Powered by data from 22+ sources — NVD, cve.org, EPSS, CISA KEV, OSV, GHSA, MITRE ATT&CK, and more.

About & licensesSource status
cvekit
CockpitCVEsATT&CKActorsSources
----‑--‑-- · --:--:-- UTCLIVE
394,623 matching
CVEs · 394,623page 1 / 7893
CVE-2026-87935HIGH8.1Received

The Paid Downloads plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 3.15 via the admin_request_handler function. This is due to missing authorization and file type validation in the admin_request_handler function, which is reachable unauthenticated via is_admin() returning true for /wp-admin/admin-post.php. This makes it possible for unauthenticated attackers to upload files that may be executable, which makes remote code execution possible. On Apache servers where AllowOverride is enabled, an .htaccess file placed in the upload directory may block direct HTTP retrieval of uploaded files, limiting exploitability to stacks that do not honor .htaccess directives such as nginx, LiteSpeed, and Apache with AllowOverride None.

CVE-2026-87796CRITICAL9.8Received

The Multi Uploader for Gravity Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.1.9 via the move_file function. This is due to insufficient file type validation during chunked upload handling. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.

CVE-2026-50604NONEReceived

A vulnerability has been identified in the Acer Agent Service component included with NitroSense and PredatorSense. The socket handshake process does not properly require authentication before granting access to the service. Under certain circumstances, an unauthorized connection may be established, potentially allowing access to functionality that should be restricted.

CVE-2026-25294HIGH7.4Received

Transient DOS while parsing frame during channel usage.

CVE-2026-25290HIGH7.8Received

Memory Corruption when validating large data buffers from external sources using addition to check buffer length.

CVE-2026-25284HIGH7.3Received

Information Disclosure when a pointer is reused after being deallocated.

CVE-2026-25283HIGH8.8Received

Memory Corruption when copying unverified data from an external source exceeds the allocated buffer size.

CVE-2026-25282HIGH7.9Received

Transient DOS when processing unverified data from a neighboring system causes out of bound memory access.

CVE-2026-25281HIGH7.4Received

Transient DOS when processing large or numerous request buffers without sufficient memory allocation validation.

CVE-2026-25280HIGH7.8Received

Memory corruption when processing escape handling flow with insufficient user buffer sizes.

CVE-2026-25278HIGH7.8Received

Memory Corruption when processing I2C transfer requests due to a race condition between memory allocation and data copying.

CVE-2026-25275HIGH7.5Received

Transient DOS when processing authentication frames with invalid FILS information element header lengths.

CVE-2026-25261MEDIUM6.7Received

Memory corruption while processing rear sensor IOCTL calls.

CVE-2026-24081HIGH7.4Received

Transient DOS when processing a channel map with insufficient used channels and adaptive frequency hopping is fully enabled.

CVE-2026-24075HIGH7.8Received

Memory Corruption when multiple threads issue concurrent IOCTL requests to the device control handler due to improper synchronization and race conditions.

CVE-2026-24074HIGH7.8Received

Memory Corruption when processing data with large offset and length values exceeds buffer limits during data copy operations.

CVE-2026-24073HIGH7.8Received

Memory corruption when processing decode statistics due to insufficient validation of offset against structure size.

CVE-2025-59607HIGH7.8Received

Memory Corruption when copying large input data exceeds normal allocation limits.

CVE-2026-92839MEDIUM4.3Received

Canva Desktop before v1.125.0 performed double decoding in the deeplink handler. A threat actor could cause the application to load arbitrary same-origin content under the user’s session.

CVE-2026-91843CRITICAL9.8Received

A stack overflow during the unauthenticated login process may allow an attacker to run arbitrary code remotely with root privileges.

CVE-2026-91749CRITICAL9.6EPSS 27%Awaiting

Use after free in Workers in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)

CVE-2026-91748HIGH8.3EPSS 12%Analyzing

Race condition in Extensions in Google Chrome on on Mac prior to 153.0.8010.47 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to potentially execute arbitrary code outside the sandbox via UI Interaction. (Chromium security severity: High)

CVE-2026-91745HIGH8.8EPSS 16%Analyzing

Use after free in V8 in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

CVE-2026-91743HIGH8.3EPSS 15%Analyzing

Race condition in Core in Google Chrome prior to 153.0.8010.47 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

CVE-2026-91741HIGH8.8EPSS 33%Analyzing

Type confusion in CacheStorage in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

CVE-2026-91738CRITICAL9.6EPSS 16%Analyzing

Improper input validation in ANGLE in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

CVE-2026-91737HIGH8.8EPSS 16%Awaiting

Use after free in PDF in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

CVE-2026-91736HIGH8.8EPSS 23%Awaiting

Use after free in DOM in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

CVE-2026-91735HIGH8.3EPSS 22%Awaiting

Incorrect authorization in WebUI in Google Chrome prior to 153.0.8010.47 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

CVE-2026-91734HIGH7.4EPSS 1%Awaiting

Incorrect authorization in Core in Google Chrome on on Windows prior to 153.0.8010.47 allowed a local attacker to execute arbitrary code outside the sandbox via a local program. (Chromium security severity: High)

CVE-2026-91731HIGH8.8EPSS 33%Analyzing

Type confusion in Compositing in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

CVE-2026-91729CRITICAL9.6EPSS 16%Analyzing

Use after free in DigitalCredentials in Google Chrome prior to 153.0.8010.47 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

CVE-2026-91728CRITICAL9.6EPSS 30%Analyzing

Integer overflow in V8 in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

CVE-2026-91727HIGH8.1EPSS 1%Analyzing

Incorrect reference resolution in Extensions in Google Chrome on on Mac prior to 153.0.8010.47 allowed a local attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a local program. (Chromium security severity: High)

CVE-2026-91726MEDIUM4.7EPSS 15%Analyzing

Out of bounds read in WebGL in Google Chrome on on Android prior to 153.0.8010.47 allowed a remote attacker to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)

CVE-2026-91724HIGH8.3EPSS 24%Analyzing

Use after free in Input in Google Chrome prior to 153.0.8010.47 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

CVE-2026-91722HIGH8.8EPSS 15%Analyzing

Use after free in Input in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

CVE-2026-91721HIGH8.8EPSS 27%Analyzing

Use after free in Internals in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)

CVE-2026-91718CRITICAL9.6EPSS 15%Analyzing

Use after free in Core in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

CVE-2026-91716CRITICAL9.6EPSS 15%Analyzing

Use after free in Auth in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

CVE-2026-91715HIGH8.8EPSS 17%Analyzing

Type confusion in ServiceWorker in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

CVE-2026-91712HIGH8.3EPSS 17%Analyzing

Race condition in Extensions in Google Chrome on on Mac prior to 153.0.8010.47 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

CVE-2026-91711HIGH8.8EPSS 15%Analyzing

Out of bounds write in ServiceWorker in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

CVE-2026-91710CRITICAL9.6EPSS 15%Analyzing

Use after free in WebAppInstalls in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

CVE-2026-91709HIGH8.8EPSS 30%Analyzing

Type confusion in ServiceWorker in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

CVE-2026-91106NONEAwaiting

HP has identified and remediated multiple externally reported vulnerabilities within HPLIP. The findings affect several software components that could potentially enable remote code execution, privilege escalation, denial of service, information disclosure, or unauthorized file modification under certain conditions.

CVE-2026-91105NONEAwaiting

HP has identified and remediated multiple externally reported vulnerabilities within HPLIP. The findings affect several software components that could potentially enable remote code execution, privilege escalation, denial of service, information disclosure, or unauthorized file modification under certain conditions.

CVE-2026-91104NONEAwaiting

HP has identified and remediated multiple externally reported vulnerabilities within HPLIP. The findings affect several software components that could potentially enable remote code execution, privilege escalation, denial of service, information disclosure, or unauthorized file modification under certain conditions.

CVE-2026-91098NONEAwaiting

HP has identified and remediated multiple externally reported vulnerabilities within HPLIP. The findings affect several software components that could potentially enable remote code execution, privilege escalation, denial of service, information disclosure, or unauthorized file modification under certain conditions.

CVE-2026-86359HIGH8.5Awaiting

Dell Repository Manager, versions prior to 3.5.2, contains an Incorrect Default Permissions vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges.

394,623 CVEs
1 / 7893

CVE-2026-73453

CRITICAL10.0Received
CNA: AristaPublished: 2026-09-16Modified: about 20 hours ago
Open full
Description

An unauthenticated P4Runtime (Programming Protocol-Independent Packet Processors Runtime) client can achieve arbitrary code execution under certain conditions on affected platforms running Arista EOS configured with P4Runtime. P4Runtime is disabled by default in Arista EOS. By crafting a malicious packet during the initiation of a P4Runtime session, an attacker can obtain complete administrative control over the compromised switch. This issue was discovered internally by Arista, and the company is not aware of any malicious exploitation of this vulnerability in customer networks.

CVSS v3.1
10.0
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
AVNACLPRNUINSCCHIHAH
CVSS across sources4
VersionTypeSourceBaseExpImp
3.1Primarycve.org10.0——
3.1SecondaryNVD10.03.96.0
4.0Primarycve.org9.5——
4.0SecondaryNVD9.5——
Modification timeline
  • NVDabout 19 hours ago1 obs
  • cve.orgabout 20 hours ago1 obs
Vendor statements1
  • arista.com
Timeline
  1. 2026-09-16
    CVE published
  2. 2026-09-16
    Last metadata update
  3. 2026-09-16
    First observed by cve_org
  4. 2026-09-16
    First observed by nvd