| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-8925 | Cri | 0.57 | 9.8 | 0.01 | Jul 3, 2026 | The curl logic that works with SASL authentication could end up cleaning up the GSASL context *twice* without clearing the pointer in between, making it `free()` the same pointer twice. | ||
| CVE-2026-8924 | Cri | 0.52 | 9.1 | 0.01 | Jul 3, 2026 | A flaw in curl’s cookie parsing logic allows a malicious HTTP server to set "super cookies" that bypass the Public Suffix List check. This enables an attacker-controlled origin to inject cookies that curl subsequently scopes and transmits to unrelated third-party domains. | ||
| CVE-2026-11856 | Cri | 0.57 | 9.8 | 0.01 | Jul 3, 2026 | Successfully using libcurl to do a transfer to a specific HTTP origin (`hostA`) with **Digest** authentication and then changing the origin to a different one (`hostB`) for a second transfer, reusing the same handle, makes libcurl wrongly pass on the `Authorization:` header… | ||
| CVE-2026-11564 | Cri | 0.52 | 9.1 | 0.00 | Jul 3, 2026 | libcurl keeps previously used connections in a connection pool for subsequent transfers to reuse if one of them matches the setup. An easy handle that first uses default native CA trust can continue trusting the native platform store after the application switches that same… | ||
| CVE-2026-10536 | Cri | 0.57 | 9.8 | 0.01 | Jul 3, 2026 | A use-after-free vulnerability exists in libcurl when an application configures an HTTP/2 stream-dependency tree via `CURLOPT_STREAM_DEPENDS` or `CURLOPT_STREAM_DEPENDS_E`, subsequently invokes `curl_easy_reset()`, and finally terminates the handle with `curl_easy_cleanup()`.… | ||
| CVE-2026-9725 | Cri | 0.00 | 9.1 | 0.01 | Jul 3, 2026 | The Printcart Web to Print Product Designer for WooCommerce plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up to, and including, 2.5.2 This is due to insufficient path validation in the store_design_data() function, which constructs a filesystem path… | ||
| CVE-2026-13768 | Cri | 0.65 | 10.0 | 0.01 | Jul 3, 2026 | Gardyn devices expose a privileged iothubowner key. Access to this key will allow a malicious user to invoke an IoTHub Registry Manager function which returns connection information for all Gardyn Home Kit and Studio devices. Access to this key also allows a malicious user to… | ||
| CVE-2026-57100 | Cri | 0.00 | 9.9 | 0.01 | Jul 2, 2026 | Server-side request forgery (ssrf) in Microsoft Entra Provisioning Service (SyncFabric) allows an authorized attacker to elevate privileges over a network. | ||
| CVE-2026-45499 | Cri | 0.00 | 9.9 | 0.01 | Jul 2, 2026 | Server-side request forgery (ssrf) in Azure OpenAI allows an authorized attacker to elevate privileges over a network. | ||
| CVE-2026-41106 | Cri | 0.00 | 9.3 | 0.01 | Jul 2, 2026 | Url redirection to untrusted site ('open redirect') in M365 Copilot allows an unauthorized attacker to elevate privileges over a network. | ||
| CVE-2026-52830 | Cri | 0.54 | 9.4 | 0.01 | Jul 2, 2026 | fast-mcp-telegram is a Telegram MCP Server. Prior to 0.19.1, fast-mcp-telegram validates HTTP Bearer tokens by joining the raw token string into a session-file path. The verifier rejects the exact reserved token telegram, but it does not reject path separators or normalize the… | ||
| CVE-2026-38971 | Cri | 0.52 | 9.1 | 0.01 | Jul 2, 2026 | ardupilot through Plane-4.6.3 was found to contain an out-of-bounds read issue in libraries/GCS_MAVLink/GCS_serial_control.cpp in GCS_MAVLINK::handle_serial_control(). | ||
| CVE-2026-38968 | Cri | 0.00 | 9.8 | 0.01 | Jul 2, 2026 | ntopng through 6.6 is vulnerable to Predictable Session Identifier which can lead to Session Hijacking. HTTP session identifiers in src/HTTPserver.cpp use weak time-seeded pseudo-randomness during session creation. As a result, fresh authenticated logins can receive… | ||
| CVE-2026-59099 | Cri | 0.00 | 9.1 | 0.01 | Jul 2, 2026 | Apereo CAS 7.3.0 before 8.0.0-RC6 contains a cryptographic vulnerability that allows remote unauthenticated attackers to recover plaintext conversation state by exploiting AES-GCM initialization vector reuse across the server lifetime. Attackers can collect multiple client-side… | ||
| CVE-2026-58466 | Cri | 0.00 | 9.8 | 0.01 | Jul 2, 2026 | AutoBangumi before 3.2.8 contains a hard-coded default credentials vulnerability that allows unauthenticated attackers to authenticate as the administrator by using the publicly known default credentials seeded at startup via add_default_user() in the database user module when… | ||
| CVE-2026-44935 | Cri | 0.57 | 9.9 | 0.00 | Jul 2, 2026 | Missing validation of "valuesFrom" references in Helm Deployer of SUSE Rancher Fleet 0.15 before 0.15.2, 0.14 before 0.14.6, 0.13 before 0.13.11 and 0.12 before 0.12.15 could be used by owners of one tenant to access fleet credentials of other tenants. | ||
| CVE-2024-14037 | Cri | 0.64 | 9.8 | 0.01 | Jul 2, 2026 | Redsea Cloud eHR contains an arbitrary file upload vulnerability that allows unauthenticated attackers to achieve remote code execution by uploading malicious files through the PtFjk.mob servlet endpoint. Attackers can submit a multipart POST request with a JSP webshell… | ||
| CVE-2022-50973 | Cri | 0.00 | 9.8 | 0.02 | Jul 2, 2026 | Yonyou KSOA 9.0 contains an unauthenticated arbitrary file upload vulnerability in the com.sksoft.bill.ImageUpload servlet that allows unauthenticated attackers to upload arbitrary files by submitting a POST request with attacker-controlled filepath and filename parameters… | ||
| CVE-2026-58455 | Cri | 0.00 | 9.8 | 0.08 | Jul 2, 2026 | Dockwatch through 0.6.567 contains an unauthenticated OS command injection vulnerability that allows remote attackers to execute arbitrary shell commands by exploiting a missing exit() after an authentication redirect in loader.php combined with unsanitized input passed to… | ||
| CVE-2026-56004 | Cri | 0.00 | 10.0 | 0.01 | Jul 2, 2026 | A shellcode injection in the mercurial handler of the obs tar_scm source service before version 0.12.4 could be used by attackers able to provide a _service file to execute code as the source service or the local user checking out the malicious services | ||
| CVE-2026-55116 | Cri | 0.00 | 9.0 | 0.00 | Jul 2, 2026 | A malicious actor with access to the network and under certain network configurations could exploit an Improper Access Control vulnerability found in certain devices running UniFi OS to make unauthorized changes to such UniFi OS devices. | ||
| CVE-2026-55115 | Cri | 0.00 | 9.9 | 0.00 | Jul 2, 2026 | A malicious actor with access to the network and low privileges could exploit a Server-Side Request Forgery (SSRF) in UniFi Protect Application to escalate privileges on the host device. | ||
| CVE-2026-54402 | Cri | 0.00 | 9.9 | 0.02 | Jul 2, 2026 | A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi OS to execute a Command Injection on the host device. | ||
| CVE-2026-54400 | Cri | 0.59 | 9.1 | 0.01 | Jul 2, 2026 | A malicious actor with access to the network and high privileges could exploit an Improper Access Control vulnerability found in UniFi Access Application to escalate privileges on the host device. | ||
| CVE-2026-50748 | Cri | 0.64 | 9.9 | 0.02 | Jul 2, 2026 | A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi Access Application to execute a Command Injection on the host device. | ||
| CVE-2026-50747 | Cri | 0.00 | 9.9 | 0.00 | Jul 2, 2026 | A malicious actor with access to the network and low privileges could exploit a series of authenticated SQL Injection vulnerabilities found in UniFi Talk Application to escalate privileges on the host device. | ||
| CVE-2026-50746 | Cri | 0.00 | 10.0 | 0.02 | Jul 2, 2026 | A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi Connect Application to execute a Command Injection on the host device. | ||
| CVE-2026-4767 | Cri | 0.00 | 9.8 | 0.01 | Jul 2, 2026 | Missing authentication for critical function vulnerability in TR7 Cyber Defense Inc. WAF-ASP allows Authentication Abuse. This issue affects WAF-ASP: from v1.0.324.900 before v1.4.0.117. | ||
| CVE-2026-5524 | Cri | 0.00 | 9.8 | 0.03 | Jul 2, 2026 | The Divi Form Builder plugin for WordPress is vulnerable to Arbitrary File Upload leading to Remote Code Execution in all versions up to and including 5.1.8. This is due to insufficient file extension validation in the do_image_upload() function where user-supplied input from… | ||
| CVE-2026-57683 | Cri | 0.00 | 9.3 | 0.00 | Jul 2, 2026 | Unauthenticated SQL Injection in WP Fast Total Search <= 1.80.280 versions. | ||
| CVE-2026-57679 | Cri | 0.00 | 9.3 | 0.00 | Jul 2, 2026 | Unauthenticated SQL Injection in GeekyBot <= 1.2.5 versions. | ||
| CVE-2026-57677 | Cri | 0.00 | 9.8 | 0.01 | Jul 2, 2026 | Unauthenticated PHP Object Injection in Novalnet Payment Gateway for WooCommerce <= 12.10.3 versions. | ||
| CVE-2026-57625 | Cri | 0.00 | 9.6 | 0.00 | Jul 2, 2026 | Unauthenticated Cross Site Scripting (XSS) in Admin and Site Enhancements (ASE) Pro <= 8.8.5 versions. | ||
| CVE-2026-57624 | Cri | 0.00 | 10.0 | 0.01 | Jul 2, 2026 | Unauthenticated Remote Code Execution (RCE) in Blocksy Companion Pro <= 2.1.46 versions. | ||
| CVE-2026-57623 | Cri | 0.00 | 9.0 | 0.01 | Jul 2, 2026 | Unauthenticated Arbitrary Code Execution in W3 Total Cache <= 2.9.4 versions. | ||
| CVE-2026-57621 | Cri | 0.00 | 9.8 | 0.01 | Jul 2, 2026 | Unauthenticated PHP Object Injection in Booktics <= 1.0.21 versions. | ||
| CVE-2026-27436 | Cri | 0.00 | 9.1 | 0.01 | Jul 2, 2026 | Editor Arbitrary Code Execution in Five Star Business Profile and Schema <= 2.3.19 versions. | ||
| CVE-2026-27419 | Cri | 0.00 | 9.9 | 0.00 | Jul 2, 2026 | Subscriber Arbitrary File Upload in Zegen <= 1.1.9 versions. | ||
| CVE-2026-14439 | Cri | 0.00 | — | 0.01 | Jul 1, 2026 | A path traversal vulnerability exists in the Git Service component shared by Altium Enterprise Server and Altium 365. The service accepts a sequence of post-clone file-manipulation operations that use user-supplied paths without validation, allowing an authenticated user with… | ||
| CVE-2026-14425 | Cri | 0.00 | 9.6 | 0.00 | Jul 1, 2026 | Use after free in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) | ||
| CVE-2026-14424 | Cri | 0.00 | 9.6 | 0.00 | Jul 1, 2026 | Use after free in Dawn in Google Chrome on Mac prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) | ||
| CVE-2026-14423 | Cri | 0.00 | 9.6 | 0.00 | Jul 1, 2026 | Type Confusion in Tint in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) | ||
| CVE-2026-14420 | Cri | 0.00 | 9.6 | 0.00 | Jul 1, 2026 | Out of bounds read and write in Dawn in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical) | ||
| CVE-2026-14419 | Cri | 0.00 | 9.6 | 0.00 | Jul 1, 2026 | Use after free in Skia in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical) | ||
| CVE-2026-14417 | Cri | 0.00 | 9.6 | 0.00 | Jul 1, 2026 | Use after free in Dawn in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical) | ||
| CVE-2026-14416 | Cri | 0.00 | 9.6 | 0.00 | Jul 1, 2026 | Out of bounds read in Dawn in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low) | ||
| CVE-2026-14411 | Cri | 0.00 | 9.6 | 0.00 | Jul 1, 2026 | Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) | ||
| CVE-2026-14405 | Cri | 0.00 | 9.6 | 0.01 | Jul 1, 2026 | Uninitialized Use in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Low) | ||
| CVE-2026-14398 | Cri | 0.00 | 9.6 | 0.00 | Jul 1, 2026 | Use after free in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical) | ||
| CVE-2026-14397 | Cri | 0.00 | 9.6 | 0.00 | Jul 1, 2026 | Out of bounds write in ANGLE in Google Chrome on Mac prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium) |
- risk 0.57cvss 9.8epss 0.01
The curl logic that works with SASL authentication could end up cleaning up the GSASL context *twice* without clearing the pointer in between, making it `free()` the same pointer twice.
- risk 0.52cvss 9.1epss 0.01
A flaw in curl’s cookie parsing logic allows a malicious HTTP server to set "super cookies" that bypass the Public Suffix List check. This enables an attacker-controlled origin to inject cookies that curl subsequently scopes and transmits to unrelated third-party domains.
- risk 0.57cvss 9.8epss 0.01
Successfully using libcurl to do a transfer to a specific HTTP origin (`hostA`) with **Digest** authentication and then changing the origin to a different one (`hostB`) for a second transfer, reusing the same handle, makes libcurl wrongly pass on the `Authorization:` header…
- risk 0.52cvss 9.1epss 0.00
libcurl keeps previously used connections in a connection pool for subsequent transfers to reuse if one of them matches the setup. An easy handle that first uses default native CA trust can continue trusting the native platform store after the application switches that same…
- risk 0.57cvss 9.8epss 0.01
A use-after-free vulnerability exists in libcurl when an application configures an HTTP/2 stream-dependency tree via `CURLOPT_STREAM_DEPENDS` or `CURLOPT_STREAM_DEPENDS_E`, subsequently invokes `curl_easy_reset()`, and finally terminates the handle with `curl_easy_cleanup()`.…
- risk 0.00cvss 9.1epss 0.01
The Printcart Web to Print Product Designer for WooCommerce plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up to, and including, 2.5.2 This is due to insufficient path validation in the store_design_data() function, which constructs a filesystem path…
- risk 0.65cvss 10.0epss 0.01
Gardyn devices expose a privileged iothubowner key. Access to this key will allow a malicious user to invoke an IoTHub Registry Manager function which returns connection information for all Gardyn Home Kit and Studio devices. Access to this key also allows a malicious user to…
- risk 0.00cvss 9.9epss 0.01
Server-side request forgery (ssrf) in Microsoft Entra Provisioning Service (SyncFabric) allows an authorized attacker to elevate privileges over a network.
- risk 0.00cvss 9.9epss 0.01
Server-side request forgery (ssrf) in Azure OpenAI allows an authorized attacker to elevate privileges over a network.
- risk 0.00cvss 9.3epss 0.01
Url redirection to untrusted site ('open redirect') in M365 Copilot allows an unauthorized attacker to elevate privileges over a network.
- risk 0.54cvss 9.4epss 0.01
fast-mcp-telegram is a Telegram MCP Server. Prior to 0.19.1, fast-mcp-telegram validates HTTP Bearer tokens by joining the raw token string into a session-file path. The verifier rejects the exact reserved token telegram, but it does not reject path separators or normalize the…
- risk 0.52cvss 9.1epss 0.01
ardupilot through Plane-4.6.3 was found to contain an out-of-bounds read issue in libraries/GCS_MAVLink/GCS_serial_control.cpp in GCS_MAVLINK::handle_serial_control().
- risk 0.00cvss 9.8epss 0.01
ntopng through 6.6 is vulnerable to Predictable Session Identifier which can lead to Session Hijacking. HTTP session identifiers in src/HTTPserver.cpp use weak time-seeded pseudo-randomness during session creation. As a result, fresh authenticated logins can receive…
- risk 0.00cvss 9.1epss 0.01
Apereo CAS 7.3.0 before 8.0.0-RC6 contains a cryptographic vulnerability that allows remote unauthenticated attackers to recover plaintext conversation state by exploiting AES-GCM initialization vector reuse across the server lifetime. Attackers can collect multiple client-side…
- risk 0.00cvss 9.8epss 0.01
AutoBangumi before 3.2.8 contains a hard-coded default credentials vulnerability that allows unauthenticated attackers to authenticate as the administrator by using the publicly known default credentials seeded at startup via add_default_user() in the database user module when…
- risk 0.57cvss 9.9epss 0.00
Missing validation of "valuesFrom" references in Helm Deployer of SUSE Rancher Fleet 0.15 before 0.15.2, 0.14 before 0.14.6, 0.13 before 0.13.11 and 0.12 before 0.12.15 could be used by owners of one tenant to access fleet credentials of other tenants.
- risk 0.64cvss 9.8epss 0.01
Redsea Cloud eHR contains an arbitrary file upload vulnerability that allows unauthenticated attackers to achieve remote code execution by uploading malicious files through the PtFjk.mob servlet endpoint. Attackers can submit a multipart POST request with a JSP webshell…
- risk 0.00cvss 9.8epss 0.02
Yonyou KSOA 9.0 contains an unauthenticated arbitrary file upload vulnerability in the com.sksoft.bill.ImageUpload servlet that allows unauthenticated attackers to upload arbitrary files by submitting a POST request with attacker-controlled filepath and filename parameters…
- risk 0.00cvss 9.8epss 0.08
Dockwatch through 0.6.567 contains an unauthenticated OS command injection vulnerability that allows remote attackers to execute arbitrary shell commands by exploiting a missing exit() after an authentication redirect in loader.php combined with unsanitized input passed to…
- risk 0.00cvss 10.0epss 0.01
A shellcode injection in the mercurial handler of the obs tar_scm source service before version 0.12.4 could be used by attackers able to provide a _service file to execute code as the source service or the local user checking out the malicious services
- risk 0.00cvss 9.0epss 0.00
A malicious actor with access to the network and under certain network configurations could exploit an Improper Access Control vulnerability found in certain devices running UniFi OS to make unauthorized changes to such UniFi OS devices.
- risk 0.00cvss 9.9epss 0.00
A malicious actor with access to the network and low privileges could exploit a Server-Side Request Forgery (SSRF) in UniFi Protect Application to escalate privileges on the host device.
- risk 0.00cvss 9.9epss 0.02
A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi OS to execute a Command Injection on the host device.
- risk 0.59cvss 9.1epss 0.01
A malicious actor with access to the network and high privileges could exploit an Improper Access Control vulnerability found in UniFi Access Application to escalate privileges on the host device.
- risk 0.64cvss 9.9epss 0.02
A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi Access Application to execute a Command Injection on the host device.
- risk 0.00cvss 9.9epss 0.00
A malicious actor with access to the network and low privileges could exploit a series of authenticated SQL Injection vulnerabilities found in UniFi Talk Application to escalate privileges on the host device.
- risk 0.00cvss 10.0epss 0.02
A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi Connect Application to execute a Command Injection on the host device.
- risk 0.00cvss 9.8epss 0.01
Missing authentication for critical function vulnerability in TR7 Cyber Defense Inc. WAF-ASP allows Authentication Abuse. This issue affects WAF-ASP: from v1.0.324.900 before v1.4.0.117.
- risk 0.00cvss 9.8epss 0.03
The Divi Form Builder plugin for WordPress is vulnerable to Arbitrary File Upload leading to Remote Code Execution in all versions up to and including 5.1.8. This is due to insufficient file extension validation in the do_image_upload() function where user-supplied input from…
- risk 0.00cvss 9.3epss 0.00
Unauthenticated SQL Injection in WP Fast Total Search <= 1.80.280 versions.
- risk 0.00cvss 9.3epss 0.00
Unauthenticated SQL Injection in GeekyBot <= 1.2.5 versions.
- risk 0.00cvss 9.8epss 0.01
Unauthenticated PHP Object Injection in Novalnet Payment Gateway for WooCommerce <= 12.10.3 versions.
- risk 0.00cvss 9.6epss 0.00
Unauthenticated Cross Site Scripting (XSS) in Admin and Site Enhancements (ASE) Pro <= 8.8.5 versions.
- risk 0.00cvss 10.0epss 0.01
Unauthenticated Remote Code Execution (RCE) in Blocksy Companion Pro <= 2.1.46 versions.
- risk 0.00cvss 9.0epss 0.01
Unauthenticated Arbitrary Code Execution in W3 Total Cache <= 2.9.4 versions.
- risk 0.00cvss 9.8epss 0.01
Unauthenticated PHP Object Injection in Booktics <= 1.0.21 versions.
- risk 0.00cvss 9.1epss 0.01
Editor Arbitrary Code Execution in Five Star Business Profile and Schema <= 2.3.19 versions.
- risk 0.00cvss 9.9epss 0.00
Subscriber Arbitrary File Upload in Zegen <= 1.1.9 versions.
- risk 0.00cvss —epss 0.01
A path traversal vulnerability exists in the Git Service component shared by Altium Enterprise Server and Altium 365. The service accepts a sequence of post-clone file-manipulation operations that use user-supplied paths without validation, allowing an authenticated user with…
- risk 0.00cvss 9.6epss 0.00
Use after free in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
- risk 0.00cvss 9.6epss 0.00
Use after free in Dawn in Google Chrome on Mac prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
- risk 0.00cvss 9.6epss 0.00
Type Confusion in Tint in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
- risk 0.00cvss 9.6epss 0.00
Out of bounds read and write in Dawn in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
- risk 0.00cvss 9.6epss 0.00
Use after free in Skia in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
- risk 0.00cvss 9.6epss 0.00
Use after free in Dawn in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
- risk 0.00cvss 9.6epss 0.00
Out of bounds read in Dawn in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low)
- risk 0.00cvss 9.6epss 0.00
Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
- risk 0.00cvss 9.6epss 0.01
Uninitialized Use in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Low)
- risk 0.00cvss 9.6epss 0.00
Use after free in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
- risk 0.00cvss 9.6epss 0.00
Out of bounds write in ANGLE in Google Chrome on Mac prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)