National notices
National security notices (Türkiye)
The Cybersecurity Directorate (formerly USOM) publishes security notices daily; CVE ids appear inside the text. Here each notice is linked to the records in our database: which is in KEV, which has a mature exploit, what to look at first.
Source: the public notice API of siberguvenlik.gov.tr; the notice text and remediation advice live on the agency's page. Mapping is automatic by CVE id; notices without an id are listed by title only.
8,051 notices · 44,675 linked CVE recordsLatest notice: Oct 2, 2026 RSSList only records cited in national notices
TR-26-1245 · Oct 2, 2026
(Loglama.net - TurkHotspot Güvenlik Bildirimi)
Open the notice on the agency's page- CVE-2026-5782No exploit5.2 · 0%Reflected XSS in Loglama.NET's TurkHotspot
TR-26-1244 · Oct 2, 2026
(GG Soft Yazılım - Paperwork Güvenlik Bildirimi)
Open the notice on the agency's page- CVE-2026-85215No exploit7.1 · 0%SQL Injection in GG Soft's Paperwork
TR-26-1243 · Oct 2, 2026
(Softtr Bilişim - E-Ticaret Paketi Güvenlik Bildirimi)
Open the notice on the agency's page- CVE-2026-11795No exploit5.3 · 0%User Enumeration in Softtr's E-Commerce Pack
TR-26-1242 · Oct 2, 2026
(AVEZ Elektronik - LMS Güvenlik Bildirimi)
Open the notice on the agency's page- CVE-2026-85209No exploit6.5 · 0%IDOR in AVEZ Electronics's LMS
TR-26-1241 · Oct 2, 2026
(HAVELSAN - Sef - AI Chatbot Platform Güvenlik Bildirimi)
Open the notice on the agency's page- CVE-2026-80298No exploit8.8 · 0%SQL Injection in HAVELSAN's Sef - AI Chatbot Platform
- CVE-2026-80337No exploit5.3 · 0%Unauthorized Cross-Chatbot Tool Invocation in HAVELSAN's Sef - AI Chatbot Platform
- CVE-2026-80443No exploit7.4 · 0%Insecure TLS Certificate Validation in API Tool Runner in HAVELSAN's Sef - AI Chatbot Platform
- CVE-2026-80464No exploit4.9 · 0%API Tool Runner SSRF in HAVELSAN's Sef - AI Chatbot Platform
TR-26-1240 · Oct 2, 2026
(Wind River VxWorks 7 Güvenlik Bildirimi)
Open the notice on the agency's page- CVE-2026-104018No exploit8.8 · 1%VxWorks 7 improper privilege management
TR-26-1239 · Oct 2, 2026
(JohnsonControls Çoklu Ürün Güvenlik Bildirimi)
Open the notice on the agency's page- CVE-2026-27873No exploit5.6 · 0%- Use of Hard-coded Credentials vulnerability in Johnson Controls EasyIO FG allows - Pasword Spraying.
- CVE-2026-34493No exploit7.2 · 0%- On-Chip Debug Interface vulnerability in Johnson Controls EasyIO FS32 allows Collect Data from Common Resource Locations.
- CVE-2026-34494No exploit7.2 · 0%- On-Chip Debug Interface vulnerability in Johnson Controls Neo Series MVP2 allows Collect Data from Common Resource Locations.
- CVE-2026-64892No exploit6.3 · 0%- Exposure of Sensitive Information vulnerability in Johnson Controls Easy IO Neo allows Collect Data from Common Resource Locations.
- CVE-2026-64893No exploit7.3 · 0%- Cleartext Transmission of Sensitive Information vulnerability in Johnson Controls EasyIO NEO allows - Man In the Middle Attack.
- CVE-2026-71448No exploit5.6 · 0%: Insecure Default Initialization of Resource vulnerability in Johnson Controls EasyIO FS32 allows : Authentication Abuse.
- CVE-2026-71449No exploit9.3 · 0%: Use of Hard-coded Cryptographic Key vulnerability in Johnson Controls EasyIO FS32 allows : Retrieve Embedded Sensitive Data.
- CVE-2026-10026No exploit7.2 · 0%CTX Feed Pro <= 7.6.12 - Authenticated (Administrator+) Remote Code Execution
- CVE-2026-101888No exploit8.6 · 1%Prime Mover < 2.2.1 Zip Slip Path Traversal File Write
- CVE-2026-101889No exploit7 · 0%Prime Mover < 2.2.1 Path Traversal via wprime-config.json
- CVE-2026-101890No exploit5.1 · 0%Prime Mover < 2.2.1 Stored XSS via Package Metadata
- CVE-2026-14378Proof of concept9.8 · 0%DevKit Pro <= 2.3.0 - Unauthenticated Authentication Bypass to Administrator Account Takeover via 'original_user_id' Cookie in Frontend Revert Switch Flow
- CVE-2026-15896No exploit9.1 · 1%Super Forms <= 6.3.316 - Unauthenticated Path Traversal to Arbitrary File Read via 'sfgtfi' URL Path Parameter
- CVE-2026-15897No exploit8.8 · 0%Super Forms – Drag & Drop Form Builder <= 6.3.316 - Authenticated (Subscriber+) Privilege Escalation via 'user_id' Parameter in Register & Login
- CVE-2026-15989Proof of concept9.8 · 0%Super Forms <= 6.3.316 - Unauthenticated Privilege Escalation via 'role' Parameter
- CVE-2026-19660Proof of concept9.8 · 0%Divi Membership <= 2.3.0 - Unauthenticated Authentication Bypass via 'paypal_param' Parameter
- CVE-2026-19807No exploit8.8 · 0%ByteCoreStack <= 1.2.3 - Authenticated (Subscriber+) Privilege Escalation via wp_update_user_meta MCP Tool
- CVE-2026-19902No exploit6.1 · 0%Ad Inserter <= 2.8.18 - Reflected Cross-Site Scripting via {search-query} Dynamic Tag (Referer Header)
- CVE-2026-62071No exploit9.3 · 0%WordPress WordPress File Upload plugin <= 5.1.10 - SQL Injection vulnerability
- CVE-2026-75957No exploit9.8 · 1%Ultimate Multisite <= 2.15.0 - Unauthenticated Authentication Bypass via 'checkout_form' Parameter
- CVE-2026-78471No exploit5.4 · 0%Autoptimize <= 3.1.15.1 - Unauthenticated Stored Cross-Site Scripting via Comment Author Name
- CVE-2026-84925No exploit6.1 · 0%Avada | Website Builder For WordPress & WooCommerce <= 7.16.1 - Reflected Cross-Site Scripting via 'lang' Parameter
- CVE-2026-89047No exploit6.1 · 0%Social Media Share Buttons & Social Sharing Icons <= 3.0.1 - Reflected DOM-Based Cross-Site Scripting via URL
- CVE-2026-90438No exploit7.2 · 0%Ninja Forms <= 3.15.4 - Unauthenticated Stored Cross-Site Scripting via Paragraph Text (RTE) Field Submission
- CVE-2026-92144No exploit7.2 · 1%Forminator Forms <= 1.57.2 - Unauthenticated Stored Cross-Site Scripting via 'postdata-1[post-custom]' Parameter
- CVE-2026-92174No exploit7.5 · 1%SiteOrigin Widgets Bundle <= 1.73.2 - Authenticated (Contributor+) Local File Inclusion via 'theme' Parameter
- CVE-2026-92820No exploit8.1 · 1%Ninja Forms - File Uploads <= 3.3.34 - Unauthenticated Arbitrary File Upload
- CVE-2026-93367No exploit7.2 · 0%Visitors Traffic Real Time Statistics Pro <= 11.22 - Unauthenticated Stored Cross-Site Scripting via ahcpro_track_visitor (page_title)
- CVE-2026-93882No exploit7.5 · 0%LearnPress <= 4.4.8 - Insecure Direct Object Reference to Unauthenticated Sensitive Information Disclosure via 'item_id' Parameter
- CVE-2026-96256No exploit6.4 · 0%Gutenberg Essential Blocks <= 6.4.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'marker' Attribute
- CVE-2026-63686No exploit7.5 · 0%Apache HTTP Server: mod_xml2enc crash on charset conversion failure
- CVE-2026-63718No exploit7.5 · 0%Apache HTTP Server: mod_proxy_uwsgi Transfer-Encoding response smuggling
- CVE-2026-73636No exploit8.1 · 0%Apache HTTP Server: mod_auth_digest one-time-nonce replay attack
- CVE-2026-73637No exploit7.3 · 0%Apache HTTP Server: mod_auth_digest DoS attack
- CVE-2026-79768No exploit5.3 · 0%Apache HTTP Server: mod_userdir information disclosure
- CVE-2026-93546No exploit8.8 · 0%Apache HTTP Server: mod_dav_fs namespace overflow
- CVE-2026-103884No exploit6.5 · 0%Keycloak-services: keycloak-services: path traversal in x.509 crl distribution point allows arbitrary local file read
TR-26-1235 · Oct 2, 2026
(cPanel WHM Mass Modify Accounts/Multilang adminbin Güvenlik Bildirimi)
Open the notice on the agency's page- CVE-2026-93029No exploit9 · 0%There is a stored XSS vulnerability allowing arbitrary code execution in the WHM Manage SSL Hosts interface.
- CVE-2026-93697No exploit9 · 0%There is a stored XSS vulnerability allowing arbitrary code execution in the WHM Mass Modify Accounts interface.
- CVE-2026-93698No exploit9.9 · 0%Insufficient validation allows arbitrary commands to be executed via the Multilang adminbin.
- CVE-2026-103266No exploit7.1 · 0%Ghost 5.2.0 before 6.62.0 Unauthenticated Stripe Checkout Account Modification
- CVE-2026-103267No exploit5.3 · 0%Ghost 0.5.0 before 6.62.0 Arbitrary Email Registration via Staff Invite
- CVE-2026-103268No exploit8.7 · 0%Ghost 1.0.0 before 6.62.0 Suspension Bypass via Password Reset
- CVE-2026-103269No exploit6.9 · 0%Ghost 5.3.0 before 6.62.0 Missing Authorization via Post Excerpts
- CVE-2026-103271No exploit8.7 · 0%Ghost 4.0.0 before 6.63.0 Restricted Content Bypass
- CVE-2026-103272No exploit8.7 · 0%Ghost 2.10.0 before 6.63.0 Staff Enumeration via Content API
- CVE-2026-103273No exploit5.3 · 0%Ghost 4.3.0 before 6.58.0 Incorrect Authorization via Staff Token
- CVE-2026-103274No exploit6.9 · 0%Ghost 5.3.0 before 6.58.0 Unauthenticated Comment Read
- CVE-2026-103275No exploit5.3 · 0%Ghost 5.42.2 before 6.58.0 Password Hash Disclosure
- CVE-2026-103276No exploit6.9 · 0%Ghost before 6.20.0 File Read via URL Encoding Bypass
- CVE-2026-103277No exploit8.6 · 0%Ghost 2.5.0 before 6.34.0 Untrusted Script Execution via oEmbed
- CVE-2026-103278No exploit8.5 · 0%Ghost 5.8.0 before 6.34.0 Staff Account Takeover via Admin iframe
- CVE-2026-103279No exploit7.6 · 0%Ghost 3.10.0 before 6.34.0 Session Invalidation Bypass
- CVE-2026-103280No exploit6.9 · 0%Ghost 0.8.0 before 6.23.0 Information Disclosure via Setup Endpoint
- CVE-2026-103281No exploit5.3 · 0%Ghost 3.23.0 before 6.23.0 API Key Exposure via Admin API
- CVE-2026-103282No exploit5.3 · 0%Ghost 0.5.0 before 6.23.0 Multiple Account Creation via Invite Token
- CVE-2026-103283No exploit8.6 · 0%Ghost 6.20.0 before 6.57.1 Authentication Bypass via Session Handling
- CVE-2026-103284No exploit5.3 · 0%Ghost 5.125.1 before 6.57.1 Information Disclosure via Feedback
- CVE-2026-103285No exploit5.3 · 0%Ghost 5.19.0 before 6.57.1 Cross-Site Request Forgery
- CVE-2026-103286No exploit8.5 · 0%Ghost 2.21.0 before 6.56.0 Privilege Escalation via Notifications
- CVE-2026-103287No exploit5.1 · 0%Ghost 1.18.0 before 6.27.0 Server-Side Request Forgery via Webhook
- CVE-2026-103288No exploit7.1 · 0%Ghost 5.9.0 before 6.44.1 Authorization Bypass via Comment Like
- CVE-2026-103289No exploit7.1 · 0%Ghost 5.9.0 before 6.44.1 Authorization Bypass via Comments
- CVE-2026-103290No exploit5.1 · 0%Ghost 6.14.0 before 6.27.0 Path Traversal via ImageSize
- CVE-2026-103291No exploit5.3 · 0%Ghost 3.20.2 before 6.51.0 SSRF via image-size fetch
- CVE-2026-103292No exploit8.6 · 0%Ghost 0.5.3 before 6.50.0 Cross-Site Scripting via ghost_head
- CVE-2026-70590No exploit4.8 · 0%Ghost: Blind Password Hash Disclosure in Ghost Admin API
- CVE-2026-103012No exploit2 · 0%Claude Code selected an API key stored by Claude Code, for example from an earlier `/login` or written directly to its configuration, ahead
- CVE-2026-13313No exploit8.9 · 1%An Active Debug Code vulnerability in certain ASUS router models allows a remote authenticated user, via a crafted HTTP request, to bypass s
- CVE-2026-14157No exploit9.4 · 1%Use of an Externally Controlled Format String in the ASUS Router modules allow a remote authenticated user to execute arbitrary commands via
- CVE-2026-93495No exploit7 · 0%Improper initialization in an ASUS certain motherboard allows an physically proximate user to read or write arbitrary memory by inserting a
TR-26-1231 · Oct 1, 2026
(Cato Networks SDP Client Güvenlik Bildirimi)
Open the notice on the agency's page- CVE-2026-10726No exploit6.8 · 0%Cato Windows SDP Client arbitrary file disclosure due to improper TLS certificate validation
- CVE-2026-10739No exploit8.5 · 0%Cato Networks SDP Client for Windows is vulnerable to Local Privilege Escalation
- CVE-2026-103473No exploit9.2 · 1%Deno 2.7.0 through 2.9.7 Command Injection via node:child_process
- CVE-2026-103239No exploit8.6 · 0%MISP Tag Collection Save Allows Privilege Escalation via Sibling Model Injection
- CVE-2026-103321No exploit8.3 · 0%MISP Stored Cross-Site Scripting (XSS) via Unvalidated Event Graph Preview Image
- CVE-2026-103388No exploit6.2 · 0%MISP Stored Cross-Site Scripting via JavaScript URL in Galaxy Cluster Source Field
- CVE-2026-103389No exploit6.2 · 0%MISP Stored Cross-Site Scripting via Unvalidated Galaxy Icon Field in Correlation Graph
- CVE-2026-101879No exploit7.1 · 0%OpenClaw Windows Node before 2026.7.1-3 Missing Authorization
- CVE-2026-101880No exploit8.7 · 1%OpenClaw Windows Node before 2026.7.1 Authorization Bypass
- CVE-2026-101881No exploit7.1 · 0%OpenClaw Windows Node before 2026.7.1 Denial of Service
- CVE-2026-101882No exploit8.7 · 1%OpenClaw Windows Node before 2026.7.1 Remote Code Execution via system.execApprovals.set
- CVE-2026-101883No exploit5.3 · 0%OpenClaw Windows Node through 2026.9.4 SSRF via canvas.present
- CVE-2026-101884No exploit7.7 · 0%OpenClaw Windows Node before 2026.7.1 Remote Code Execution via Environment Override
TR-26-1227 · Oct 1, 2026
(Kiteworks Çoklu Bileşen Güvenlik Zafiyeti)
Open the notice on the agency's page- CVE-2026-102103No exploit9.1 · 0%Kiteworks Email Protection Gateway server-side request forgery
- CVE-2026-102104No exploit9.1 · 0%Kiteworks Email Protection Gateway server-side request forgery
- CVE-2026-102105No exploit9.1 · 0%Kiteworks Email Protection Gateway server-side request forgery
- CVE-2026-102106No exploit9.1 · 0%Kiteworks Email Protection Gateway improper authentication
- CVE-2026-102107No exploit4.6 · 0%Kiteworks Core user impersonation in a file-request feature
- CVE-2026-102108No exploit7.2 · 0%Kiteworks Email Protection Gateway deserialization of untrusted data
- CVE-2026-102109No exploit7.1 · 0%Kiteworks Secure Data Forms SQL injection
- CVE-2026-102111No exploit4.9 · 0%Kiteworks Core Improper Validation of Specified Quantity in Input
- CVE-2026-102112No exploit7.8 · 0%Kiteworks Core Local Privilege Escalation
- CVE-2026-102113No exploit7.8 · 0%Kiteworks Core Local Privilege Escalation
- CVE-2026-102114No exploit7.2 · 1%Kiteworks Core OS Command Injection
- CVE-2026-102115No exploit9.8 · 0%Kiteworks Core Authentication Bypass in the Password Reset Workflow
- CVE-2026-102116No exploit7.2 · 1%Kiteworks Email Protection Gateway Path Traversal
- CVE-2026-102118No exploit7.8 · 0%Kiteworks Core before version 9.5.0 is vulnerable to Local Privilege Escalation
- CVE-2026-102120No exploit8.8 · 0%Kiteworks Core OS Command Injection
- CVE-2026-102122No exploit4.3 · 0%Kiteworks Core Incorrect Authorization
- CVE-2026-102123No exploit7.4 · 0%Kiteworks Core Path Traversal
- CVE-2026-102124No exploit6.5 · 0%Kiteworks Core Missing Authentication for Critical Function
- CVE-2026-102125No exploit8.8 · 0%Kiteworks Core Sandbox Escape
- CVE-2026-102126No exploit8.1 · 0%Kiteworks Core Stored Cross-site Scripting (XSS)
TR-26-1226 · Oct 1, 2026
(JetBrains Çoklu Ürün Güvenlik Bildirimi)
Open the notice on the agency's page- CVE-2026-100253No exploit8.8 · 0%In JetBrains TeamCity before 2026.2, 2026.1.4, 2025.11.8 sandbox escape leading to code execution was possible via the versioned settings
- CVE-2026-100254No exploit8.8 · 0%In JetBrains TeamCity before 2026.2, 2026.1.4, 2025.11.8 authenticated users could execute commands on Windows servers via CRLF injection
- CVE-2026-100255No exploit9.8 · 0%In JetBrains TeamCity before 2026.2, 2026.1.4, 2025.11.8 administrator account takeover was possible via password reset
- CVE-2026-100256No exploit7.8 · 0%In JetBrains IntelliJ IDEA before 2026.2.3 rCE via Structural Search script constraints was possible in untrusted projects
- CVE-2026-100257No exploit4.3 · 0%In JetBrains YouTrack before 2026.2.18991 sSRF via stored XHTML injection was possible during PDF export
- CVE-2026-100258No exploit4.3 · 1%In JetBrains YouTrack before 2026.2.18991 missing authorisation allowed read-only users to read project settings
- CVE-2026-100259No exploit4.3 · 0%In JetBrains YouTrack before 2026.2.18991 improper access control on Gantt chart allowed edits by users with view-only access
- CVE-2026-100260No exploit5.3 · 0%In JetBrains YouTrack before 2026.2.18991 mailbox integration allowed authentication after a password reset
- CVE-2026-100261No exploit5.4 · 0%In JetBrains YouTrack before 2026.2.18991 changing article visibility settings was possible without update permission
- CVE-2026-100262No exploit7.1 · 0%In JetBrains YouTrack before 2026.2.18991 missing authorisation allowed users with read-only project access to overwrite project notificatio
- CVE-2026-100263No exploit6.1 · 0%In JetBrains YouTrack before 2026.2.18991 stored HTML injection via the User-Agent header was possible
- CVE-2026-100264No exploit2.7 · 0%In JetBrains YouTrack before 2026.2.18991 stored SMTP server credentials could be disclosed by changing the server host
- CVE-2026-100265No exploit6.5 · 0%In JetBrains Rider before 2026.2.1 aI Assistant could auto-update third-party skills without user confirmation
- CVE-2026-100266No exploit6.5 · 0%In JetBrains Hub before 2026.2.52366 missing authorisation allowed authenticated users to send arbitrary emails from the server's trusted ad
- CVE-2026-100267No exploit5.9 · 0%In JetBrains YouTrack before 2026.2.19197 reDoS attack was possible via mailbox regex mail-rule filters
- CVE-2026-100268No exploit2.7 · 0%In JetBrains YouTrack before 2026.2.19197 project administrators could read comments from other projects via notification templates
- CVE-2026-100269No exploit4.3 · 0%In JetBrains YouTrack before 2026.2.19197 helpdesk project's Authorized Reporters list could be bypassed
- CVE-2026-100270No exploit2.7 · 0%In JetBrains YouTrack before 2026.2.19197 low-level Admin Read permission users could disclose integration credentials via import configurat
- CVE-2026-100271No exploit2.7 · 0%In JetBrains YouTrack before 2026.2.19197 missing authorisation on several endpoints allowed authenticated users to access information from
- CVE-2026-100272No exploit4.9 · 0%In JetBrains YouTrack before 2026.2.19197 missing authorisation in the notification template preview allowed Project Administrators to read
- CVE-2026-100273No exploit9.8 · 0%In JetBrains YouTrack before 2026.2.19197 authorisation bypass in the scripts debugger allowed arbitrary code execution
- CVE-2026-100274No exploit6.5 · 1%In JetBrains YouTrack before 2026.2.19197 project Admin could trigger DoS via a notification template
- CVE-2026-100275No exploit4.8 · 0%In JetBrains YouTrack before 2026.2.19197 stored XSS in the workflow error notification toast was possible
- CVE-2026-100276No exploit7.5 · 0%In JetBrains YouTrack before 2026.2.19197 guest users could remove a workflow action's visibility restriction and run the action
- CVE-2026-100277No exploit9.8 · 0%In JetBrains YouTrack before 2026.2.19197 account takeover was possible by replaying a notification signature
- CVE-2026-100278No exploit4.9 · 0%In JetBrains YouTrack before 2026.2.19197 users with restricted permission could edit and hide other users' comments
- CVE-2026-100279No exploit6.5 · 0%In JetBrains YouTrack before 2026.2.19197 changing an integration URL exposed its stored credentials
- CVE-2026-100280No exploit4.3 · 0%In JetBrains YouTrack before 2026.2.19197 creating a project from an unreadable custom template was possible
TR-26-1225 · Sep 30, 2026
(Trex Dijital -Trex MES Güvenlik Bildirimi)
Open the notice on the agency's page- CVE-2026-18782Proof of concept9.8 · 0%SQL Injection in Trex Digital Manufacturing's Trex MES
- CVE-2026-18783Proof of concept8.8 · 0%Missing Server-Side Authentication on REST API Endpoint in Trex Digital Manufacturing's Trex MES
TR-26-1224 · Sep 30, 2026
(Dolusoft Yazılım - SOPLOG Güvenlik Bildirimi)
Open the notice on the agency's page- CVE-2026-82307No exploit9.8 · 0%Multiple Vulnerabilities in Dolusoft Software's SOPLOG
TR-26-1223 · Sep 30, 2026
(Maksisoft Teknoloji - Maksisoft Gym Güvenlik Bildirimi)
Open the notice on the agency's page- CVE-2026-86778No exploit5.3 · 0%Username Enumeration in Maksisoft Technology's Maksisoft Gym
TR-26-1222 · Sep 30, 2026
(Hitachi Energy RTU500 Güvenlik Bildirimi)
Open the notice on the agency's page- CVE-2026-8065Proof of concept9.1 · 1%An authentication bypass vulnerability in the firmware update endpoint of Hitachi Energy RTU500 end-of-life versions allows an unauthenticat
- CVE-2026-8066No exploit9.1 · 1%A directory traversal vulnerability in the file upload functionality of Hitachi Energy RTU500 end-of-life versions allows an unauthenticated
- CVE-2026-10518No exploit4.3 · 0%Incorrect Authorization in GitLab
- CVE-2026-4523No exploit3.7 · 0%Missing Authorization in GitLab
- CVE-2026-84739No exploit8.7 · 0%Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab
- CVE-2026-8937No exploit4.3 · 0%Missing Authorization in GitLab
- CVE-2026-100143No exploit6.5 · 0%FluentCart < 1.6.5 - Unauthenticated Guest Customer Account Takeover via Checkout Email
- CVE-2026-75823No exploit7.4 · 0%WP User Frontend 3.5.29 - 4.3.11 - Unauthenticated Privilege Escalation via Registration Role Encryption
- CVE-2026-75824No exploit5.3 · 0%WP User Frontend 2.5.8 - 4.3.11 - Unauthenticated Account Creation with Registration Disabled
- CVE-2026-75873No exploit9.8 · 1%Zella Theme < 2.6.3 - Unauthenticated Arbitrary File Upload
- CVE-2026-80333No exploit5.3 · 0%Solace Extra < 1.7.2 - Unauthenticated Non-Published Post Content Disclosure via Preview Routes
- CVE-2026-82127No exploit3.5 · 0%Schema & Structured Data for WP & AMP < 1.67 - Editor+ Stored XSS via Taxonomy Term Fields
- CVE-2026-83560No exploit5.3 · 0%New User Approve 3.1.0 - 3.2.9 - Unauthenticated PII Disclosure via Zapier API Key Bypass
- CVE-2026-85001No exploit6.8 · 0%EmbedPress 4.4.9 - 4.6.6 - Contributor+ Stored XSS via Elementor Widget showTitle Attribute
- CVE-2026-85415No exploit6.8 · 0%Audio Player Block 1.1.0 - 1.6.2 - Contributor+ Stored XSS via Audio Download URL
- CVE-2026-85573No exploit8.8 · 0%All in One Files Upload for WooCommerce 2.0.3 - 2.0.16 - Unauthenticated Stored XSS via SVG Upload
- CVE-2026-85576No exploit4.3 · 0%All in One Files Upload for WooCommerce < 2.0.17 - Subscriber+ Arbitrary Plugin Settings Update
- CVE-2026-86789No exploit5.3 · 0%Connections Business Directory <= 10.4.67 - Unauthenticated Non-Public Directory Entry Disclosure via cn-api/v1 REST Routes
- CVE-2026-87777No exploit6.8 · 0%Hostinger Reach 1.0.6 - 1.8.2 - Contributor+ Stored XSS via formId Elementor Widget Attribute
- CVE-2026-88791No exploit3.4 · 0%Safe Redirect Manager < 2.3.0 - Open Redirect via Wildcard Redirect Rules
- CVE-2026-88797No exploit7.1 · 0%Vayu X < 1.0.6 - Subscriber+ Arbitrary WordPress.org Plugin Installation and Activation
- CVE-2026-89190No exploit4.3 · 0%Robin Image Optimizer < 2.0.8 - Subscriber+ Plugin Settings Disclosure via fy_ajax
- CVE-2026-89193No exploit7.5 · 0%Robin Image Optimizer 2.0.0 - 2.0.7 - Unauthenticated Stored XSS via WebP URL Delivery HTML Parser
- CVE-2026-89294No exploit7.5 · 1%Simply Schedule Appointments <= 1.6.12.27 - Authenticated (Subscriber+) Local File Inclusion via 'ssa_locale' Parameter
- CVE-2026-90953No exploit4.3 · 0%Image Optimizer by Elementor < 1.7.7 - Subscriber+ Attachment Metadata and Site Statistics Disclosure via Discarded REST Permission Callbacks
- CVE-2026-91051No exploit6.6 · 0%EWWW Image Optimizer 8.6.0 - 8.7.7 - Author+ PHP Object Injection via 'eio_page_settings' Post Meta
- CVE-2026-91072No exploit4.4 · 0%EWWW Image Optimizer < 8.8.0 - Admin+ WebP File Rename and Deletion via Unrestricted Path in WebP Migration Handler
- CVE-2026-91832No exploit7.1 · 0%WP Mobile Menu 2.7.4 - 2.8.8 - Stored XSS via CSRF
- CVE-2026-92424No exploit6.8 · 0%Content Egg < 11.9.0 - Contributor+ Stored XSS via Import Queue
- CVE-2026-92994No exploit8.8 · 0%Verge3D < 4.13.1 - Unauthenticated Stored XSS via File Storage API
- CVE-2026-93580No exploit5.3 · 0%InPost for WooCommerce 1.7.5 - 1.9.7 - Unauthenticated Order Status Forgery via Shipment Webhook
- CVE-2026-94274No exploit5.3 · 0%YayReviews 1.0.4 - 1.4.0 - Unauthenticated Sensitive Data Disclosure via REST API
- CVE-2026-94297No exploit2.7 · 0%Media Library Organizer 2.0.4 - 2.1.3 - Contributor+ Arbitrary Taxonomy Term Creation
- CVE-2026-96649No exploit7.2 · 0%Frontend Post Submission Manager Lite <= 1.3.4 - Unauthenticated Stored DOM-Based Cross-Site Scripting via post_content Parameter (data-label DOM Sink)
- CVE-2026-96886No exploit5.3 · 0%Course Booking System < 7.0.9 - Unauthenticated Attendee PII Disclosure via CSV Export
- CVE-2026-97316No exploit5.8 · 0%Broken Link Notifier 1.3.1 - 2.0.0 - Unauthenticated SSRF via Redirect Bypass
TR-26-1219 · Sep 30, 2026
(Dell Secure Connect Gateway (SCG) Policy Manager Güvenlik Bildirimi)
Open the notice on the agency's page- CVE-2026-73593No exploit3 · 0%Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Active Debug Code vulnerability.
- CVE-2026-73594No exploit6.4 · 0%Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, Versions prior to 5.36, contains an Improper Certificate Val
- CVE-2026-73595No exploit4.7 · 0%Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, Versions prior to 5.36, contains a Download of Code Without
- CVE-2026-73596No exploit3.8 · 0%Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Initialization of a Resource with an Insecure De
- CVE-2026-73597No exploit6.5 · 0%Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains a Cross-Site Request Forgery (CSRF) vulnerability.
- CVE-2026-73598No exploit7.8 · 0%Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Incorrect Permission Assignment for Critical Res
- CVE-2026-73599No exploit5.4 · 0%Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an URL Redirection to Untrusted Site ('Open Redirec
- CVE-2026-76114No exploit5.9 · 0%Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains a Cleartext Transmission of Sensitive Information v
- CVE-2026-35189No exploit5.3 · 0%Excessive Memory Allocation in Relative CRLDP Processing
- CVE-2026-35191No exploit3.7 · 0%QUIC Unvalidated Amplification Credit may be Over Accounted
- CVE-2026-42772No exploit5.3 · 0%Potential CPU DoS via O(n^2) Fragment Reassembly in QUIC
- CVE-2026-54873No exploit7.5 · 0%QUIC STREAM Fragment Metadata DoS
- CVE-2026-54875No exploit3.7 · 0%Non-Constant-Time SM2 Scalar Multiplication on ARM64 and RISC-V
- CVE-2026-72897No exploit7.5 · 0%Out-of-Bounds Access After SSL_set_SSL_CTX() During a Handshake
- CVE-2026-75804No exploit5.3 · 0%QUIC Connection-Level Flow Control is Not Enforced for Streams
- CVE-2026-75805No exploit5.3 · 0%NULL Pointer Dereference in CMP Client Revocation Response Handling
- CVE-2026-84783No exploit7.5 · 0%Use-After-Free in X.509 Extension Cache Under Concurrent Use
- CVE-2026-84784No exploit7.5 · 0%QUIC: Unbounded RETIRE_CONNECTION_ID Backlog
TR-26-1217 · Sep 30, 2026
(Wikimedia Foundation MediaWiki Güvenlik Zafiyeti)
Open the notice on the agency's page- CVE-2026-100240No exploit9.1 · 0%TemplateSandbox does not check read permissions for the page being previewed
- CVE-2026-100241No exploit7.5 · 0%Private change tags exposed to anonymous users via revision-tags-change events
- CVE-2026-103046No exploit6.1 · 0%WikifunctionsFragmentRenderer does unsafe string replacements on user-provided HTML
- CVE-2026-76718No exploit8.2 · 0%HPE OneView - Cross-site scripting vulnerability
- CVE-2026-76719No exploit8.2 · 0%HPE OneView - Cross-site scripting vulnerability
- CVE-2026-76720No exploit4.3 · 0%HPE OneView - URL Redirect vulnerability
- CVE-2026-76721No exploit9.8 · 1%Unauthenticated Buffer Overflow Vulnerability leads to Remote Code Execution in HPE Networking Instant ON APs
- CVE-2026-76722No exploit9.8 · 1%Uncontrolled Format String Vulnerabilities lead to Remote Code Execution or Denial-of-Service in HPE Networking Instant ON APs
- CVE-2026-76723No exploit9.6 · 0%Unauthenticated Adjacent Buffer Overflow Vulnerabilities lead to Remote Code Execution in HPE Networking Instant ON APS
- CVE-2026-76724No exploit9.6 · 1%Unauthenticated Adjacent Command Injection Vulnerability in HPE Networking Instant ON APs Command Line Interface (CLI) Accessed by the PAPI Protocol
- CVE-2026-76725No exploit9.6 · 0%Authentication Bypass in a Management Protocol of HPE Networking Instant ON APs
- CVE-2026-76726No exploit8.1 · 0%Authentication Bypass Leading to Unauthorized Network Access in HPE Networking Instant ON API Endpoint
- CVE-2026-76727No exploit7.2 · 1%Authenticated Command Injection Vulnerabilities in HPE Networking Instant ON
- CVE-2026-76728No exploit7.2 · 1%Authenticated Server-Side Request Forgery Leading to Remote Code Execution in HPE Networking Instant ON APs
- CVE-2026-76729No exploit6.6 · 0%Authenticated Format String Vulnerability allows Memory Corruption in HPE Networking Instant ON API Endpoint
- CVE-2026-76730No exploit6.5 · 0%Improper PAPI Packet handling leads to unauthorized access in HPE Networking Instant ON APs
- CVE-2026-76731No exploit6.5 · 0%Authentication Bypass in the Captive Portal of HPE Networking Instant On
- CVE-2026-76732No exploit6.4 · 0%Authenticated Local Privilege Escalation Vulnerability in a Daemon of HPE Networking Instant ON
- CVE-2026-76733No exploit4.9 · 0%Authenticated Denial-of-Service Vulnerability in HPE Networking Instant On API Endpoint
- CVE-2026-76734No exploit4.8 · 0%Unauthenticated Memory Corruption Vulnerability leads to Denial-of-Service in HPE Networking Instant On
- CVE-2026-76735No exploit4.1 · 0%Authenticated Local Sensitive Information Disclosure in HPE Networking Instant On
- CVE-2026-76736No exploit3.3 · 0%Authenticated Local Buffer Overflow Vulnerability leads to Denial-of-Service in HPE Networking Instant On
- CVE-2026-76737No exploit3 · 0%Authenticated Local Path Traversal Vulnerability Leads to Denial-of-Service in HPE Networking Instant On
- CVE-2026-76738No exploit2.7 · 0%Authenticated Buffer Overflow Vulnerability in the API Endpoint of HPE Networking Instant On Causes Denial-of-Service
- CVE-2026-100756No exploit8.1 · 0%Incorrect boundary conditions in the Audio/Video: Playback component
- CVE-2026-100757No exploit8.8 · 0%Use-after-free in the Widget component
- CVE-2026-100758No exploit9.6 · 0%Sandbox escape in the DOM: Navigation component
- CVE-2026-100759No exploit8.1 · 0%Uninitialized memory in the Storage: Quota Manager component
- CVE-2026-100760No exploit9.6 · 0%Sandbox escape in the Security: Process Sandboxing component
- CVE-2026-100761No exploit8.8 · 0%Privilege escalation due to use-after-free in the Graphics: WebGPU component
- CVE-2026-100762No exploit9.6 · 0%Sandbox escape due to use-after-free in the DOM: Content Processes component
- CVE-2026-100763No exploit9.1 · 0%Incorrect boundary conditions in the Graphics: WebGPU component
- CVE-2026-100764No exploit8.8 · 0%Privilege escalation due to incorrect boundary conditions in the Graphics: WebGPU component
- CVE-2026-100765No exploit8.8 · 0%Use-after-free in the JavaScript: WebAssembly component
- CVE-2026-100766No exploit4.3 · 0%Information disclosure in the Networking: JAR component
- CVE-2026-100767No exploit8.8 · 0%Use-after-free in the Networking: Cache component
- CVE-2026-100768No exploit8.8 · 0%Use-after-free in the Graphics: WebGPU component
- CVE-2026-100769No exploit8.8 · 0%Use-after-free in the JavaScript: WebAssembly component
- CVE-2026-100770No exploit9.6 · 0%Sandbox escape due to use-after-free in the DOM: Content Processes component
- CVE-2026-100771No exploit8.1 · 0%Undefined behavior in the DOM: Streams component
- CVE-2026-100772No exploit8.8 · 0%Use-after-free in the DOM: Core & HTML component
- CVE-2026-100773No exploit8.8 · 0%Use-after-free in the Storage: IndexedDB component
- CVE-2026-100774No exploit8.8 · 0%Use-after-free in the DOM: Core & HTML component
- CVE-2026-100775No exploit9.6 · 0%Sandbox escape in the Graphics component
- CVE-2026-100776No exploit8.8 · 0%Use-after-free in the JavaScript: WebAssembly component
- CVE-2026-100777No exploit8.8 · 0%Use-after-free in the Graphics: Canvas2D component
- CVE-2026-100778No exploit9.6 · 0%Sandbox escape due to use-after-free in the DOM: Core & HTML component
- CVE-2026-100779No exploit8.8 · 0%Use-after-free in the XSLT component
- CVE-2026-100780No exploit8.8 · 0%Use-after-free in the DOM: Core & HTML component
- CVE-2026-100781No exploit9.6 · 0%Sandbox escape due to incorrect boundary conditions in the Graphics: WebRender component
- CVE-2026-100782No exploit8.8 · 0%Privilege escalation due to incorrect boundary conditions in the Graphics component
- CVE-2026-100783No exploit4.3 · 0%Uninitialized memory in the Audio/Video component
- CVE-2026-100784No exploit8.8 · 0%Use-after-free in the Layout: Text and Fonts component
- CVE-2026-100785No exploit8.8 · 0%Use-after-free in the DOM: Core & HTML component
- CVE-2026-100786No exploit9.6 · 0%Sandbox escape due to use-after-free in the Graphics component
- CVE-2026-100787No exploit9.6 · 0%Sandbox escape in the XUL component
- CVE-2026-100788No exploit9.8 · 0%Invalid pointer in the JavaScript: WebAssembly component
- CVE-2026-100789No exploit8.8 · 0%Use-after-free in the Graphics: Canvas2D component
- CVE-2026-100790No exploit8.8 · 0%Use-after-free in the XSLT component
- CVE-2026-100791No exploit8.8 · 0%Use-after-free in the DOM: Core & HTML component
- CVE-2026-100792No exploit7.1 · 0%JIT miscompilation in the JavaScript: WebAssembly component
- CVE-2026-100793No exploit6.5 · 0%JIT miscompilation in the JavaScript Engine component
- CVE-2026-100794No exploit9.6 · 0%Sandbox escape due to incorrect boundary conditions in the Internationalization component
- CVE-2026-100795No exploit6.5 · 0%Denial-of-service in the Networking component
- CVE-2026-100796No exploit8.8 · 0%Use-after-free in the JavaScript: WebAssembly component
- CVE-2026-100797No exploit8.8 · 0%Privilege escalation due to use-after-free in the Graphics: WebRender component
- CVE-2026-100798No exploit8.1 · 0%Cryptography misuse in Storage: Quota Manager component
- CVE-2026-100799No exploit4.3 · 0%Uninitialized memory in the Graphics: WebGPU component
- CVE-2026-100800No exploit9.6 · 0%Sandbox escape due to use-after-free in the Disability Access APIs component
- CVE-2026-100801No exploit8.8 · 0%Privilege escalation in the DLL Services component
- CVE-2026-100802No exploit4.3 · 0%Uninitialized memory in the Graphics: WebGPU component
- CVE-2026-100803No exploit8.1 · 0%Same-origin policy bypass in the WebExtensions component
- CVE-2026-100804No exploit9.6 · 0%Sandbox escape due to use-after-free in the Preferences: Backend component
- CVE-2026-100805No exploit7.5 · 0%Race condition, use-after-free in the Audio/Video component
- CVE-2026-100806No exploit4.3 · 0%Uninitialized memory in the Graphics: WebGPU component
- CVE-2026-100807No exploit8.8 · 0%Privilege escalation in the DOM: Service Workers component
- CVE-2026-100808No exploit8.8 · 0%Mitigation bypass in the DOM: Service Workers component
- CVE-2026-100809No exploit8.1 · 0%Same-origin policy bypass in the DevTools component
- CVE-2026-100810No exploit9.8 · 0%Other issue in the DevTools component
- CVE-2026-100811No exploit9.6 · 0%Sandbox escape due to use-after-free in the DOM: Core & HTML component
- CVE-2026-100812No exploit6.5 · 0%Denial-of-service in the Graphics component
- CVE-2026-100813No exploit8.8 · 0%Invalid pointer in the JavaScript Engine: JIT component
- CVE-2026-100814No exploit8.8 · 0%Incorrect boundary conditions in the JavaScript Engine: JIT component
- CVE-2026-100815No exploit8.8 · 0%Use-after-free in the CSS Parsing and Computation component
- CVE-2026-100816No exploit8.1 · 0%Site isolation issue in the DOM: Networking component
- CVE-2026-100817No exploit5.4 · 0%Other issue in the JavaScript: WebAssembly component
- CVE-2026-100818No exploit9.6 · 0%Sandbox escape due to use-after-free in the Widget: Gtk component
- CVE-2026-100819No exploit9.6 · 0%Sandbox escape due to incorrect boundary conditions in the XPCOM component
- CVE-2026-100820No exploit8.8 · 0%Privilege escalation in the Address Bar component
- CVE-2026-100821No exploit4.7 · 0%Site isolation issue in the Panning and Zooming component
- CVE-2026-100822No exploit5.4 · 0%Spoofing issue in the Networking: HTTP component
- CVE-2026-100823No exploit5.4 · 0%Spoofing issue in the Downloads component in Firefox for Android
- CVE-2026-100824No exploit8.8 · 0%Privilege escalation in the Places component
- CVE-2026-100825No exploit8.8 · 0%Use-after-free in the JavaScript Engine: JIT component
- CVE-2026-100826No exploit6.5 · 0%Denial-of-service in the Storage: StorageManager component
- CVE-2026-100828No exploit9.6 · 0%Mitigation bypass in the Bookmarks & History component
- CVE-2026-100829No exploit9.6 · 0%Mitigation bypass in the DOM: Security component
- CVE-2026-100830No exploit8.1 · 0%Mitigation bypass in the DOM: Navigation component
- CVE-2026-100831No exploit8.8 · 0%Use-after-free in the DOM: UI Events & Focus Handling component
- CVE-2026-100832No exploit8.8 · 0%Use-after-free in the Graphics: Canvas2D component
- CVE-2026-96869No exploit4.3 · 0%Information disclosure in the Networking component
- CVE-2026-19547No exploit7 · 0%Local Privilege Escalation in Ghostscript for Windows
- CVE-2026-103100No exploit7.5 · 0%Pexip Infinity before 40.1 is affected by improper input validation in the signaling implementation that allows a malicious attacker to trig
- CVE-2026-103101No exploit8.6 · 0%Pexip Infinity 30.0 through 40.x before 41.0 is affected by improper input validation in the web server that allows a malicious attacker to
- CVE-2026-103102No exploit8.6 · 0%Pexip Infinity before 41.0 is affected by improper input validation in the signaling implementation which allows a remote attacker to trigge
- CVE-2026-103104No exploit7.5 · 0%Pexip Infinity before 38.2, plus 39.0, 39.1 and 40.0, is affected by improper input validation in the media implementation which allows a re
TR-26-1212 · Sep 30, 2026
(WatchGuard Fireware OS Güvenlik Bildirimi)
Open the notice on the agency's page- CVE-2026-86134No exploit8.7 · 0%Fireware OS Pre-Authentication NULL Pointer Dereference Allows Remote Denial of Service
- CVE-2026-95274No exploit8.3 · 0%Improper output encoding in DevTools in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer proc
- CVE-2026-95275No exploit6.5 · 0%Incorrect reference resolution in MediaStream in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to bypass web origin policy
- CVE-2026-95276No exploit8.3 · 0%Improper input validation in Themes in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer proce
- CVE-2026-95277No exploit9.6 · 0%Use after free in Views in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to potentially execute arbitrary code outside the
- CVE-2026-95278No exploit8.4 · 0%Missing authorization in WakeLock in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process
- CVE-2026-95279No exploit5.4 · 0%UI misrepresentation in Omnibox in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker to spoof address bar via a c
- CVE-2026-95280No exploit7.5 · 0%Race condition in V8 in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code inside the sandbox via a cr
- CVE-2026-95281No exploit9.6 · 1%Buffer overflow in ANGLE in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code outside t
- CVE-2026-95282No exploit8.8 · 0%Use after free in Platform in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code inside the sandbox vi
- CVE-2026-95283No exploit9.6 · 1%Buffer overflow in Tint in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker to potentially execute arbitrary cod
- CVE-2026-95284No exploit9.6 · 1%Buffer overflow in ANGLE in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code outside t
- CVE-2026-95285No exploit8.4 · 0%Missing authorization in WebView in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker who had compromised the ren
- CVE-2026-95286No exploit8.8 · 0%Type confusion in Bindings in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code inside the sandbox vi
- CVE-2026-95287No exploit5.4 · 0%Missing authorization in Navigation in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer proce
- CVE-2026-95288No exploit5.4 · 0%UI misrepresentation in Mobile in Google Chrome on on iOS prior to 154.0.8037.57 allowed a remote attacker to spoof UI elements via a crafte
- CVE-2026-95289No exploit4.3 · 0%Incorrect authorization in Scroll in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to obtain
- CVE-2026-95290No exploit5.4 · 0%Missing authorization in NFC in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to b
- CVE-2026-95291No exploit5.4 · 0%UI misrepresentation in SecurityIndicators in Google Chrome on on iOS prior to 154.0.8037.57 allowed a remote attacker to spoof address bar
- CVE-2026-95292No exploit4.8 · 0%Incorrect authorization in Safebrowsing in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to bypass system access restrictio
- CVE-2026-95293No exploit4.7 · 0%Uninitialized resource in GPU in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to read memory outside the sandbox via a cra
- CVE-2026-95294No exploit5.4 · 0%UI misrepresentation in Browser in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to spoof UI
- CVE-2026-95295No exploit4.6 · 0%Information leak in Mobile in Google Chrome on on iOS prior to 154.0.8037.57 allowed a local attacker to leak sensitive information via phys
- CVE-2026-95296No exploit4.3 · 0%Missing authorization in Core in Google Chrome on on Mac prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to o
- CVE-2026-95297No exploit6.5 · 0%Missing authorization in Contextual Tasks in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to bypass web origin policy via
- CVE-2026-95298No exploit7.8 · 0%Use after free in Browser in Google Chrome prior to 154.0.8037.57 allowed a local attacker to potentially execute arbitrary code outside the
- CVE-2026-95299No exploit9.6 · 0%Use after free in GPU in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code outside the sandbox via a
- CVE-2026-95300No exploit4.8 · 0%Missing authorization in DevTools in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to bypass
- CVE-2026-95301No exploit8.1 · 0%Missing authorization in Extensions in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer proce
- CVE-2026-95302No exploit2.9 · 0%Incorrect authorization in WebAPKs in Google Chrome on on Android prior to 154.0.8037.57 allowed a local attacker to obtain cross-origin dat
- CVE-2026-95303No exploit6.5 · 0%Incomplete cleanup in SmartCard in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to bypass sy
- CVE-2026-95304No exploit8.8 · 0%Out of bounds write in V8 in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code inside the sandbox via
- CVE-2026-95305No exploit4.8 · 0%UI misrepresentation in Chromoting in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to spoof
- CVE-2026-95306No exploit8.8 · 0%Type confusion in V8 in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code inside the sandbox via a cr
- CVE-2026-95307No exploit5.4 · 0%UI misrepresentation in ExtensionsMenu in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to sp
- CVE-2026-95308No exploit3.4 · 0%Integer overflow in Metrics in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to po
- CVE-2026-95309No exploit5.4 · 0%UI misrepresentation in Mobile in Google Chrome on on iOS prior to 154.0.8037.57 allowed a remote attacker to spoof UI elements via a crafte
- CVE-2026-95310No exploit9.6 · 0%Use after free in AdFilter in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code outside the sandbox v
- CVE-2026-95311No exploit9.6 · 0%Free of non-heap memory in Fonts in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to potentia
- CVE-2026-95312No exploit3.1 · 0%Information leak in Passwords in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to
- CVE-2026-95313No exploit9.6 · 0%Use after free in Fullscreen in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to potentially execute arbitrary code outside
- CVE-2026-95314No exploit8.1 · 0%Incorrect authorization in HID in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to
- CVE-2026-95315No exploit7.8 · 0%Use after free in Aura in Google Chrome prior to 154.0.8037.57 allowed a local attacker to potentially execute arbitrary code outside the sa
- CVE-2026-95316No exploit2.9 · 0%Unchecked return value in Performance in Google Chrome prior to 154.0.8037.57 allowed a local attacker to potentially read memory via a loca
- CVE-2026-95317No exploit3.1 · 0%Incorrect authorization in MediaCapture in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to o
- CVE-2026-95318No exploit9.6 · 1%Buffer overflow in Video in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to potentially execute arbitrary code outside the
- CVE-2026-95319No exploit8.3 · 0%Use after free in Printing in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to pot
- CVE-2026-95320No exploit5.4 · 0%Missing authorization in Navigation in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer proce
- CVE-2026-95321No exploit5.4 · 0%UI misrepresentation in Payments in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker to spoof UI elements via a
- CVE-2026-95322No exploit8.3 · 0%Out of bounds write in GPU in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer
- CVE-2026-95323No exploit5.4 · 0%UI misrepresentation in Chromium in Google Chrome on on iOS prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering t
- CVE-2026-95324No exploit3.4 · 0%Uninitialized resource in GPU in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to
- CVE-2026-95325No exploit9.6 · 0%Use after free in ANGLE in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to potentially execute arbitrary code outside the
- CVE-2026-95326No exploit8.4 · 0%Incomplete cleanup in Bluetooth in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to bypass sy
- CVE-2026-95327No exploit6.5 · 0%Information leak in Networking in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to leak sensitive information via a crafted
- CVE-2026-95328No exploit6.5 · 0%Confused deputy in Mobile in Google Chrome on on Android prior to 154.0.8037.57 allowed a local attacker leveraging social engineering to ob
- CVE-2026-95329No exploit9.6 · 0%Out of bounds write in WebGL in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker to potentially execute arbitrar
- CVE-2026-95330No exploit6.5 · 0%Improper state validation in Downloads in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to bypass system access restriction
- CVE-2026-95331No exploit9.6 · 0%Out of bounds write in ANGLE in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to potentially execute arbitrary code outside
- CVE-2026-95332No exploit4.7 · 0%Use of uninitialized variable in Tint in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker to read memory outside
- CVE-2026-95333No exploit8.1 · 0%Use after free in Metrics in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code outside the sandbox vi
- CVE-2026-95334No exploit8.3 · 0%Incorrect reference resolution in WebProtect in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the rende
- CVE-2026-95335No exploit8.3 · 0%Use after free in HID in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to potentia
- CVE-2026-95336No exploit6.5 · 0%Information leak in Transactions Platform in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to
- CVE-2026-95337No exploit5.4 · 0%UI misrepresentation in Messages in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker leveraging social engineeri
- CVE-2026-95338No exploit8.8 · 0%Use after free in PDFium in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code inside the sandbox via
- CVE-2026-95339No exploit9.6 · 0%Use after free in ServiceWorker in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code outside the sand
- CVE-2026-95340No exploit4.3 · 0%Incorrect authorization in PictureInPicture in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering
- CVE-2026-95341No exploit8.3 · 0%Improper input validation in Desktop in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer proc
- CVE-2026-95342No exploit4.3 · 0%Missing authorization in V8 in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to bypass web origin policy via a crafted HTML
- CVE-2026-95343No exploit8.8 · 1%Use after free in WebAudio in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code inside the sandbox vi
- CVE-2026-95344No exploit8 · 0%Race condition in DevTools in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to bypass site is
- CVE-2026-95345No exploit8.8 · 0%Use after free in Actor in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code inside the sandbox via a
- CVE-2026-95346No exploit4.8 · 0%UI misrepresentation in Chromoting in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to spoof UI elements via crafted networ
- CVE-2026-95347No exploit9.6 · 0%Use after free in Updater in Google Chrome on on Mac prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code outside the
- CVE-2026-95348No exploit8.3 · 0%Use after free in Bluetooth in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to po
- CVE-2026-95349No exploit9.6 · 1%Buffer overflow in WebGL in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker to potentially execute arbitrary co
- CVE-2026-95350No exploit9.6 · 1%Buffer overflow in ANGLE in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code outside t
- CVE-2026-95351No exploit8.3 · 0%Use after free in Views in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to execut
- CVE-2026-95352No exploit5.4 · 0%Incorrect authorization in DevTools in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to bypas
- CVE-2026-95353No exploit8.8 · 0%Use after free in Bindings in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code inside the sandbox vi
- CVE-2026-95354No exploit8.3 · 0%Use after free in Verifier in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to pot
- CVE-2026-95355No exploit8.3 · 0%Incorrect authorization in Navigation in Google Chrome on on iOS prior to 154.0.8037.57 allowed a remote attacker who had compromised the re
- CVE-2026-95356No exploit9.6 · 0%Use after free in WindowDialog in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to potentiall
- CVE-2026-95357No exploit9.6 · 0%Out of bounds write in GPU in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker to potentially execute arbitrary
- CVE-2026-95358No exploit4.4 · 0%Incorrect authorization in Mobile in Google Chrome on on Android prior to 154.0.8037.57 allowed a local attacker to bypass system access res
- CVE-2026-95359No exploit3.4 · 0%Uninitialized resource in GPU in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker who had compromised the render
- CVE-2026-95360No exploit5.3 · 0%Race condition in Editing in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to obtain sensitiv
- CVE-2026-95361No exploit4.3 · 0%Confused deputy in DevTools in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to bypass web or
- CVE-2026-95362No exploit8.8 · 0%Cross-site request forgery in DevTools in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to by
- CVE-2026-95363No exploit5.4 · 0%UI misrepresentation in FileSystem in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to spoof
- CVE-2026-95364No exploit5.4 · 0%Improper input validation in Passwords in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to spoof UI elements via a crafted
- CVE-2026-95365No exploit8.8 · 0%Type confusion in IndexedDB in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to potentially execute arbitrary code inside t
- CVE-2026-95366No exploit6.5 · 0%Use of released resource in Core in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process
- CVE-2026-95367No exploit5.3 · 0%Information leak in DataTransfer in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process
- CVE-2026-95368not in the database yet
- CVE-2026-95369not in the database yet
- CVE-2026-95370not in the database yet
- CVE-2026-95371not in the database yet
- CVE-2026-95372not in the database yet
- CVE-2026-95373not in the database yet
- CVE-2026-95374not in the database yet
- CVE-2026-95375not in the database yet
- CVE-2026-95376not in the database yet
- CVE-2026-95380not in the database yet
- CVE-2026-95381not in the database yet
- CVE-2026-95382not in the database yet
- CVE-2026-95384not in the database yet
- CVE-2026-95385not in the database yet
TR-26-1210 · Sep 29, 2026
(Parla Auto - DetaWix Mobile Web Portal Güvenlik Bildirimi)
Open the notice on the agency's page- CVE-2026-86450not in the database yet
TR-26-1209 · Sep 29, 2026
(Interprobe - Qorela DC Güvenlik Bildirimi)
Open the notice on the agency's page- CVE-2026-87748not in the database yet
- CVE-2026-19444not in the database yet
- CVE-2026-93355not in the database yet
- CVE-2026-85185not in the database yet
- CVE-2026-85526not in the database yet
- CVE-2026-86334not in the database yet
- CVE-2026-86335not in the database yet
- CVE-2026-87798not in the database yet
- CVE-2026-87799not in the database yet
- CVE-2026-97335not in the database yet
Add your products on the dashboard to be notified when a matching record enters KEV. →