The NVD is the U.S. government repository of standards based vulnerability management data represented using the Security Content Automation Protocol (SCAP). This data enables automation of vulnerability management, security measurement, and compliance. The NVD includes databases of security checklist references, security-related software flaws, product names, and impact metrics.
For information on how to cite the NVD, including the database's Digital Object Identifier (DOI), please consult NIST's Public Data Repository.
Legal Disclaimer:
Here is where you can read the NVD legal disclaimer.
-
CVE-2026-76034 - Buffer overflow in WebGL in Google Chrome prior to 151.0.7922.169 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)
Published: August 18, 2026; 5:18:27 PM -0400 -
CVE-2026-76036 - Buffer overflow in Dawn in Google Chrome on on Android prior to 151.0.7922.169 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)
Published: August 18, 2026; 5:18:27 PM -0400 -
CVE-2026-76037 - Link following in CredentialProvider in Google Chrome on on Windows prior to 151.0.7922.169 allowed a local attacker to potentially execute arbitrary code outside the sandbox via a local program. (Chromium security severity: High)
Published: August 18, 2026; 5:18:27 PM -0400 -
CVE-2026-76038 - Type confusion in V8 in Google Chrome prior to 151.0.7922.169 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
Published: August 18, 2026; 5:18:27 PM -0400 -
CVE-2026-76047 - Type confusion in V8 in Google Chrome prior to 151.0.7922.169 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
Published: August 18, 2026; 5:18:28 PM -0400 -
CVE-2026-76033 - Inappropriate implementation in CORS in Google Chrome prior to 151.0.7922.169 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: High)
Published: August 18, 2026; 5:18:27 PM -0400 -
CVE-2026-47865 - VMware Avi Load Balancer contains an authentication bypass vulnerability. A malicious user with network access may be able to access the Avi Control plane by bypassing the authentication mechanism. Affected versions: 31.1.1 through 31.2.2 (fixed ... read CVE-2026-47865
Published: July 18, 2026; 5:17:08 AM -0400 -
CVE-2026-47866 - VMware Avi Load Balancer contains an authorization bypass vulnerability. A malicious actor on the network can access a limited subset of the Avi Control Plane without proper authorization. Affected versions: 32.1.1 (fixed in 32.1.2) 31.1.1 throug... read CVE-2026-47866
Published: July 18, 2026; 5:17:08 AM -0400 -
CVE-2026-47867 - VMware Avi Load Balancer contains a remote code execution vulnerability. A malicious user with network access may be able to access the Avi Control plane and execute code remotely. Affected versions: 32.1.1 (fixed in 32.1.2) 31.1.1 through 31.2.2... read CVE-2026-47867
Published: July 18, 2026; 5:17:08 AM -0400V3.1: 8.8 HIGH
-
CVE-2026-47868 - VMware Avi Load Balancer contains a local privilege escalation vulnerability. A malicious user with local access may be able to escalate their privileges to run code as root. Affected versions: 32.1.1 (fixed in 32.1.2) 31.1.1 through 31.2.2 (fixe... read CVE-2026-47868
Published: July 18, 2026; 5:17:08 AM -0400 -
CVE-2026-47869 - VMware Avi Load Balancer contains a remote code execution vulnerability. A malicious authenticated user with network access may be able to inject and execute code. Affected versions: 32.1.1 (fixed in 32.1.2) 31.1.1 through 31.2.2 (fixed in 31.2.2... read CVE-2026-47869
Published: July 18, 2026; 5:17:08 AM -0400V3.1: 8.8 HIGH
-
CVE-2026-47870 - VMware Avi Load Balancer contains a privilege escalation vulnerability. A malicious authenticated user with network access may be able to execute remote code. Affected versions: 32.1.1 (fixed in 32.1.2) 31.1.1 through 31.2.2 (fixed in 31.2.2-2p3)... read CVE-2026-47870
Published: July 18, 2026; 5:17:08 AM -0400V3.1: 8.8 HIGH
-
CVE-2026-47871 - VMware Avi Load Balancer contains a directory traversal vulnerability. Flaws in file path validation allow malicious, authenticated network users to perform directory traversal attacks. Affected versions: 32.1.1 (fixed in 32.1.2) 31.1.1 through 3... read CVE-2026-47871
Published: July 18, 2026; 5:17:08 AM -0400 -
CVE-2026-74241 - A flaw was found in Red Hat Quay's external Lightweight Directory Access Protocol (LDAP) authentication handling. When an LDAP referral is returned during authentication, the system does not properly escape the username input. This allows an attac... read CVE-2026-74241
Published: August 14, 2026; 7:16:34 PM -0400V3.1: 6.5 MEDIUM
-
CVE-2026-72529 - A remote unauthorized attacker with network access via port 4307/TCP to the TrueConf server versions 5.3.X to 5.3.9, 5.4.X to 5.4.9, 5.5.X to 5.5.5, and earlier could execute an arbitrary script by calling an undocumented function.
Published: August 19, 2026; 1:21:00 PM -0400 -
CVE-2026-72530 - A remote unauthorized attacker with network access via port 4307/TCP to the TrueConf server versions 5.3.X to 5.3.9, 5.4.X to 5.4.9, 5.5.X to 5.5.5, and earlier could use a specially crafted script to break out of the isolated environment and exec... read CVE-2026-72530
Published: August 19, 2026; 1:21:01 PM -0400 -
CVE-2026-74242 - A flaw was found in Red Hat Quay. An administrator of any repository, by knowing or guessing a target notification's Universally Unique Identifier (UUID), can read the notification configuration, including sensitive details like webhook URLs, Slac... read CVE-2026-74242
Published: August 14, 2026; 7:16:34 PM -0400V3.1: 4.4 MEDIUM
-
CVE-2025-66824 - A Stored Cross-Site Scripting (XSS) vulnerability exists in the Meeting location field of the Create/Edit Conference functionality in TrueConf Server v5.5.2.10813. The injected payload is stored via the meeting_room parameter and executed when use... read CVE-2025-66824
Published: December 30, 2025; 2:15:44 PM -0500V3.1: 8.7 HIGH
-
CVE-2025-66834 - A CSV Formula Injection vulnerability in TrueConf Server v5.5.2.10813 allows a normal user to inject malicious spreadsheet formulas into exported chat logs via crafted Display Name.
Published: December 30, 2025; 2:15:44 PM -0500 -
CVE-2025-66823 - An HTML Injection vulnerability in TrueConf server 5.5.2.10813 in the conference description field allows an attacker to inject arbitrary HTML in the Create/Edit conference functionality. The payload will be triggered when the victim opens the Con... read CVE-2025-66823
Published: December 30, 2025; 3:16:01 PM -0500V3.1: 5.4 MEDIUM