortiSOAR PaaS 7.3 all versions, FortiSOAR on-premise 7.6.0 thr...Show more
A improper access control vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.6, FortiSOAR PaaS 7.5.0 through 7.5.3, FortiSOAR PaaS 7.4 all versions, FortiSOAR PaaS 7.3 all versions, FortiSOAR on-premise 7.6.0 through 7.6.6, FortiSOAR on-premise 7.5.0 through 7.5.3, FortiSOAR on-premise 7.4 all versions, FortiSOAR on-premise 7.3 all versions may allow attacker to escalation of privilege via <insert attack vector here>Show less
-
-
Sep 10, 2026
Sep 8, 2026
7.6 HIGH· v4
8.1 HIGH· v3
N/A· v2
A security issue exists in MongoDB's LDAP authorization integration where pooled LDAP connections can retain stale authentication identities after user authentication under certain configurations. Subsequent authorizatio...Show more
A security issue exists in MongoDB's LDAP authorization integration where pooled LDAP connections can retain stale authentication identities after user authentication under certain configurations. Subsequent authorization queries may execute under an unintended LDAP identity rather than the expected one. This can result in incorrect role assignments based on the LDAP directory's access control configuration, potentially allowing an authenticated user to acquire elevated privileges that were not intended by the deployment's authorization policy.Show less
-
-
Sep 10, 2026
Sep 8, 2026
N/A· v4
8.1 HIGH· v3
N/A· v2
Use after free in DNS Server allows an unauthorized attacker to execute code over a network.
-
-
Sep 10, 2026
Sep 8, 2026
N/A· v4
8.1 HIGH· v3
N/A· v2
Use after free in Windows DNS allows an unauthorized attacker to execute code over a network.
-
-
Sep 10, 2026
Sep 8, 2026
N/A· v4
8.1 HIGH· v3
N/A· v2
Use after free in Windows DNS allows an unauthorized attacker to execute code over a network.
-
-
Sep 10, 2026
Sep 8, 2026
N/A· v4
7.8 HIGH· v3
N/A· v2
Heap-based buffer overflow in Windows Encrypting File System (EFS) allows an authorized attacker to elevate privileges locally.
-
-
Sep 10, 2026
Sep 8, 2026
N/A· v4
8.1 HIGH· v3
N/A· v2
Use after free in Windows DNS allows an unauthorized attacker to execute code over a network.
-
-
Sep 10, 2026
Sep 8, 2026
N/A· v4
7.1 HIGH· v3
N/A· v2
Use after free in Windows DWM Core Library allows an authorized attacker to elevate privileges over a network.