{"success":true,"data":{"threats":[{"id":"94817980-315f-4276-a68a-d77c22c90be6","slug":"cve-2026-14508","externalId":"CVE-2026-14508","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-14508 — IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, and 11.0.0.0 through 11.0.0.2 could allow a re…","description":"IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, and 11.0.0.0 through 11.0.0.2 could allow a remote attacker to cause a denial of service and obtain sensitive information due to a use-after-free.","cveId":"CVE-2026-14508","cvssScore":6.5,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:H","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-416"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://www.ibm.com/support/pages/node/7289775","type":"advisory","title":"psirt@us.ibm.com"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T15:17:49.413Z","addedAt":"2026-10-08T16:39:35.916Z","updatedAt":"2026-10-08T21:05:50.437Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-14508","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-14508","note":"authoritative record"}]},{"id":"77a17fde-7ae3-44dd-96a3-beb3f487ea03","slug":"cve-2026-105824","externalId":"CVE-2026-105824","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-105824 — ImageMagick before 6.9.13-55 and 7.x before 7.1.2-30 contains a use-after-free vulnerability in the RSVG decoder when built without cairo support, …","description":"ImageMagick before 6.9.13-55 and 7.x before 7.1.2-30 contains a use-after-free vulnerability in the RSVG decoder when built without cairo support, triggered when a limit is hit during decoding. Attackers can supply crafted SVG files that cause a limit to be reached, leading to access of freed memory and a crash.","cveId":"CVE-2026-105824","cvssScore":8.2,"cvssVector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-416"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-f2r2-qw7g-3c8x","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/imagemagick-before-7.1.2-30-use-after-free-in-rsvg-decoder-without-cairo","type":"advisory","title":"disclosure@vulncheck.com"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T15:17:34.323Z","addedAt":"2026-10-08T16:39:35.657Z","updatedAt":"2026-10-08T21:05:49.914Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-105824","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-105824","note":"authoritative record"}]},{"id":"18f7b965-d55f-47dc-be49-2a32767bdd78","slug":"cve-2026-107209","externalId":"CVE-2026-107209","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-107209 — ImageMagick is free and open-source software used for editing and manipulating digital images.","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-30 and 6.9.13-55, when ImageMagick is built without Cairo support, a crafted RSVG image that reaches a resource limit can cause the RSVG decoder to free image state twice and then use freed memory, crashing the process. This issue is fixed in versions 7.1.2-30 and 6.9.13-55.","cveId":"CVE-2026-107209","cvssScore":5.9,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-415","CWE-416"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/ImageMagick/ImageMagick/commit/326451aae51ac2dabc99fe66e063de6ec14cf8c8","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/ImageMagick/ImageMagick/releases/tag/7.1.2-30","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-f2r2-qw7g-3c8x","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/ImageMagick/ImageMagick6/commit/04a4c5b89c034cf2c93bb0a10044332d941b4fa5","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/ImageMagick/ImageMagick6/releases/tag/6.9.13-55","type":"advisory","title":"security-advisories@github.com"}],"epssScore":0.00315,"epssPercentile":0.22457,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-07T16:17:45.940Z","addedAt":"2026-10-07T16:39:32.713Z","updatedAt":"2026-10-08T21:05:42.327Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107209","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-107209","note":"authoritative record"}]},{"id":"4290d498-8db3-48d2-8dd8-26b6f7cf007f","slug":"cve-2026-107167","externalId":"CVE-2026-107167","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-107167 — A flaw was found in m17n-lib.","description":"A flaw was found in m17n-lib. A user providing specially crafted text input can trigger a heap use-after-free condition during input-method state transitions. Under specific conditions, the library frees an internal input context object but subsequently attempts to write to that freed memory. This issue can cause applications relying on the library to crash, leading to a Denial of Service (DoS), or potentially allow arbitrary code execution.","cveId":"CVE-2026-107167","cvssScore":6.2,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-416"],"tags":["nvd","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://access.redhat.com/security/cve/CVE-2026-107167","type":"advisory","title":"secalert@redhat.com"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2547408","type":"advisory","title":"secalert@redhat.com"}],"epssScore":0.00121,"epssPercentile":0.01715,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-07T15:17:18.710Z","addedAt":"2026-10-07T16:39:32.483Z","updatedAt":"2026-10-07T18:39:31.056Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107167","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-107167","note":"authoritative record"}]},{"id":"c914760b-6cb0-406e-82e2-52f4ec2c3e0a","slug":"cve-2026-107183","externalId":"CVE-2026-107183","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-107183 — llama.cpp before b11393 contains a use-after-free and double free vulnerability in common_chat_peg_mapper::map that allows unauthenticated remote a…","description":"llama.cpp before b11393 contains a use-after-free and double free vulnerability in common_chat_peg_mapper::map that allows unauthenticated remote attackers to corrupt heap memory via a dangling current_tool pointer. Attackers can submit a chat_parser in a POST /completion request emitting a tool-id after a tool-close tag to crash llama-server and shape a heap write primitive.","cveId":"CVE-2026-107183","cvssScore":9.2,"cvssVector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"critical","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-416"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/ggml-org/llama.cpp","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://github.com/ggml-org/llama.cpp/blob/bed0a856606ee4a24a164066f73d2379447033f5/common/chat-peg-parser.cpp#L343-L355","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://github.com/ggml-org/llama.cpp/blob/bed0a856606ee4a24a164066f73d2379447033f5/tools/server/server-schema.cpp#L321-L324","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://github.com/ggml-org/llama.cpp/commit/dbe4c3ed42343f0a7ba0fd7e808ffeaca404d29f","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://github.com/ggml-org/llama.cpp/pull/29942","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/llama-cpp-before-b11393-use-after-free-via-common-chat-peg-mapper-chat-parser","type":"advisory","title":"disclosure@vulncheck.com"}],"epssScore":0.00422,"epssPercentile":0.34503,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-07T14:17:09.003Z","addedAt":"2026-10-07T14:39:35.205Z","updatedAt":"2026-10-07T16:39:32.230Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107183","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-107183","note":"authoritative record"}]},{"id":"9c629c69-b889-44db-8410-de1c2e14cd88","slug":"cve-2026-55330","externalId":"CVE-2026-55330","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-55330 — In BluetoothCccHandlerCallbackImpl of bluetooth_ccc.cc, there is a possible use-after-free due to a logic error in the code.","description":"In BluetoothCccHandlerCallbackImpl of bluetooth_ccc.cc, there is a possible use-after-free due to a logic error in the code. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.","cveId":"CVE-2026-55330","cvssScore":9.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","severity":"critical","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-416"],"tags":["nvd","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://source.android.com/docs/security/bulletin/pixel/2026/2026-10-01","type":"advisory","title":"dsap-vuln-management@google.com"}],"epssScore":0.00299,"epssPercentile":0.2067,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-06T19:18:14.810Z","addedAt":"2026-10-06T20:39:32.487Z","updatedAt":"2026-10-07T04:39:33.904Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-55330","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-55330","note":"authoritative record"}]},{"id":"71ab1143-6d2d-46b0-9e61-c7d2db615e64","slug":"cve-2026-106423","externalId":"CVE-2026-106423","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-106423 — Use after free in Media in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafte…","description":"Use after free in Media in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)","cveId":"CVE-2026-106423","cvssScore":8.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","severity":"high","vendor":"google","product":"chrome","affectedVersions":["< 155.0.8059.39"],"cwes":["CWE-416"],"tags":["nvd","status:awaiting-analysis","status:analyzed"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","type":"vendor","title":"Release Notes"},{"url":"https://issues.chromium.org/issues/566347711","type":"advisory","title":"Permissions Required"}],"epssScore":0.00303,"epssPercentile":0.21131,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-06T19:18:12.130Z","addedAt":"2026-10-06T20:39:32.379Z","updatedAt":"2026-10-07T14:39:33.718Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-106423","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-106423","note":"authoritative record"}]},{"id":"57539e5f-5bb2-4f7f-b1ad-2d17372bfbab","slug":"cve-2026-106421","externalId":"CVE-2026-106421","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-106421 — Use after free in PDF in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted …","description":"Use after free in PDF in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)","cveId":"CVE-2026-106421","cvssScore":8.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","severity":"high","vendor":"google","product":"chrome","affectedVersions":["< 155.0.8059.39"],"cwes":["CWE-416"],"tags":["nvd","status:awaiting-analysis","status:analyzed"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","type":"vendor","title":"Release Notes"},{"url":"https://issues.chromium.org/issues/567873463","type":"advisory","title":"Permissions Required"}],"epssScore":0.00303,"epssPercentile":0.21132,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-06T19:18:11.893Z","addedAt":"2026-10-06T20:39:32.364Z","updatedAt":"2026-10-07T14:39:33.707Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-106421","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-106421","note":"authoritative record"}]},{"id":"33c7239c-e86b-4fe7-be20-5734a418888b","slug":"cve-2026-106419","externalId":"CVE-2026-106419","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-106419 — Use after free in ANGLE in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code outside the sandb…","description":"Use after free in ANGLE in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)","cveId":"CVE-2026-106419","cvssScore":9.6,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","severity":"critical","vendor":"google","product":"chrome","affectedVersions":["< 155.0.8059.39"],"cwes":["CWE-416"],"tags":["nvd","status:awaiting-analysis","status:analyzed"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","type":"vendor","title":"Release Notes"},{"url":"https://issues.chromium.org/issues/550379413","type":"advisory","title":"Permissions Required"}],"epssScore":0.00338,"epssPercentile":0.25188,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-06T19:18:11.670Z","addedAt":"2026-10-06T20:39:32.348Z","updatedAt":"2026-10-07T14:39:33.687Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-106419","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-106419","note":"authoritative record"}]},{"id":"74162cbd-4948-49de-8ceb-76cddbdcf40f","slug":"cve-2026-106411","externalId":"CVE-2026-106411","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-106411 — Use after free in Parser in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a craft…","description":"Use after free in Parser in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)","cveId":"CVE-2026-106411","cvssScore":8.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","severity":"high","vendor":"google","product":"chrome","affectedVersions":["< 155.0.8059.39"],"cwes":["CWE-416"],"tags":["nvd","status:awaiting-analysis","status:analyzed"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","type":"vendor","title":"Release Notes"},{"url":"https://issues.chromium.org/issues/566136674","type":"advisory","title":"Permissions Required"}],"epssScore":0.00303,"epssPercentile":0.21096,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-06T19:18:10.750Z","addedAt":"2026-10-06T20:39:32.288Z","updatedAt":"2026-10-07T14:39:33.614Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-106411","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-106411","note":"authoritative record"}]},{"id":"d8789bde-f75c-4fd4-9366-6f9bee54aabf","slug":"cve-2026-106393","externalId":"CVE-2026-106393","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-106393 — Use after free in Storage in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to execute arb…","description":"Use after free in Storage in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)","cveId":"CVE-2026-106393","cvssScore":8.3,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H","severity":"high","vendor":"google","product":"chrome","affectedVersions":["< 155.0.8059.39"],"cwes":["CWE-416"],"tags":["nvd","status:awaiting-analysis","status:analyzed"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","type":"vendor","title":"Release Notes"},{"url":"https://issues.chromium.org/issues/559793873","type":"advisory","title":"Permissions Required"}],"epssScore":0.00296,"epssPercentile":0.20429,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-06T19:18:08.677Z","addedAt":"2026-10-06T20:39:32.150Z","updatedAt":"2026-10-07T14:39:33.515Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-106393","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-106393","note":"authoritative record"}]},{"id":"783340cc-b319-44f3-ae73-7e029c875ba8","slug":"cve-2026-106383","externalId":"CVE-2026-106383","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-106383 — Use after free in Media in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafte…","description":"Use after free in Media in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)","cveId":"CVE-2026-106383","cvssScore":8.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","severity":"high","vendor":"google","product":"chrome","affectedVersions":["< 155.0.8059.39"],"cwes":["CWE-416"],"tags":["nvd","status:awaiting-analysis","status:analyzed"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","type":"vendor","title":"Release Notes"},{"url":"https://issues.chromium.org/issues/567447106","type":"advisory","title":"Permissions Required"}],"epssScore":0.00331,"epssPercentile":0.24142,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-06T19:18:07.517Z","addedAt":"2026-10-06T20:39:32.075Z","updatedAt":"2026-10-07T14:39:33.464Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-106383","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-106383","note":"authoritative record"}]},{"id":"24408535-0229-4aab-82c0-1916ba60addc","slug":"cve-2026-106382","externalId":"CVE-2026-106382","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-106382 — Use after free in Chromecast in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code outside the sandbox via a …","description":"Use after free in Chromecast in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)","cveId":"CVE-2026-106382","cvssScore":9.6,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","severity":"critical","vendor":"google","product":"chrome","affectedVersions":["< 155.0.8059.39"],"cwes":["CWE-416"],"tags":["nvd","status:awaiting-analysis","status:analyzed"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","type":"vendor","title":"Release Notes"},{"url":"https://issues.chromium.org/issues/534994449","type":"advisory","title":"Permissions Required"}],"epssScore":0.00396,"epssPercentile":0.31684,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-06T19:18:07.400Z","addedAt":"2026-10-06T20:39:32.068Z","updatedAt":"2026-10-07T14:39:33.453Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-106382","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-106382","note":"authoritative record"}]},{"id":"551ad228-e381-42ba-a64f-0e8d423f1227","slug":"cve-2026-106373","externalId":"CVE-2026-106373","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-106373 — Use after free in Fonts in Google Chrome on on Windows prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbo…","description":"Use after free in Fonts in Google Chrome on on Windows prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)","cveId":"CVE-2026-106373","cvssScore":8.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","severity":"high","vendor":"google","product":"chrome","affectedVersions":["< 155.0.8059.39"],"cwes":["CWE-416"],"tags":["nvd","status:awaiting-analysis","status:analyzed"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","type":"vendor","title":"Release Notes"},{"url":"https://issues.chromium.org/issues/523699645","type":"advisory","title":"Permissions Required"}],"epssScore":0.00331,"epssPercentile":0.24142,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-06T19:18:06.413Z","addedAt":"2026-10-06T20:39:31.997Z","updatedAt":"2026-10-07T14:39:33.381Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-106373","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-106373","note":"authoritative record"}]},{"id":"cd80be06-8de7-453e-a053-924ac215392a","slug":"cve-2026-106358","externalId":"CVE-2026-106358","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-106358 — Use after free in Navigation in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code outside the sandbox via a …","description":"Use after free in Navigation in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)","cveId":"CVE-2026-106358","cvssScore":9.6,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","severity":"critical","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-416"],"tags":["nvd","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","type":"advisory","title":"chrome-cve-admin@google.com"},{"url":"https://issues.chromium.org/issues/567160164","type":"advisory","title":"chrome-cve-admin@google.com"}],"epssScore":0.00438,"epssPercentile":0.3607,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-06T19:18:04.740Z","addedAt":"2026-10-06T20:39:31.879Z","updatedAt":"2026-10-07T04:39:33.727Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-106358","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-106358","note":"authoritative record"}]},{"id":"8badd662-4e28-493e-8760-e0b6379e02c4","slug":"cve-2026-106357","externalId":"CVE-2026-106357","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-106357 — Use after free in WebRTC in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a craft…","description":"Use after free in WebRTC in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)","cveId":"CVE-2026-106357","cvssScore":8.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-416"],"tags":["nvd","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","type":"advisory","title":"chrome-cve-admin@google.com"},{"url":"https://issues.chromium.org/issues/567160162","type":"advisory","title":"chrome-cve-admin@google.com"}],"epssScore":0.00463,"epssPercentile":0.3815,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-06T19:18:04.630Z","addedAt":"2026-10-06T20:39:31.872Z","updatedAt":"2026-10-07T04:39:33.719Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-106357","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-106357","note":"authoritative record"}]},{"id":"bfd6b5d7-3e32-4441-a5a8-98914ec2f45b","slug":"cve-2026-106349","externalId":"CVE-2026-106349","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-106349 — Use after free in V8 in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted H…","description":"Use after free in V8 in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)","cveId":"CVE-2026-106349","cvssScore":8.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-416"],"tags":["nvd","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","type":"advisory","title":"chrome-cve-admin@google.com"},{"url":"https://issues.chromium.org/issues/567538973","type":"advisory","title":"chrome-cve-admin@google.com"}],"epssScore":0.00292,"epssPercentile":0.19978,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-06T19:18:03.523Z","addedAt":"2026-10-06T20:39:31.810Z","updatedAt":"2026-10-07T04:39:33.710Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-106349","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-106349","note":"authoritative record"}]},{"id":"e54b031d-42ba-4129-893c-513fa42772d3","slug":"cve-2026-106347","externalId":"CVE-2026-106347","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-106347 — Use after free in Track in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafte…","description":"Use after free in Track in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Critical)","cveId":"CVE-2026-106347","cvssScore":8.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-416"],"tags":["nvd","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","type":"advisory","title":"chrome-cve-admin@google.com"},{"url":"https://issues.chromium.org/issues/567936270","type":"advisory","title":"chrome-cve-admin@google.com"}],"epssScore":0.00313,"epssPercentile":0.22257,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-06T19:18:03.253Z","addedAt":"2026-10-06T20:39:31.793Z","updatedAt":"2026-10-07T04:39:33.701Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-106347","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-106347","note":"authoritative record"}]},{"id":"ef66b170-1b59-4dd4-a1dc-5c1f60985073","slug":"cve-2026-106335","externalId":"CVE-2026-106335","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-106335 — Use after free in Media in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafte…","description":"Use after free in Media in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)","cveId":"CVE-2026-106335","cvssScore":8.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","severity":"high","vendor":"google","product":"chrome","affectedVersions":["< 155.0.8059.39"],"cwes":["CWE-416"],"tags":["nvd","status:awaiting-analysis","status:analyzed"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","type":"vendor","title":"Release Notes"},{"url":"https://issues.chromium.org/issues/502105238","type":"advisory","title":"Permissions Required"}],"epssScore":0.00331,"epssPercentile":0.24142,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-06T19:18:01.910Z","addedAt":"2026-10-06T20:39:31.701Z","updatedAt":"2026-10-07T14:39:33.307Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-106335","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-106335","note":"authoritative record"}]},{"id":"fcf660ab-a391-4bd0-9630-23373cb7f053","slug":"cve-2026-106318","externalId":"CVE-2026-106318","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-106318 — Use after free in Media in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafte…","description":"Use after free in Media in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)","cveId":"CVE-2026-106318","cvssScore":8.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","severity":"high","vendor":"google","product":"chrome","affectedVersions":["< 155.0.8059.39"],"cwes":["CWE-416"],"tags":["nvd","status:awaiting-analysis","status:analyzed"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","type":"vendor","title":"Release Notes"},{"url":"https://issues.chromium.org/issues/566111249","type":"advisory","title":"Permissions Required"}],"epssScore":0.00303,"epssPercentile":0.2113,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-06T19:18:00.120Z","addedAt":"2026-10-06T20:39:31.570Z","updatedAt":"2026-10-07T14:39:33.191Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-106318","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-106318","note":"authoritative record"}]}],"pagination":{"page":1,"limit":20,"total":2358,"totalPages":118,"hasNext":true,"hasPrev":false}},"meta":{"apiVersion":"v1","requestedAt":"2026-10-09T01:18:44.457Z","durationMs":46,"filters":{"search":null,"severity":[],"type":[],"country":[],"tag":[],"cwe":["CWE-416"],"vendor":null,"product":null,"cve":null,"source":[],"days":null,"publishedAfter":null,"publishedBefore":null,"minCvss":null,"maxCvss":null,"minEpss":null,"knownExploited":null,"hasPatch":null,"hasNucleiTemplate":null},"sort":"newest","unknownParams":[],"warnings":[]}}