3w ago
2026-08-25 22:17Z
CRIT

CVE-2026-65637 — Input: Improper Input Validation vulnerability in Apache Tomcat due to incomplete fix for CVE-2026-32990.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-65637

Improper Input Validation vulnerability in Apache Tomcat due to incomplete fix for CVE-2026-32990. This issue affects Apache Tomcat: from 11.0.20 through 11.0.24, from 10.1.53 through 10.1.57, from 9.0.115 through 9.0.120. Users are recommended to upgrade to version 11.0.25, 10.1.58 or 9.0.121, which fix the issue. CVSSv3.1 9.8 (CRITICAL)

CWECWE 20VNDInputTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
3w ago
2026-08-25 22:17Z
HIGH

CVE-2026-65183 — Time: Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Apache Tomcat when creating unix domain sockets

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-65183

Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Apache Tomcat when creating unix domain sockets allows an unauthorised local user to access the unix domain socket. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, from 10.1.0-M1 through 10.1.57, from 9.0.42 through 9.0.120. Users are recommended to upgrade to version 11.0.25, 10.1.58, 9.0.121, which fixes the issue. CVSSv3.1 8.1 (HIGH)

CWECWE 367TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
3w ago
2026-08-25 22:17Z
CRIT

CVE-2026-65182 — Access: Improper Access Control, Incorrect Authorization vulnerability in Apache Tomcat leads to security constraint bypass

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-65182

Improper Access Control, Incorrect Authorization vulnerability in Apache Tomcat leads to security constraint bypass if a constraint for a longer path is specified before a more restrictive constraint for a shorter sub-path. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, from 10.1.0-M1 through 10.1.57, from 9.0.0.M1 through 9.0.120, from 8.5.0 through 8.5.100, from 7.0.0 through 7.0.109. Users are recommended to upgrade to version 11.0.25, 10.1.58, 9.0 CVSSv3.1 9.1 (CRITICAL)

CWECWE 284CWECWE 863VNDAccessTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
3w ago
2026-08-25 21:18Z
CRIT

CVE-2026-80104 — GPT: DB-GPT builds the destination path for an uploaded skill from the multipart filename without

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-80104

DB-GPT builds the destination path for an uploaded skill from the multipart filename without constraining it to the upload directory. skill_upload in packages/dbgpt-app/src/dbgpt_app/openapi/api_v1/agentic_data_api.py takes file.filename as given and writes the request body to upload_dir / filename. A path composed with that operator discards the left operand when the right one is absolute and follows parent references otherwise, so a filename such as ../../../tmp/x or /tmp/x CVSSv3.1 9.8 (CRITICAL)

CWECWE 22VNDGptTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
3w ago
2026-08-25 21:18Z
HIGH

CVE-2026-79292 — Integer: overflow in Chromecast in Google Chrome prior to 152.0.7977.65 allowed a remote attacker

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-79292

Integer overflow in Chromecast in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.3 (HIGH)

CWECWE 190TYPVulnerability
8.3
CVSS v3.1
92
Edit Score
3w ago
2026-08-25 21:18Z
CRIT

CVE-2026-79290 — Use: after free in Aura in Google Chrome prior to 152.0.7977.65 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-79290

Use after free in Aura in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical) CVSSv3.1 9.6 (CRITICAL)

CWECWE 416TYPVulnerability
9.6
CVSS v3.1
98
Edit Score
3w ago
2026-08-25 21:18Z
CRIT

CVE-2026-79282 — Use: after free in ANGLE in Google Chrome on on Android prior to 152.0.7977.65

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-79282

Use after free in ANGLE in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical) CVSSv3.1 9.6 (CRITICAL)

CWECWE 416TYPVulnerability
9.6
CVSS v3.1
98
Edit Score
728 × 90 / responsive · programmatic ad slot
3w ago
2026-08-25 21:18Z
CRIT

CVE-2026-79275 — Use: after free in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-79275

Use after free in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 9.6 (CRITICAL)

CWECWE 416TYPVulnerability
9.6
CVSS v3.1
98
Edit Score
3w ago
2026-08-25 21:18Z
HIGH

CVE-2026-79266 — Use: after free in DevTools in Google Chrome prior to 152.0.7977.65 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-79266

Use after free in DevTools in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to execute arbitrary code inside the sandbox via a crafted Chrome extension. (Chromium security severity: Medium) CVSSv3.1 8.8 (HIGH)

CWECWE 416TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
3w ago
2026-08-25 21:18Z
HIGH

CVE-2026-79263 — Race: condition in Extensions in Google Chrome prior to 152.0.7977.65 allowed a remote attacker

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-79263

Race condition in Extensions in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code inside the sandbox via crafted network traffic. (Chromium security severity: Low) CVSSv3.1 8.1 (HIGH)

CWECWE 367VNDRaceTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
3w ago
2026-08-25 21:18Z
CRIT

CVE-2026-79257 — Use: after free in Views in Google Chrome prior to 152.0.7977.65 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-79257

Use after free in Views in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 9.6 (CRITICAL)

CWECWE 416TYPVulnerability
9.6
CVSS v3.1
98
Edit Score
3w ago
2026-08-25 21:18Z
HIGH

CVE-2026-79256 — Externally: controlled reference in WebView in Google Chrome on on Android prior to 152.0.7977.65

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-79256

Externally controlled reference in WebView in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium) CVSSv3.1 8.3 (HIGH)

CWECWE 610VNDExternallyTYPVulnerability
8.3
CVSS v3.1
92
Edit Score
3w ago
2026-08-25 21:18Z
HIGH

CVE-2026-79247 — Use: after free in Chromoting in Google Chrome on on Windows prior to 152.0.7977.65

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-79247

Use after free in Chromoting in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via crafted network traffic. (Chromium security severity: High) CVSSv3.1 8.3 (HIGH)

CWECWE 416TYPVulnerability
8.3
CVSS v3.1
92
Edit Score
3w ago
2026-08-25 21:18Z
HIGH

CVE-2026-79244 — Use: after free in Animation in Google Chrome prior to 152.0.7977.65 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-79244

Use after free in Animation in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Low) CVSSv3.1 8.8 (HIGH)

CWECWE 416TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
3w ago
2026-08-25 21:18Z
HIGH

CVE-2026-79240 — Out: of bounds write in ANGLE in Google Chrome on on Windows prior to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-79240

Out of bounds write in ANGLE in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.8 (HIGH)

CWECWE 787TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
3w ago
2026-08-25 21:18Z
HIGH

CVE-2026-79236 — Type: confusion in V8 in Google Chrome prior to 152.0.7977.65 allowed a remote attacker

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-79236

Type confusion in V8 in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.8 (HIGH)

CWECWE 843VNDTypeTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
3w ago
2026-08-25 21:18Z
CRIT

CVE-2026-79235 — Use: after free in WebGL in Google Chrome prior to 152.0.7977.65 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-79235

Use after free in WebGL in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 9.6 (CRITICAL)

CWECWE 416TYPVulnerability
9.6
CVSS v3.1
98
Edit Score
3w ago
2026-08-25 21:18Z
CRIT

CVE-2026-79232 — Use: after free in Aura in Google Chrome prior to 152.0.7977.65 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-79232

Use after free in Aura in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 9.6 (CRITICAL)

CWECWE 416TYPVulnerability
9.6
CVSS v3.1
98
Edit Score
3w ago
2026-08-25 21:18Z
HIGH

CVE-2026-79231 — Buffer: overflow in Media in Google Chrome prior to 152.0.7977.65 allowed a remote attacker

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-79231

Buffer overflow in Media in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium) CVSSv3.1 8.8 (HIGH)

CWECWE 122VNDBufferTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
3w ago
2026-08-25 21:18Z
HIGH

CVE-2026-79230 — ANGLE: Improper input validation in ANGLE in Google Chrome on on Mac prior to 152.0.7977.65

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-79230

Improper input validation in ANGLE in Google Chrome on on Mac prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium) CVSSv3.1 8.8 (HIGH)

CWECWE 20VNDAngleTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
3w ago
2026-08-25 21:18Z
HIGH

CVE-2026-79227 — Type: confusion in DevTools in Google Chrome prior to 152.0.7977.65 allowed a remote attacker

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-79227

Type confusion in DevTools in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium) CVSSv3.1 8.8 (HIGH)

CWECWE 843VNDTypeTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
3w ago
2026-08-25 21:18Z
HIGH

CVE-2026-79226 — Regional: Improper privilege management in Regional Capabilities in Google Chrome prior to 152.0.7977.65 allowed a

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-79226

Improper privilege management in Regional Capabilities in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted Chrome extension. (Chromium security severity: Medium) CVSSv3.1 8.8 (HIGH) · EPSS 11th percentile

CWECWE 269VNDRegionalTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
3w ago
2026-08-25 21:18Z
HIGH

CVE-2026-79224 — Use: after free in Chromecast in Google Chrome prior to 152.0.7977.65 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-79224

Use after free in Chromecast in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical) CVSSv3.1 8.3 (HIGH)

CWECWE 416TYPVulnerability
8.3
CVSS v3.1
92
Edit Score
3w ago
2026-08-25 21:18Z
HIGH

CVE-2026-79223 — Integer: overflow in Chromium in Google Chrome prior to 152.0.7977.65 allowed a remote attacker

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-79223

Integer overflow in Chromium in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to read memory inside the sandbox via a crafted file. (Chromium security severity: Low) CVSSv3.1 8.8 (HIGH)

CWECWE 190TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
3w ago
2026-08-25 21:18Z
HIGH

CVE-2026-79219 — Use: after free in Bluetooth in Google Chrome prior to 152.0.7977.65 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-79219

Use after free in Bluetooth in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox via a crafted Chrome extension. (Chromium security severity: High) CVSSv3.1 8.8 (HIGH)

CWECWE 416TYPVulnerability
8.8
CVSS v3.1
94
Edit Score