| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-19264 | Cri | 0.57 | 9.8 | 0.01 | Aug 7, 2026 | Postiz is an open-source social media scheduling tool. The route that serves locally stored media joins URL-supplied path segments onto the upload directory and streams the file without normalising the path or confining it to that directory, and the route requires no… | ||
| CVE-2022-4995 | Cri | 0.64 | 9.8 | 0.01 | Aug 7, 2026 | Weaver (Fanwei) E-cology 9.0 versions prior to 10.52 contain a file upload vulnerability that allows a remote, unauthenticated attacker to upload arbitrary files, including JSP webshells, by submitting a multipart/form-data POST request to /workrelate/plan/util/uploaderOperate.js… | ||
| CVE-2026-66914 | Cri | 0.60 | — | 0.01 | Aug 7, 2026 | Joomla Extension - seblod.com - Unauthenticated path traversal in SEBLOD < 3.30.0, < 4.7.0, < 6.0.1 - An unauthenticated attacker could download files from both inside and outside the webroot. | ||
| CVE-2026-71560 | Cri | 0.52 | 9.1 | 0.01 | Aug 7, 2026 | Out-of-bounds Read vulnerability in Apache Fory C++ deserialization. This issue affects Apache Fory C++ versions from 0.14.0 before 1.5.0 when deserializing structs containing tagged integer fields. A crafted input payload may trigger an out-of-bounds heap read in the tagged… | ||
| CVE-2026-71558 | Cri | 0.57 | 9.8 | 0.01 | Aug 7, 2026 | Heap type confusion vulnerability in Apache Fory C++ deserialization. This issue affects Apache Fory C++ versions from 0.14.0 before 1.5.0. A crafted input payload can bypass type compatibility checks during polymorphic smart-pointer deserialization, causing an object of an… | ||
| CVE-2026-54213 | Cri | 0.60 | — | 0.01 | Aug 7, 2026 | Tobit Laboratories AG TeamDavid's Webbox application exposes a functionality that allows the server to be shut down when a specific endpoint (/internalRestart) is accessed. This endpoint is accessible to unauthenticated users over the public Internet. Instead of… | ||
| CVE-2026-54212 | Cri | 0.62 | — | 0.01 | Aug 7, 2026 | Tobit Laboratories AG TeamDavid's Webbox application implements an API endpoint that is vulnerable to a buffer overflow condition. By submitting a specially crafted JSON body, such as one that is at least 8 characters long and begins with a number, an unauthenticated attacker… | ||
| CVE-2026-54211 | Cri | 0.62 | — | 0.01 | Aug 7, 2026 | Tobit Laboratories AG TeamDavid's Webbox application’s endpoint “//serverClient_close.html” is vulnerable to a buffer overflow vulnerability in multiple form data parameters. By submitting excessively long values in these parameters, an authenticated attacker can… | ||
| CVE-2026-54210 | Cri | 0.62 | — | 0.01 | Aug 7, 2026 | Tobit Laboratories AG TeamDavid's Webbox application implements various file upload functionalities that are vulnerable to a buffer overflow condition. By specifying an excessively long filename in a file upload request, an unauthenticated attacker can trigger a crash of the… | ||
| CVE-2026-54203 | Cri | 0.60 | — | 0.01 | Aug 7, 2026 | Memory Leak to an Unauthorized Actor vulnerability in Tobit Laboratories AG TeamDavid's Webbox allows reading of sensitive information. When accessing the URL “/.well-known/mta-sts.”, the application responds with memory. By repeatedly requesting this endpoint, an attacker… | ||
| CVE-2026-16258 | Cri | 0.64 | 9.8 | 0.01 | Aug 7, 2026 | The Ajax Search Lite WordPress plugin before 4.14.5 does not prevent the deserialization of untrusted input, allowing unauthenticated attackers to perform PHP Object Injection. When a suitable POP chain is present via another installed Ajax Search Lite WordPress plugin before… | ||
| CVE-2026-16038 | Cri | 0.59 | 9.1 | 0.00 | Aug 7, 2026 | The MStore API WordPress plugin before 4.21.0 does not verify the payment with the payment gateway before marking an order as paid on several of its payment-completion endpoints, allowing an unauthenticated attacker to mark an arbitrary order fully paid without paying and… | ||
| CVE-2026-14205 | Cri | 0.64 | 9.8 | 0.00 | Aug 7, 2026 | The WP Events Manager WordPress plugin before 2.2.5 does not validate the requested quantity when registering for a paid event and computes the price from the attacker-controlled quantity, allowing any authenticated user to create a completed booking for a paid event without… | ||
| CVE-2026-14365 | Cri | 0.57 | 9.8 | 0.01 | Aug 7, 2026 | The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.2.3. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it… | ||
| CVE-2026-14364 | Cri | 0.57 | 9.8 | 0.01 | Aug 7, 2026 | The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress is vulnerable to account takeover via improper password reset validation in all versions up to, and including, 1.2.3. This is due to the plugin not properly validating a user's identity before… | ||
| CVE-2026-70332 | Cri | 0.62 | 9.6 | 0.01 | Aug 7, 2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network. | ||
| CVE-2026-68823 | Cri | 0.59 | 9.1 | 0.01 | Aug 7, 2026 | Exposed dangerous method or function in Azure Confidential Ledger allows an authorized attacker to execute code over a network. | ||
| CVE-2026-65667 | Cri | 0.65 | 10.0 | 0.01 | Aug 7, 2026 | Missing authorization in Microsoft Teams allows an unauthorized attacker to elevate privileges over a network. | ||
| CVE-2026-63508 | Cri | 0.65 | 10.0 | 0.01 | Aug 7, 2026 | Missing authentication for critical function in Microsoft Planetary Computer Pro allows an unauthorized attacker to elevate privileges over a network. | ||
| CVE-2026-62896 | Cri | 0.62 | 9.6 | 0.01 | Aug 7, 2026 | Improper authentication in Microsoft Teams allows an authorized attacker to elevate privileges over a network. | ||
| CVE-2026-62873 | Cri | 0.64 | 9.8 | 0.01 | Aug 7, 2026 | Improper verification of cryptographic signature in Microsoft 365 Admin Center allows an unauthorized attacker to elevate privileges over a network. | ||
| CVE-2026-62830 | Cri | 0.64 | 9.9 | 0.01 | Aug 7, 2026 | Missing authorization in Azure SRE Agent allows an authorized attacker to elevate privileges over a network. | ||
| CVE-2026-59118 | Cri | 0.60 | 9.3 | 0.01 | Aug 7, 2026 | Improper authorization in Copilot Cowork allows an unauthorized attacker to elevate privileges over a network. | ||
| CVE-2026-59115 | Cri | 0.64 | 9.9 | 0.01 | Aug 7, 2026 | '.../...//' in Microsoft Entra Provisioning Service (SyncFabric) allows an authorized attacker to elevate privileges over a network. | ||
| CVE-2026-56162 | Cri | 0.65 | 10.0 | 0.01 | Aug 7, 2026 | Improper authentication in Azure SQL Database allows an unauthorized attacker to elevate privileges over a network. | ||
| CVE-2026-56161 | Cri | 0.62 | 9.6 | 0.01 | Aug 7, 2026 | Improper access control in Azure Logic Apps allows an authorized attacker to disclose information over a network. | ||
| CVE-2026-50515 | Cri | 0.64 | 9.9 | 0.02 | Aug 7, 2026 | Deserialization of untrusted data in Azure Service Bus allows an authorized attacker to execute code over a network. | ||
| CVE-2026-50481 | Cri | 0.64 | 9.9 | 0.01 | Aug 7, 2026 | Modification of assumed-immutable data (maid) in Azure Active Directory allows an authorized attacker to elevate privileges over a network. | ||
| CVE-2026-71324 | Cri | 0.52 | 9.1 | 0.01 | Aug 6, 2026 | Traefik is an open source HTTP reverse proxy and load balancer. Prior to 2.11.53, 3.6.24, and 3.7.9, Traefik's default HTTP reverse proxy forwards a plain HTTP/2 or HTTP/3 CONNECT request and its body to an HTTP/1.1 upstream through a shared net/http.Transport. When the upstream… | ||
| CVE-2026-70558 | Cri | 0.64 | 9.8 | 0.01 | Aug 6, 2026 | Dinky's POST /download/uploadFromRsByLocal handler passes the caller-supplied path parameter directly to new File(path) and file.transferTo(dest) with no path validation. The route is marked @SaIgnore and /download/** is excluded from the Sa-Token interceptor, so the only guard… | ||
| CVE-2026-67689 | Cri | 0.64 | 9.8 | 0.01 | Aug 6, 2026 | SQL Injection vulnerability in FineAdmin V1.0 allows a remote attacker to execute arbitrary code via the `field` and `order` parameters in paginated list endpoints | ||
| CVE-2026-67688 | Cri | 0.64 | 9.8 | 0.01 | Aug 6, 2026 | ICS-Park Smart Park Management System v2.0 contains an unrestricted file upload vulnerability in the file upload module. This allows a remote attacker to execute arbitrary code. | ||
| CVE-2026-67622 | Cri | 0.64 | 9.9 | 0.00 | Aug 6, 2026 | Flowise through 3.1.4 contains an insecure direct object reference vulnerability in the OpenAI Assistants integration that allows authenticated attackers to access credentials belonging to other workspaces by supplying an arbitrary credential UUID to Assistants endpoints without… | ||
| CVE-2026-65400 | Cri | 0.76 | 9.8 | 0.02 | KEV | Aug 6, 2026 | An authentication issue was addressed with improved state management. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.7.9, macOS Sonoma 14.8.9, macOS Tahoe 26.6.1, macOS Tahoe 26.7. An attacker on the network may be able to authenticate to Screen Sharing without… | |
| CVE-2026-53984 | Cri | 0.59 | 9.1 | 0.01 | Aug 6, 2026 | Ground Station prior to 0.6.0 contains an unauthenticated database-destruction and arbitrary-data-injection vulnerability in the Socket.IO server's database_backup event handler that allows any unauthenticated network peer to wipe or replace the entire SQLite database by… | ||
| CVE-2026-48088 | Cri | 0.61 | 9.4 | 0.00 | Aug 6, 2026 | OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.4, the route `POST /api/tenants/{tenantId}/staff/{staffId}/crypto` accepts and stores attacker-controlled ML-KEM-768 public keys against any tenant on… | ||
| CVE-2026-48087 | Cri | 0.64 | 9.8 | 0.01 | Aug 6, 2026 | OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.2, the registration handler at `POST /api/auth/register/{userId}` validates the relationship between the WebAuthn challenge and the registration… | ||
| CVE-2026-48086 | Cri | 0.64 | 9.9 | 0.00 | Aug 6, 2026 | OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.2, a TENANT_ADMIN promotes themselves to platform-wide GLOBAL_ADMIN through a single PUT request. The role-update handler accepts the `GLOBAL_ADMIN`… | ||
| CVE-2026-48085 | Cri | 0.64 | 9.8 | 0.01 | Aug 6, 2026 | OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.1, a fully provisioned OpenReception instance accepts unauthenticated POST requests to `/setup/create-admin-account` and creates additional… | ||
| CVE-2026-3418 | — | Cri | 0.59 | 9.1 | 0.01 | Aug 6, 2026 | The System REST API accepts user-supplied file uploads without enforcing sufficient validation on the file type or destination, allowing files to be written to arbitrary server-accessible locations. Exploitation requires authenticated administrative access with publisher… | |
| CVE-2026-19175 | Cri | 0.62 | 9.6 | 0.00 | Aug 6, 2026 | Use after free in Payments in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) | ||
| CVE-2026-19171 | Cri | 0.62 | 9.6 | 0.00 | Aug 6, 2026 | Use after free in Media in Google Chrome on Windows prior to 151.0.7922.109 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) | ||
| CVE-2026-19170 | Cri | 0.62 | 9.6 | 0.00 | Aug 6, 2026 | Use after free in WebGL in Google Chrome on Android prior to 151.0.7922.109 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical) | ||
| CVE-2026-19166 | Cri | 0.62 | 9.6 | 0.00 | Aug 6, 2026 | Use after free in Web Authentication in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) | ||
| CVE-2026-19164 | Cri | 0.62 | 9.6 | 0.00 | Aug 6, 2026 | Insufficient validation of untrusted input in Codecs in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) | ||
| CVE-2026-19157 | Cri | 0.62 | 9.6 | 0.00 | Aug 6, 2026 | Out of bounds write in ANGLE in Google Chrome on Android prior to 151.0.7922.109 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical) | ||
| CVE-2026-19149 | Cri | 0.62 | 9.6 | 0.00 | Aug 6, 2026 | Use after free in Aura in Google Chrome on Linux prior to 151.0.7922.109 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical) | ||
| CVE-2026-18367 | Cri | 0.60 | 9.3 | 0.00 | Aug 6, 2026 | A privilege escalation vulnerability allows local users to execute arbitrary code as root via Sophos Endpoint for macOS older than version 2026.1.1 and Sophos Home for macOS older than version 10.11.6. | ||
| CVE-2026-17032 | Cri | 0.64 | 9.8 | 0.01 | Aug 6, 2026 | Multiple Supsystic Pro plugins were distributed with malicious code through the vendor's compromised update server, allowing unauthenticated attackers to deploy a second-stage payload that exfiltrates credentials and other sensitive data and grants full control of affected sites. | ||
| CVE-2026-15734 | Cri | 0.64 | 9.8 | 0.01 | Aug 6, 2026 | A Server-Side Template Injection (SSTI) vulnerability in WGDashboard version 4.3.2 and earlier, allows authenticated attackers to execute arbitrary code as root. |
- risk 0.57cvss 9.8epss 0.01
Postiz is an open-source social media scheduling tool. The route that serves locally stored media joins URL-supplied path segments onto the upload directory and streams the file without normalising the path or confining it to that directory, and the route requires no…
- risk 0.64cvss 9.8epss 0.01
Weaver (Fanwei) E-cology 9.0 versions prior to 10.52 contain a file upload vulnerability that allows a remote, unauthenticated attacker to upload arbitrary files, including JSP webshells, by submitting a multipart/form-data POST request to /workrelate/plan/util/uploaderOperate.js…
- risk 0.60cvss —epss 0.01
Joomla Extension - seblod.com - Unauthenticated path traversal in SEBLOD < 3.30.0, < 4.7.0, < 6.0.1 - An unauthenticated attacker could download files from both inside and outside the webroot.
- risk 0.52cvss 9.1epss 0.01
Out-of-bounds Read vulnerability in Apache Fory C++ deserialization. This issue affects Apache Fory C++ versions from 0.14.0 before 1.5.0 when deserializing structs containing tagged integer fields. A crafted input payload may trigger an out-of-bounds heap read in the tagged…
- risk 0.57cvss 9.8epss 0.01
Heap type confusion vulnerability in Apache Fory C++ deserialization. This issue affects Apache Fory C++ versions from 0.14.0 before 1.5.0. A crafted input payload can bypass type compatibility checks during polymorphic smart-pointer deserialization, causing an object of an…
- risk 0.60cvss —epss 0.01
Tobit Laboratories AG TeamDavid's Webbox application exposes a functionality that allows the server to be shut down when a specific endpoint (/internalRestart) is accessed. This endpoint is accessible to unauthenticated users over the public Internet. Instead of…
- risk 0.62cvss —epss 0.01
Tobit Laboratories AG TeamDavid's Webbox application implements an API endpoint that is vulnerable to a buffer overflow condition. By submitting a specially crafted JSON body, such as one that is at least 8 characters long and begins with a number, an unauthenticated attacker…
- risk 0.62cvss —epss 0.01
Tobit Laboratories AG TeamDavid's Webbox application’s endpoint “//serverClient_close.html” is vulnerable to a buffer overflow vulnerability in multiple form data parameters. By submitting excessively long values in these parameters, an authenticated attacker can…
- risk 0.62cvss —epss 0.01
Tobit Laboratories AG TeamDavid's Webbox application implements various file upload functionalities that are vulnerable to a buffer overflow condition. By specifying an excessively long filename in a file upload request, an unauthenticated attacker can trigger a crash of the…
- risk 0.60cvss —epss 0.01
Memory Leak to an Unauthorized Actor vulnerability in Tobit Laboratories AG TeamDavid's Webbox allows reading of sensitive information. When accessing the URL “/.well-known/mta-sts.”, the application responds with memory. By repeatedly requesting this endpoint, an attacker…
- risk 0.64cvss 9.8epss 0.01
The Ajax Search Lite WordPress plugin before 4.14.5 does not prevent the deserialization of untrusted input, allowing unauthenticated attackers to perform PHP Object Injection. When a suitable POP chain is present via another installed Ajax Search Lite WordPress plugin before…
- risk 0.59cvss 9.1epss 0.00
The MStore API WordPress plugin before 4.21.0 does not verify the payment with the payment gateway before marking an order as paid on several of its payment-completion endpoints, allowing an unauthenticated attacker to mark an arbitrary order fully paid without paying and…
- risk 0.64cvss 9.8epss 0.00
The WP Events Manager WordPress plugin before 2.2.5 does not validate the requested quantity when registering for a paid event and computes the price from the attacker-controlled quantity, allowing any authenticated user to create a completed booking for a paid event without…
- risk 0.57cvss 9.8epss 0.01
The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.2.3. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it…
- risk 0.57cvss 9.8epss 0.01
The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress is vulnerable to account takeover via improper password reset validation in all versions up to, and including, 1.2.3. This is due to the plugin not properly validating a user's identity before…
- risk 0.62cvss 9.6epss 0.01
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.
- risk 0.59cvss 9.1epss 0.01
Exposed dangerous method or function in Azure Confidential Ledger allows an authorized attacker to execute code over a network.
- risk 0.65cvss 10.0epss 0.01
Missing authorization in Microsoft Teams allows an unauthorized attacker to elevate privileges over a network.
- risk 0.65cvss 10.0epss 0.01
Missing authentication for critical function in Microsoft Planetary Computer Pro allows an unauthorized attacker to elevate privileges over a network.
- risk 0.62cvss 9.6epss 0.01
Improper authentication in Microsoft Teams allows an authorized attacker to elevate privileges over a network.
- risk 0.64cvss 9.8epss 0.01
Improper verification of cryptographic signature in Microsoft 365 Admin Center allows an unauthorized attacker to elevate privileges over a network.
- risk 0.64cvss 9.9epss 0.01
Missing authorization in Azure SRE Agent allows an authorized attacker to elevate privileges over a network.
- risk 0.60cvss 9.3epss 0.01
Improper authorization in Copilot Cowork allows an unauthorized attacker to elevate privileges over a network.
- risk 0.64cvss 9.9epss 0.01
'.../...//' in Microsoft Entra Provisioning Service (SyncFabric) allows an authorized attacker to elevate privileges over a network.
- risk 0.65cvss 10.0epss 0.01
Improper authentication in Azure SQL Database allows an unauthorized attacker to elevate privileges over a network.
- risk 0.62cvss 9.6epss 0.01
Improper access control in Azure Logic Apps allows an authorized attacker to disclose information over a network.
- risk 0.64cvss 9.9epss 0.02
Deserialization of untrusted data in Azure Service Bus allows an authorized attacker to execute code over a network.
- risk 0.64cvss 9.9epss 0.01
Modification of assumed-immutable data (maid) in Azure Active Directory allows an authorized attacker to elevate privileges over a network.
- risk 0.52cvss 9.1epss 0.01
Traefik is an open source HTTP reverse proxy and load balancer. Prior to 2.11.53, 3.6.24, and 3.7.9, Traefik's default HTTP reverse proxy forwards a plain HTTP/2 or HTTP/3 CONNECT request and its body to an HTTP/1.1 upstream through a shared net/http.Transport. When the upstream…
- risk 0.64cvss 9.8epss 0.01
Dinky's POST /download/uploadFromRsByLocal handler passes the caller-supplied path parameter directly to new File(path) and file.transferTo(dest) with no path validation. The route is marked @SaIgnore and /download/** is excluded from the Sa-Token interceptor, so the only guard…
- risk 0.64cvss 9.8epss 0.01
SQL Injection vulnerability in FineAdmin V1.0 allows a remote attacker to execute arbitrary code via the `field` and `order` parameters in paginated list endpoints
- risk 0.64cvss 9.8epss 0.01
ICS-Park Smart Park Management System v2.0 contains an unrestricted file upload vulnerability in the file upload module. This allows a remote attacker to execute arbitrary code.
- risk 0.64cvss 9.9epss 0.00
Flowise through 3.1.4 contains an insecure direct object reference vulnerability in the OpenAI Assistants integration that allows authenticated attackers to access credentials belonging to other workspaces by supplying an arbitrary credential UUID to Assistants endpoints without…
- risk 0.76cvss 9.8epss 0.02
An authentication issue was addressed with improved state management. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.7.9, macOS Sonoma 14.8.9, macOS Tahoe 26.6.1, macOS Tahoe 26.7. An attacker on the network may be able to authenticate to Screen Sharing without…
- risk 0.59cvss 9.1epss 0.01
Ground Station prior to 0.6.0 contains an unauthenticated database-destruction and arbitrary-data-injection vulnerability in the Socket.IO server's database_backup event handler that allows any unauthenticated network peer to wipe or replace the entire SQLite database by…
- risk 0.61cvss 9.4epss 0.00
OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.4, the route `POST /api/tenants/{tenantId}/staff/{staffId}/crypto` accepts and stores attacker-controlled ML-KEM-768 public keys against any tenant on…
- risk 0.64cvss 9.8epss 0.01
OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.2, the registration handler at `POST /api/auth/register/{userId}` validates the relationship between the WebAuthn challenge and the registration…
- risk 0.64cvss 9.9epss 0.00
OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.2, a TENANT_ADMIN promotes themselves to platform-wide GLOBAL_ADMIN through a single PUT request. The role-update handler accepts the `GLOBAL_ADMIN`…
- risk 0.64cvss 9.8epss 0.01
OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.1, a fully provisioned OpenReception instance accepts unauthenticated POST requests to `/setup/create-admin-account` and creates additional…
- risk 0.59cvss 9.1epss 0.01
The System REST API accepts user-supplied file uploads without enforcing sufficient validation on the file type or destination, allowing files to be written to arbitrary server-accessible locations. Exploitation requires authenticated administrative access with publisher…
- risk 0.62cvss 9.6epss 0.00
Use after free in Payments in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
- risk 0.62cvss 9.6epss 0.00
Use after free in Media in Google Chrome on Windows prior to 151.0.7922.109 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
- risk 0.62cvss 9.6epss 0.00
Use after free in WebGL in Google Chrome on Android prior to 151.0.7922.109 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
- risk 0.62cvss 9.6epss 0.00
Use after free in Web Authentication in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
- risk 0.62cvss 9.6epss 0.00
Insufficient validation of untrusted input in Codecs in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
- risk 0.62cvss 9.6epss 0.00
Out of bounds write in ANGLE in Google Chrome on Android prior to 151.0.7922.109 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
- risk 0.62cvss 9.6epss 0.00
Use after free in Aura in Google Chrome on Linux prior to 151.0.7922.109 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
- risk 0.60cvss 9.3epss 0.00
A privilege escalation vulnerability allows local users to execute arbitrary code as root via Sophos Endpoint for macOS older than version 2026.1.1 and Sophos Home for macOS older than version 10.11.6.
- risk 0.64cvss 9.8epss 0.01
Multiple Supsystic Pro plugins were distributed with malicious code through the vendor's compromised update server, allowing unauthenticated attackers to deploy a second-stage payload that exfiltrates credentials and other sensitive data and grants full control of affected sites.
- risk 0.64cvss 9.8epss 0.01
A Server-Side Template Injection (SSTI) vulnerability in WGDashboard version 4.3.2 and earlier, allows authenticated attackers to execute arbitrary code as root.