U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.


The NVD is the U.S. government repository of standards based vulnerability management data represented using the Security Content Automation Protocol (SCAP). This data enables automation of vulnerability management, security measurement, and compliance. The NVD includes databases of security checklist references, security-related software flaws, product names, and impact metrics.

For information on how to cite the NVD, including the database's Digital Object Identifier (DOI), please consult NIST's Public Data Repository.

Last 20 Scored Vulnerability IDs & Summaries CVSS Severity
  • CVE-2026-76039 - Incorrect reference resolution in Core in Google Chrome on on Android prior to 151.0.7922.169 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: High)
    Published: August 18, 2026; 5:18:27 PM -0400

  • CVE-2026-76040 - Use after free in Browser in Google Chrome on on Mac prior to 151.0.7922.169 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
    Published: August 18, 2026; 5:18:28 PM -0400

  • CVE-2026-76041 - Information leak in Skia in Google Chrome prior to 151.0.7922.169 allowed a remote attacker to potentially bypass web origin policy via a crafted HTML page. (Chromium security severity: High)
    Published: August 18, 2026; 5:18:28 PM -0400

  • CVE-2026-76042 - Use of uninitialized resource in GPU in Google Chrome prior to 151.0.7922.169 allowed a remote attacker who had compromised the renderer process to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: High)
    Published: August 18, 2026; 5:18:28 PM -0400

  • CVE-2026-76043 - Incorrect calculation in V8 in Google Chrome prior to 151.0.7922.169 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
    Published: August 18, 2026; 5:18:28 PM -0400

  • CVE-2026-76044 - Race condition in USB in Google Chrome prior to 151.0.7922.169 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
    Published: August 18, 2026; 5:18:28 PM -0400

  • CVE-2026-76045 - Use after free in WebGL in Google Chrome prior to 151.0.7922.169 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
    Published: August 18, 2026; 5:18:28 PM -0400

  • CVE-2026-76046 - Buffer overflow in ANGLE in Google Chrome on on Android prior to 151.0.7922.169 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: ... read CVE-2026-76046
    Published: August 18, 2026; 5:18:28 PM -0400

  • CVE-2026-71110 - Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 4.5.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS t... read CVE-2026-71110
    Published: August 18, 2026; 5:18:11 PM -0400

  • CVE-2026-73892 - Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 4.5.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP t... read CVE-2026-73892
    Published: August 18, 2026; 5:18:21 PM -0400

  • CVE-2026-73893 - Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 4.5.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP t... read CVE-2026-73893
    Published: August 18, 2026; 5:18:21 PM -0400

  • CVE-2026-73894 - Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 4.5.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP t... read CVE-2026-73894
    Published: August 18, 2026; 5:18:21 PM -0400

  • CVE-2026-73895 - Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 3.2.18. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP ... read CVE-2026-73895
    Published: August 18, 2026; 5:18:22 PM -0400

  • CVE-2026-73897 - Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 4.5.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP t... read CVE-2026-73897
    Published: August 18, 2026; 5:18:22 PM -0400

  • CVE-2026-73898 - Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 4.5.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP t... read CVE-2026-73898
    Published: August 18, 2026; 5:18:22 PM -0400

  • CVE-2026-73899 - Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 3.2.19. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP ... read CVE-2026-73899
    Published: August 18, 2026; 5:18:22 PM -0400

  • CVE-2026-73900 - Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 4.5.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP t... read CVE-2026-73900
    Published: August 18, 2026; 5:18:22 PM -0400

  • CVE-2026-73901 - Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 4.5.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP... read CVE-2026-73901
    Published: August 18, 2026; 5:18:22 PM -0400

  • CVE-2026-73939 - Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 3.2.20. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP ... read CVE-2026-73939
    Published: August 18, 2026; 5:18:27 PM -0400

  • CVE-2026-19579 - Snipe-IT before 8.6.0 contains an authorization bypass (insecure direct object reference) in the asset checkout-request cancellation endpoint. The cancel_by_admin and requestingUser values are read from user-controlled URL path segments and used w... read CVE-2026-19579
    Published: August 11, 2026; 5:17:35 PM -0400

Created September 20, 2022 , Updated August 27, 2024