2026-08-18
2026-08-18 21:18Z
HIGH

CVE-2026-76045 — Use: after free in WebGL in Google Chrome prior to 151.0.7922.169 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-76045

Use after free in WebGL in Google Chrome prior to 151.0.7922.169 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.8 (HIGH)

CWECWE 416TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-18
2026-08-18 21:18Z
HIGH

CVE-2026-76044 — Race: condition in USB in Google Chrome prior to 151.0.7922.169 allowed a remote attacker

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-76044

Race condition in USB in Google Chrome prior to 151.0.7922.169 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.3 (HIGH)

CWECWE 367VNDRaceTYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-08-18
2026-08-18 21:18Z
HIGH

CVE-2026-76043 — Incorrect: calculation in V8 in Google Chrome prior to 151.0.7922.169 allowed a remote attacker

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-76043

Incorrect calculation in V8 in Google Chrome prior to 151.0.7922.169 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.8 (HIGH)

CWECWE 682TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-18
2026-08-18 21:18Z
HIGH

CVE-2026-76040 — Use: after free in Browser in Google Chrome on on Mac prior to 151.0.7922.169

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-76040

Use after free in Browser in Google Chrome on on Mac prior to 151.0.7922.169 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.8 (HIGH)

CWECWE 416TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-18
2026-08-18 21:18Z
HIGH

CVE-2026-76038 — Type: confusion in V8 in Google Chrome prior to 151.0.7922.169 allowed a remote attacker

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-76038

Type confusion in V8 in Google Chrome prior to 151.0.7922.169 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.8 (HIGH)

CWECWE 843VNDTypeTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-18
2026-08-18 21:18Z
HIGH

CVE-2026-76037 — Link: following in CredentialProvider in Google Chrome on on Windows prior to 151.0.7922.169 allowed

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-76037

Link following in CredentialProvider in Google Chrome on on Windows prior to 151.0.7922.169 allowed a local attacker to potentially execute arbitrary code outside the sandbox via a local program. (Chromium security severity: High) CVSSv3.1 8.4 (HIGH)

CWECWE 59VNDLinkTYPVulnerability
8.4
CVSS v3.1
92
Edit Score
2026-08-18
2026-08-18 21:18Z
CRIT

CVE-2026-76036 — Buffer: overflow in Dawn in Google Chrome on on Android prior to 151.0.7922.169 allowed

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-76036

Buffer overflow in Dawn in Google Chrome on on Android prior to 151.0.7922.169 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical) CVSSv3.1 9.6 (CRITICAL)

CWECWE 122VNDBufferTYPVulnerability
9.6
CVSS v3.1
98
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-08-18
2026-08-18 21:18Z
CRIT

CVE-2026-76035 — Inappropriate: implementation in Media in Google Chrome on on Mac prior to 151.0.7922.169 allowed

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-76035

Inappropriate implementation in Media in Google Chrome on on Mac prior to 151.0.7922.169 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 9.6 (CRITICAL)

CWECWE 20VNDInappropriateTYPVulnerability
9.6
CVSS v3.1
98
Edit Score
2026-08-18
2026-08-18 21:18Z
HIGH

CVE-2026-76034 — Buffer: overflow in WebGL in Google Chrome prior to 151.0.7922.169 allowed a remote attacker

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-76034

Buffer overflow in WebGL in Google Chrome prior to 151.0.7922.169 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical) CVSSv3.1 8.8 (HIGH)

CWECWE 122VNDBufferTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-18
2026-08-18 21:18Z
HIGH

CVE-2026-73939 — Vulnerability: Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-73939

Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 3.2.20. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. While the vulnerability is in Helidon, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modificat CVSSv3.1 8.6 (HIGH)

VNDVulnerabilityTYPVulnerability
8.6
CVSS v3.1
93
Edit Score
2026-08-18
2026-08-18 21:18Z
HIGH

CVE-2026-73937 — Vulnerability: Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP/2 to compromise Helidon.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-73937

Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 4.5.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP/2 to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Helidon and unauthorized read access to a subset of Helidon access CVSSv3.1 8.2 (HIGH)

VNDVulnerabilityTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-08-18
2026-08-18 21:18Z
HIGH

CVE-2026-73931 — Vulnerability: Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-73931

Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 4.5.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. While the vulnerability is in Helidon, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access CVSSv3.1 8.3 (HIGH)

VNDVulnerabilityTYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-08-18
2026-08-18 21:18Z
CRIT

CVE-2026-73930 — Vulnerability: Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-73930

Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 4.5.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. While the vulnerability is in Helidon, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modificati CVSSv3.1 9.9 (CRITICAL)

VNDVulnerabilityTYPVulnerability
9.9
CVSS v3.1
100
Edit Score
2026-08-18
2026-08-18 21:18Z
HIGH

CVE-2026-73929 — Vulnerability: Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-73929

Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 4.5.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. While the vulnerability is in Helidon, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access CVSSv3.1 8.3 (HIGH)

VNDVulnerabilityTYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-08-18
2026-08-18 21:18Z
HIGH

CVE-2026-73925 — Vulnerability: Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-73925

Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 1.4.19. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Helidon accessible data as well as unauthorized read access to a subset o CVSSv3.1 8.2 (HIGH)

VNDVulnerabilityTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-08-18
2026-08-18 21:18Z
CRIT

CVE-2026-73924 — Vulnerability: Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-73924

Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 1.4.19. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Helidon accessible data as well as unauthorized access to critical data o CVSSv3.1 9.1 (CRITICAL)

VNDVulnerabilityTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-08-18
2026-08-18 21:18Z
CRIT

CVE-2026-73922 — Vulnerability: Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-73922

Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 1.4.19. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Helidon accessible data as well as unauthorized access to critical data o CVSSv3.1 9.1 (CRITICAL)

VNDVulnerabilityTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-08-18
2026-08-18 21:18Z
CRIT

CVE-2026-73921 — Vulnerability: Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-73921

Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 1.4.20. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in takeover of Helidon. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I: CVSSv3.1 9.8 (CRITICAL)

VNDVulnerabilityTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-18
2026-08-18 21:18Z
CRIT

CVE-2026-73920 — Vulnerability: Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-73920

Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 4.5.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Helidon accessible data as well as unauthorized access to critical data or CVSSv3.1 9.4 (CRITICAL)

VNDVulnerabilityTYPVulnerability
9.4
CVSS v3.1
97
Edit Score
2026-08-18
2026-08-18 21:18Z
CRIT

CVE-2026-73917 — Vulnerability: Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-73917

Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 4.5.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Helidon accessible data as well as unauthorized access to critical data or CVSSv3.1 9.1 (CRITICAL)

VNDVulnerabilityTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-08-18
2026-08-18 21:18Z
CRIT

CVE-2026-73916 — Vulnerability: Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-73916

Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 3.2.18. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Helidon accessible data as well as unauthorized access to critical data o CVSSv3.1 9.1 (CRITICAL)

VNDVulnerabilityTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-08-18
2026-08-18 21:18Z
CRIT

CVE-2026-73912 — Vulnerability: Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-73912

Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 4.5.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in takeover of Helidon. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H CVSSv3.1 9.8 (CRITICAL)

VNDVulnerabilityTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-18
2026-08-18 21:18Z
CRIT

CVE-2026-73905 — Vulnerability: Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-73905

Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 4.5.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in takeover of Helidon. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H CVSSv3.1 9.8 (CRITICAL)

VNDVulnerabilityTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-18
2026-08-18 21:18Z
CRIT

CVE-2026-73866 — Vulnerability: Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-73866

Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 4.5.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Helidon accessible data as well as unauthorized access to critical data or CVSSv3.1 9.1 (CRITICAL)

VNDVulnerabilityTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-08-18
2026-08-18 21:18Z
CRIT

CVE-2026-73865 — Vulnerability: Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-73865

Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 3.2.18. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Helidon accessible data as well as unauthorized access to critical data o CVSSv3.1 9.1 (CRITICAL)

VNDVulnerabilityTYPVulnerability
9.1
CVSS v3.1
96
Edit Score