VULNERABILITY INTELLIGENCE

CVE index

Use CVSS, EPSS, CISA KEV, affected-version data, and source evidence as separate signals for prioritization.

NVD data is used under its public data terms. This service is not endorsed or certified by NVD.
17,661 CVE recordsPage 38 of 1178 · EPSS data 2026.08.06
ReviewHigh
CVE-2026-18188

ASUSTOR Inc. ADM, data master

A format string vulnerability was found in the Rsync Backup on the ADM. The vulnerability occurs because user-controlled rsync backup configuration or log data may be processed through an unsafe format string operation. An authenticated attacker can exploit this issue to disclose memory information or cause denial of service of the affected backup component. Affected products and versions include: from ADM 4.1.0 through ADM 4.3.3.RUN1 as well as from ADM 5.0.0 through ADM 5.1.3.RI81.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-18187

ASUSTOR Inc. ADM, data master

A format string vulnerability was found in the Internal Backup on the ADM. The vulnerability occurs because user-controlled task input may be included in an error response and processed through an unsafe format string operation. An authenticated attacker can exploit this issue to disclose memory information or cause denial of service of the affected CGI process. Affected products and versions include: from ADM 4.1.0 through ADM 4.3.3.RUN1 as well as from ADM 5.0.0 through ADM 5.1.3.RI81.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-18186

ASUSTOR Inc. ADM, data master

A stored format string vulnerability was found in the FTP Backup on the ADM. The vulnerability occurs because user-controlled backup configuration data may be written into a task log and later processed through an unsafe format string operation. An authenticated attacker can exploit this issue to disclose memory information or cause denial of service of the affected CGI process. Affected products and versions include: from ADM 4.1.0 through ADM 4.3.3.RUN1 as well as from ADM 5.0.0 through ADM 5.1.3.RI81.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-16727

ASUS Armoury Crate

Concurrent Execution using Shared Resource with Improper Synchronization (“Race Condition”) in ASUS Armoury Crate allows a local user to execute arbitrary code with elevated privileges via a crafted file replacement. Refer to the ' Security Update for ASUS Armoury Crate ' section on the ASUS Security Advisory for more information.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-15929

LG Electronics SmartShare

Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in LG Electronics SmartShare allows SQL Injection. This issue affects SmartShare: through 2.3.1712.1202, which is supported on Microsoft Windows 10 and earlier versions.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-18017

Google Chrome, chrome

Use after free in Dawn in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Low)

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2026-18015

Google Chrome, chrome, macos

Inappropriate implementation in Tint in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low)

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-18012

Google Chrome, chrome

Use after free in PDFium in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted PDF file. (Chromium security severity: Low)

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2026-18002

Google Chrome, chrome

Insufficient validation of untrusted input in Google Lens in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low)

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-17995

Google Chrome, chrome

Out of bounds read in Dawn in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: Low)

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-17993

Google Chrome, chrome

Race in Updater in Google Chrome on Windows prior to 151.0.7922.72 allowed a local attacker to perform privilege escalation via a malicious file. (Chromium security severity: Low)

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2026-17991

Google Chrome, chrome

Insufficient validation of untrusted input in AI in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low)

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2026-17990

Google Chrome, chrome

Insufficient validation of untrusted input in WebAuthn in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted PDF file. (Chromium security severity: Low)

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-17989

Google Chrome, chrome

Type Confusion in V8 in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Low)

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2026-17987

Google Chrome, chrome

Insufficient validation of untrusted input in Notifications in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted PDF file. (Chromium security severity: Low)

The CVSS severity warrants an early asset and exposure review.