3w ago
2026-08-25 21:17Z
HIGH

CVE-2026-78938 — Type: confusion in V8 in Google Chrome prior to 152.0.7977.65 allowed a remote attacker

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-78938

Type confusion in V8 in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.8 (HIGH)

CWECWE 843VNDTypeTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
3w ago
2026-08-25 21:17Z
CRIT

CVE-2026-78937 — Use: after free in Search in Google Chrome on on Android prior to 152.0.7977.65

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-78937

Use after free in Search in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium) CVSSv3.1 9.6 (CRITICAL)

CWECWE 416TYPVulnerability
9.6
CVSS v3.1
98
Edit Score
3w ago
2026-08-25 21:17Z
CRIT

CVE-2026-78935 — Google Chrome: Use of uninitialized variable in Mobile in Google Chrome on on iOS prior to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-78935

Use of uninitialized variable in Mobile in Google Chrome on on iOS prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical) CVSSv3.1 9.6 (CRITICAL)

CWECWE 457VNDGoogleTYPVulnerability
9.6
CVSS v3.1
98
Edit Score
3w ago
2026-08-25 21:17Z
HIGH

CVE-2026-78934 — Race: condition in ReadAloud in Google Chrome prior to 152.0.7977.65 allowed a remote attacker

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-78934

Race condition in ReadAloud in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.3 (HIGH)

CWECWE 362VNDRaceTYPVulnerability
8.3
CVSS v3.1
92
Edit Score
3w ago
2026-08-25 21:17Z
HIGH

CVE-2026-78913 — Use: after free in Chromoting in Google Chrome prior to 152.0.7977.65 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-78913

Use after free in Chromoting in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via crafted network traffic. (Chromium security severity: Medium) CVSSv3.1 8.1 (HIGH)

CWECWE 416TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
3w ago
2026-08-25 21:17Z
HIGH

CVE-2026-78911 — Incorrect: authorization in USB in Google Chrome prior to 152.0.7977.65 allowed a remote attacker

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-78911

Incorrect authorization in USB in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.3 (HIGH)

CWECWE 863TYPVulnerability
8.3
CVSS v3.1
92
Edit Score
3w ago
2026-08-25 21:17Z
HIGH

CVE-2026-78910 — Buffer: overflow in V8 in Google Chrome prior to 152.0.7977.65 allowed a remote attacker

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-78910

Buffer overflow in V8 in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium) CVSSv3.1 8.8 (HIGH)

CWECWE 121VNDBufferTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
728 × 90 / responsive · programmatic ad slot
3w ago
2026-08-25 21:17Z
CRIT

CVE-2026-78909 — Use: after free in Views in Google Chrome prior to 152.0.7977.65 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-78909

Use after free in Views in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium) CVSSv3.1 9.6 (CRITICAL)

CWECWE 416TYPVulnerability
9.6
CVSS v3.1
98
Edit Score
3w ago
2026-08-25 21:17Z
HIGH

CVE-2026-78905 — Type: confusion in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-78905

Type confusion in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium) CVSSv3.1 8.8 (HIGH)

CWECWE 843VNDTypeTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
3w ago
2026-08-25 21:17Z
CRIT

CVE-2026-78904 — Type: confusion in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-78904

Type confusion in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 9.6 (CRITICAL)

CWECWE 843VNDTypeTYPVulnerability
9.6
CVSS v3.1
98
Edit Score
3w ago
2026-08-25 21:17Z
CRIT

CVE-2026-78900 — Media: Improper input validation in Media in Google Chrome prior to 152.0.7977.65 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-78900

Improper input validation in Media in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 9.6 (CRITICAL)

CWECWE 20VNDMediaTYPVulnerability
9.6
CVSS v3.1
98
Edit Score
3w ago
2026-08-25 21:17Z
HIGH

CVE-2026-78899 — Use: after free in V8 in Google Chrome prior to 152.0.7977.65 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-78899

Use after free in V8 in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.8 (HIGH)

CWECWE 416TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
3w ago
2026-08-25 21:17Z
HIGH

CVE-2026-78891 — Buffer: overflow in WebRTC in Google Chrome prior to 152.0.7977.65 allowed a remote attacker

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-78891

Buffer overflow in WebRTC in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium) CVSSv3.1 8.8 (HIGH)

CWECWE 122VNDBufferTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
3w ago
2026-08-25 21:17Z
HIGH

CVE-2026-65105 — NVIDIA: A successful exploit of this vulnerability may lead to information disclosure and denial of

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-65105

NVIDIA NemoClaw for Linux contains a vulnerability in its inference server setup, where a remote attacker may access the inference service without authentication. A successful exploit of this vulnerability may lead to information disclosure and denial of service. CVSSv3.1 8.1 (HIGH)

CWECWE 306VNDNvidiaTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
3w ago
2026-08-25 21:17Z
HIGH

CVE-2026-65098 — NVIDIA: A successful exploit of this vulnerability might lead to code execution, information disclosure, and

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-65098

NVIDIA NemoClaw for Linux contains a vulnerability in its remote-access helper workflow, where an attacker could cause weak authentication. A successful exploit of this vulnerability might lead to code execution, information disclosure, and data tampering. CVSSv3.1 8.1 (HIGH)

CWECWE 1390VNDNvidiaTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
3w ago
2026-08-25 21:17Z
CRIT

CVE-2026-65093 — NVIDIA: A successful exploit of this vulnerability might lead to code execution, escalation of privileges

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-65093

NVIDIA OpenShell for Linux contains a vulnerability where an attacker could cause a sandbox escape. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, and information disclosure. CVSSv3.1 9.9 (CRITICAL)

CWECWE 427VNDNvidiaTYPVulnerability
9.9
CVSS v3.1
100
Edit Score
3w ago
2026-08-25 21:17Z
HIGH

CVE-2026-65092 — NVIDIA: OpenShell Sandbox for Linux contains a vulnerability where an attacker could cause a

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-65092

NVIDIA OpenShell Sandbox for Linux contains a vulnerability where an attacker could cause a path traversal bypass of L7 REST network policy. A successful exploit of this vulnerability might lead to information disclosure and data tampering. CVSSv3.1 8.5 (HIGH)

CWECWE 22VNDNvidiaTYPVulnerability
8.5
CVSS v3.1
93
Edit Score
3w ago
2026-08-25 21:17Z
HIGH

CVE-2026-65091 — NVIDIA: OpenShell for all platforms contains a vulnerability where a malicious gateway could cause

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-65091

NVIDIA OpenShell for all platforms contains a vulnerability where a malicious gateway could cause OS command injection. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure. CVSSv3.1 8.8 (HIGH)

CWECWE 78VNDNvidiaTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
3w ago
2026-08-25 21:17Z
HIGH

CVE-2026-65084 — NVIDIA: A successful exploit of this vulnerability might lead to information disclosure, data tampering, code

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-65084

NVIDIA NemoClaw for Linux contains a vulnerability in its deployment process, where an attacker could cause improper certificate validation. A successful exploit of this vulnerability might lead to information disclosure, data tampering, code execution, and escalation of privileges. CVSSv3.1 8.1 (HIGH)

CWECWE 295VNDNvidiaTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
3w ago
2026-08-25 21:17Z
CRIT

CVE-2026-65083 — NVIDIA: A successful exploit of this vulnerability might lead to code execution, escalation of privileges

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-65083

NVIDIA OpenShell for Linux contains a vulnerability in its sandbox provisioning API, where an attacker could cause an incomplete list of disallowed inputs. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, information disclosure, data tampering, and denial of service. CVSSv3.1 9.9 (CRITICAL)

CWECWE 184VNDNvidiaTYPVulnerability
9.9
CVSS v3.1
100
Edit Score
3w ago
2026-08-25 21:17Z
HIGH

CVE-2026-65081 — NVIDIA: A successful exploit of this vulnerability might lead to code execution, escalation of privileges

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-65081

NVIDIA NemoClaw for Linux contains a vulnerability in its installation process, where an attacker could cause execution of untrusted code. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, information disclosure, and denial of service. CVSSv3.1 8.1 (HIGH)

CWECWE 494VNDNvidiaTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
3w ago
2026-08-25 21:17Z
HIGH

CVE-2026-52491 — An issue in libtiff 85f2ac8e0b01cb7db2bbecf4a3b891bdbef67938 allows an attacker to execute arbitrary code via the

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-52491

An issue in libtiff 85f2ac8e0b01cb7db2bbecf4a3b891bdbef67938 allows an attacker to execute arbitrary code via the libtiff/tools/thumbnail.c: main() component CVSSv3.1 8.4 (HIGH) · EPSS 7th percentile

CWECWE 190TYPVulnerability
8.4
CVSS v3.1
92
Edit Score
3w ago
2026-08-25 21:17Z
CRIT

CVE-2026-51368 — Beijing: An issue in Beijing Tongtech Co., Ltd tongweb v.7.0.24 in the Spring HttpInovkerServiceExporter component

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-51368

An issue in Beijing Tongtech Co., Ltd tongweb v.7.0.24 in the Spring HttpInovkerServiceExporter component allows a remote attacker to execute arbitrary code via a crafted request to the console/heimdall endpoint CVSSv3.1 9.8 (CRITICAL) · EPSS 17th percentile

CWECWE 502VNDBeijingTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
3w ago
2026-08-25 20:17Z
HIGH

CVE-2026-66152 — Path: A Path traversal vulnerability in OPSWAT tarball in the SonicWall NetExtender Linux client allows

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-66152

A Path traversal vulnerability in OPSWAT tarball in the SonicWall NetExtender Linux client allows an attacker to write arbitrary file as root. CVSSv3.1 8.8 (HIGH)

CWECWE 29TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
3w ago
2026-08-25 20:16Z
CRIT

CVE-2026-45018 — Chainlit: From 2.4.0rc0 until 2.12.0, Chainlit deployments with features.mcp.enabled set to true in .chainlit/config.toml expose

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-45018

Chainlit is a Python framework for building production-ready conversational AI applications. From 2.4.0rc0 until 2.12.0, Chainlit deployments with features.mcp.enabled set to true in .chainlit/config.toml expose the POST /mcp endpoint without requiring authentication. For stdio transport, the endpoint accepts a user-controlled fullCommand string. The validate_mcp_command() function in backend/chainlit/mcp.py checks only the executable name against config.features.mcp.stdio.al CVSSv3.1 9.8 (CRITICAL)

CWECWE 78VNDChainlitTYPVulnerability
9.8
CVSS v3.1
99
Edit Score