Total
11548 CVE
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-87437 | 1 Google | 1 Chrome | 2026-09-09 | 6.5 Medium |
| Information leak in Frames in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to leak sensitive information via a crafted HTML page. (Chromium security severity: Low) | ||||
| CVE-2026-87574 | 1 Google | 1 Chrome | 2026-09-09 | 4.3 Medium |
| Information leak in ServiceWorker in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (Chromium security severity: Medium) | ||||
| CVE-2026-81022 | 2026-09-09 | 5.3 Medium | ||
| The SupportCandy WordPress plugin before 3.5.3 does not validate a submitted per-ticket authorization code before disclosing the real code to the requester, allowing unauthenticated users to read the contents of any support ticket. | ||||
| CVE-2026-87477 | 1 Google | 1 Chrome | 2026-09-09 | 6.5 Medium |
| Information leak in Core in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to leak sensitive information via a crafted HTML page. (Chromium security severity: Low) | ||||
| CVE-2026-87593 | 1 Google | 1 Chrome | 2026-09-09 | 6.5 Medium |
| Information leak in Editing in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Low) | ||||
| CVE-2026-16960 | 2026-09-09 | 7.5 High | ||
| The Loops & Logic WordPress plugin before 4.3.0 does not restrict its public template-data action to the data a visitor is permitted to see, allowing unauthenticated users to read arbitrary user records (including email addresses and roles) and arbitrary site options. | ||||
| CVE-2026-87035 | 2026-09-09 | 4.3 Medium | ||
| Tanium addressed an information disclosure vulnerability in Comply. | ||||
| CVE-2026-87032 | 2026-09-09 | 4.3 Medium | ||
| Tanium addressed an information disclosure vulnerability in Tanium Server. | ||||
| CVE-2026-87454 | 2 Google, Microsoft | 2 Chrome, Windows | 2026-09-09 | 6.5 Medium |
| Information leak in Enterprise in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium) | ||||
| CVE-2026-87439 | 1 Google | 1 Chrome | 2026-09-09 | 5.3 Medium |
| Information leak in ServiceWorker in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium) | ||||
| CVE-2026-87435 | 1 Google | 1 Chrome | 2026-09-09 | 5.3 Medium |
| Information leak in ControlledFrame in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium) | ||||
| CVE-2026-84222 | 2026-09-09 | 5.3 Medium | ||
| The Kirki WordPress plugin before 6.3.0 does not check whether the requester is allowed to read a post before rendering and returning its page content, allowing unauthenticated users to retrieve the content of pages that are not publicly available, such as private, draft, pending and trashed ones. | ||||
| CVE-2026-81021 | 2026-09-09 | 5.3 Medium | ||
| The SupportCandy WordPress plugin before 3.5.3 does not perform an authorization check on one of its support-ticket attachment download paths, allowing unauthenticated attackers to read protected customer-uploaded attachments by enumerating sequential attachment identifiers. | ||||
| CVE-2026-80340 | 2026-09-09 | 5.3 Medium | ||
| The Payment Plugins for PayPal WooCommerce WordPress plugin before 2.0.26 does not validate the order key before adding order data to the JavaScript configuration it outputs on the front end, allowing unauthenticated users to obtain the secret that gates access to any order and, through it, that customer's billing and shipping details, by iterating sequential order identifiers. | ||||
| CVE-2026-80339 | 2026-09-09 | 5.3 Medium | ||
| The Payment Plugins for Stripe WooCommerce WordPress plugin before 4.0.12 does not validate the order key before adding order data to the JavaScript configuration it outputs on the front end, allowing unauthenticated users to obtain the billing details of any order, together with the secret that gates access to it, by iterating sequential order identifiers. | ||||
| CVE-2026-28623 | 2026-09-09 | N/A | ||
| In writeToParcel of BleRssiRangingCapabilities.java, there is a possible way to obtain the Bluetooth MAC address due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. | ||||
| CVE-2026-28627 | 2026-09-09 | N/A | ||
| In btm_sec_encrypt_change of btm_sec.cc, there is a possible downgrade attack due to a logic error in the code. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. | ||||
| CVE-2026-28630 | 2026-09-09 | N/A | ||
| In onCreate of ContactsPickerActivity.kt, there is a possible misleading UI due to a tapjacking/overlay attack. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. | ||||
| CVE-2026-28638 | 2026-09-09 | N/A | ||
| In multiple functions of XmpDataParser.java, there is a possible improper data sanitization due to a logic error in the code. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. | ||||
| CVE-2026-28652 | 2026-09-09 | N/A | ||
| In multiple functions of RangingServiceImpl.java, there is a possible MITM due to a missing permission check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. | ||||