Common Vulnerabilities and Exposures (CVE)

CVE-2026-107161

Oct 9, 2026 22:07:16 UTC

A heap-based buffer overflow flaw was found in Cyrus SASL. The add_to_challenge() function in the DIGEST-MD5 plugin computes the size of the buffer needed for a challenge/response field before DIGEST-MD5 quoting is applied, but does not rec...

CVE-2026-22061

Oct 9, 2026 22:02:54 UTC

Trident versions v25.02.1 through v26.06.1 are susceptible to a vulnerability that could allow an authenticated attacker with access to debug logs to view LUKS passphrases or SMB Active Directory credentials.

CVE-2026-106286

Oct 9, 2026 21:48:37 UTC

Confused deputy in Omnibox in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to bypass web origin policy via crafted network traffic. (Chromium security severity: Medium)

CVE-2026-106365

Oct 9, 2026 21:48:31 UTC

Missing authorization in Animation in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)

CVE-2026-106267

Oct 9, 2026 21:48:23 UTC

Missing authorization in Network in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium)

CVE-2026-106381

Oct 9, 2026 21:48:16 UTC

Incorrect authorization in Passwords in Google Chrome on on iOS prior to 155.0.8059.39 allowed a remote attacker to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)

CVE-2026-106266

Oct 9, 2026 21:48:08 UTC

Confused deputy in Contextual Tasks in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to bypass web origin policy into a privileged page via a crafted HTML page. (Chromium security se...

CVE-2026-106287

Oct 9, 2026 21:47:58 UTC

Information loss in CORS in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to bypass web origin policy via crafted network traffic. (Chromium security severity: Low)

CVE-2026-106297

Oct 9, 2026 21:47:51 UTC

Incorrect authorization in Scheduling in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to bypass web origin policy via a crafted HTML page. (Chromium security severity: Low)

CVE-2026-106362

Oct 9, 2026 21:47:43 UTC

Missing authorization in DevTools in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to bypass web origin policy via a crafted Chrome extension. (Chromium security severity: Low)

CVE-2026-106237

Oct 9, 2026 21:47:35 UTC

Information leak in Permissions in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to bypass site isolation via a crafted HTML page. (Chromium security severity: Low)

CVE-2026-106331

Oct 9, 2026 21:47:28 UTC

Improper input validation in Extensions in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to bypass web origin policy into a privileged page via a crafted Chrome extension. (Chromium security se...

CVE-2026-106418

Oct 9, 2026 21:47:20 UTC

Missing authorization in Network in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to bypass web origin policy via crafted network traffic. (Chromium security severity: Low)

CVE-2026-106195

Oct 9, 2026 21:47:11 UTC

Incorrect authorization in Chromoting in Google Chrome on on Mac prior to 155.0.8059.39 allowed a remote attacker to bypass system access restrictions via crafted network traffic. (Chromium security severity: Low)

CVE-2026-106385

Oct 9, 2026 21:47:01 UTC

Race condition in Chromoting in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to potentially bypass system access restrictions via crafted network traffic. (Chromium security severity: Low)