Use after free in WebGL in Google Chrome prior to 151.0.7922.169 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
CVSSv3.1 8.8 (HIGH)
CWECWE 416TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-18
2026-08-18 21:18Z
HIGH
CVE-2026-76044 — Race: condition in USB in Google Chrome prior to 151.0.7922.169 allowed a remote attacker
Race condition in USB in Google Chrome prior to 151.0.7922.169 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
CVSSv3.1 8.3 (HIGH)
CWECWE 367VNDRaceTYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-08-18
2026-08-18 21:18Z
HIGH
CVE-2026-76043 — Incorrect: calculation in V8 in Google Chrome prior to 151.0.7922.169 allowed a remote attacker
Incorrect calculation in V8 in Google Chrome prior to 151.0.7922.169 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
CVSSv3.1 8.8 (HIGH)
CWECWE 682TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-18
2026-08-18 21:18Z
HIGH
CVE-2026-76040 — Use: after free in Browser in Google Chrome on on Mac prior to 151.0.7922.169
Use after free in Browser in Google Chrome on on Mac prior to 151.0.7922.169 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
CVSSv3.1 8.8 (HIGH)
CWECWE 416TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-18
2026-08-18 21:18Z
HIGH
CVE-2026-76038 — Type: confusion in V8 in Google Chrome prior to 151.0.7922.169 allowed a remote attacker
Type confusion in V8 in Google Chrome prior to 151.0.7922.169 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
CVSSv3.1 8.8 (HIGH)
CWECWE 843VNDTypeTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-18
2026-08-18 21:18Z
HIGH
CVE-2026-76037 — Link: following in CredentialProvider in Google Chrome on on Windows prior to 151.0.7922.169 allowed
Link following in CredentialProvider in Google Chrome on on Windows prior to 151.0.7922.169 allowed a local attacker to potentially execute arbitrary code outside the sandbox via a local program. (Chromium security severity: High)
CVSSv3.1 8.4 (HIGH)
CWECWE 59VNDLinkTYPVulnerability
8.4
CVSS v3.1
92
Edit Score
2026-08-18
2026-08-18 21:18Z
CRIT
CVE-2026-76036 — Buffer: overflow in Dawn in Google Chrome on on Android prior to 151.0.7922.169 allowed
Buffer overflow in Dawn in Google Chrome on on Android prior to 151.0.7922.169 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)
CVSSv3.1 9.6 (CRITICAL)
CWECWE 122VNDBufferTYPVulnerability
9.6
CVSS v3.1
98
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-08-18
2026-08-18 21:18Z
CRIT
CVE-2026-76035 — Inappropriate: implementation in Media in Google Chrome on on Mac prior to 151.0.7922.169 allowed
Inappropriate implementation in Media in Google Chrome on on Mac prior to 151.0.7922.169 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
CVSSv3.1 9.6 (CRITICAL)
CWECWE 20VNDInappropriateTYPVulnerability
9.6
CVSS v3.1
98
Edit Score
2026-08-18
2026-08-18 21:18Z
HIGH
CVE-2026-76034 — Buffer: overflow in WebGL in Google Chrome prior to 151.0.7922.169 allowed a remote attacker
Buffer overflow in WebGL in Google Chrome prior to 151.0.7922.169 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)
CVSSv3.1 8.8 (HIGH)
CWECWE 122VNDBufferTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-18
2026-08-18 21:18Z
HIGH
CVE-2026-73939 — Vulnerability: Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon.
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 3.2.20. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. While the vulnerability is in Helidon, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modificat
CVSSv3.1 8.6 (HIGH)
VNDVulnerabilityTYPVulnerability
8.6
CVSS v3.1
93
Edit Score
2026-08-18
2026-08-18 21:18Z
HIGH
CVE-2026-73937 — Vulnerability: Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP/2 to compromise Helidon.
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 4.5.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP/2 to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Helidon and unauthorized read access to a subset of Helidon access
CVSSv3.1 8.2 (HIGH)
VNDVulnerabilityTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-08-18
2026-08-18 21:18Z
HIGH
CVE-2026-73931 — Vulnerability: Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon.
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 4.5.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. While the vulnerability is in Helidon, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access
CVSSv3.1 8.3 (HIGH)
VNDVulnerabilityTYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-08-18
2026-08-18 21:18Z
CRIT
CVE-2026-73930 — Vulnerability: Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon.
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 4.5.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. While the vulnerability is in Helidon, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modificati
CVSSv3.1 9.9 (CRITICAL)
VNDVulnerabilityTYPVulnerability
9.9
CVSS v3.1
100
Edit Score
2026-08-18
2026-08-18 21:18Z
HIGH
CVE-2026-73929 — Vulnerability: Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon.
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 4.5.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. While the vulnerability is in Helidon, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access
CVSSv3.1 8.3 (HIGH)
VNDVulnerabilityTYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-08-18
2026-08-18 21:18Z
HIGH
CVE-2026-73925 — Vulnerability: Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon.
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 1.4.19. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Helidon accessible data as well as unauthorized read access to a subset o
CVSSv3.1 8.2 (HIGH)
VNDVulnerabilityTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-08-18
2026-08-18 21:18Z
CRIT
CVE-2026-73924 — Vulnerability: Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon.
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 1.4.19. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Helidon accessible data as well as unauthorized access to critical data o
CVSSv3.1 9.1 (CRITICAL)
VNDVulnerabilityTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-08-18
2026-08-18 21:18Z
CRIT
CVE-2026-73922 — Vulnerability: Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon.
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 1.4.19. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Helidon accessible data as well as unauthorized access to critical data o
CVSSv3.1 9.1 (CRITICAL)
VNDVulnerabilityTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-08-18
2026-08-18 21:18Z
CRIT
CVE-2026-73921 — Vulnerability: Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon.
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 1.4.20. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in takeover of Helidon. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:
CVSSv3.1 9.8 (CRITICAL)
VNDVulnerabilityTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-18
2026-08-18 21:18Z
CRIT
CVE-2026-73920 — Vulnerability: Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon.
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 4.5.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Helidon accessible data as well as unauthorized access to critical data or
CVSSv3.1 9.4 (CRITICAL)
VNDVulnerabilityTYPVulnerability
9.4
CVSS v3.1
97
Edit Score
2026-08-18
2026-08-18 21:18Z
CRIT
CVE-2026-73917 — Vulnerability: Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon.
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 4.5.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Helidon accessible data as well as unauthorized access to critical data or
CVSSv3.1 9.1 (CRITICAL)
VNDVulnerabilityTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-08-18
2026-08-18 21:18Z
CRIT
CVE-2026-73916 — Vulnerability: Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon.
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 3.2.18. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Helidon accessible data as well as unauthorized access to critical data o
CVSSv3.1 9.1 (CRITICAL)
VNDVulnerabilityTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-08-18
2026-08-18 21:18Z
CRIT
CVE-2026-73912 — Vulnerability: Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon.
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 4.5.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in takeover of Helidon. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H
CVSSv3.1 9.8 (CRITICAL)
VNDVulnerabilityTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-18
2026-08-18 21:18Z
CRIT
CVE-2026-73905 — Vulnerability: Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon.
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 4.5.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in takeover of Helidon. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H
CVSSv3.1 9.8 (CRITICAL)
VNDVulnerabilityTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-18
2026-08-18 21:18Z
CRIT
CVE-2026-73866 — Vulnerability: Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon.
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 4.5.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Helidon accessible data as well as unauthorized access to critical data or
CVSSv3.1 9.1 (CRITICAL)
VNDVulnerabilityTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-08-18
2026-08-18 21:18Z
CRIT
CVE-2026-73865 — Vulnerability: Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon.
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 3.2.18. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Helidon accessible data as well as unauthorized access to critical data o
CVSSv3.1 9.1 (CRITICAL)