Common Vulnerabilities and Exposures (CVE)

CVE-2026-91712

Sep 15, 2026 23:39:58 UTC

Race condition in Extensions in Google Chrome on on Mac prior to 153.0.8010.47 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium s...

CVE-2026-91744

Sep 15, 2026 23:39:24 UTC

Race condition in PlatformIntegration in Google Chrome on on Mac prior to 153.0.8010.47 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to obtain sensitive information via a crafted HTML p...

CVE-2026-91743

Sep 15, 2026 23:38:51 UTC

Race condition in Core in Google Chrome prior to 153.0.8010.47 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity...

CVE-2026-91734

Sep 15, 2026 23:38:07 UTC

Incorrect authorization in Core in Google Chrome on on Windows prior to 153.0.8010.47 allowed a local attacker to execute arbitrary code outside the sandbox via a local program. (Chromium security severity: High)

CVE-2026-91727

Sep 15, 2026 23:37:45 UTC

Incorrect reference resolution in Extensions in Google Chrome on on Mac prior to 153.0.8010.47 allowed a local attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a local program. (Chromium se...

CVE-2026-91728

Sep 15, 2026 23:36:06 UTC

Integer overflow in V8 in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

CVE-2026-92184

Sep 15, 2026 23:30:12 UTC

A security flaw has been discovered in ag-ui-protocol ag-ui 0.3.0. Affected is the function urllib.request.urlopen of the file integrations/aws-strands/python/src/ag_ui_strands/utils.py of the component Multimodal Content. The manipulation ...

CVE-2026-91724

Sep 15, 2026 23:26:22 UTC

Use after free in Input in Google Chrome prior to 153.0.8010.47 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severit...

CVE-2026-15640

Sep 15, 2026 23:22:15 UTC

Under certain conditions a valid SAML IdP response may be used to impersonate another Secret Server user.

CVE-2026-15639

Sep 15, 2026 23:21:38 UTC

An attacker can craft a malicious link that, if used by a legitimate user, may cause the user's browser to run JavaScript supplied by the attacker.

CVE-2026-21588

Sep 15, 2026 23:21:14 UTC

This High severity DoS (Denial of Service) vulnerability was introduced in versions 8.9.0, 9.0.1, 9.1.0, 9.2.0, 9.3.1, 9.4.0, 9.5.1, 10.0.2, 10.1.0, and 10.2.0 of Confluence Data Center. This DoS (Denial of Service) vulnerability, with a...

CVE-2026-15638

Sep 15, 2026 23:20:56 UTC

An unauthenticated user with access to Secret Server could leverage a padding oracle to decrypt or encrypt data using one of the server's cryptographic keys. The key itself is not exposed.

CVE-2026-91749

Sep 15, 2026 23:20:51 UTC

Use after free in Workers in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)

CVE-2026-73460

Sep 15, 2026 23:20:43 UTC

On affected platforms running Arista EOS with IS-IS graceful restart enabled, an unauthenticated attacker who can inject a malformed IS-IS LSP PDU packet can cause the IS-IS graceful restart procedure to terminate prematurely. This may resu...

CVE-2026-91721

Sep 15, 2026 23:19:47 UTC

Use after free in Internals in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)