CVEs from 2026
Total
14,691
critical
critical 1,318
high
high 4,976
medium
medium 4,752
low
low 501
% Critical
9.0%
% with KEV
0.4%
% with exploit
0.7%
Top vendors
Top products
- chrome 621
- firepower_threat_defense_software 310
- gcp 299
- firepower_threat_defense 298
- openclaw 172
- commerce 104
- netweaver_application_server_abap 102
- commerce_b2b 89
Top packages
| CVE | Severity | CVSS | Risk | Flags | OS | Vendor | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-43172 | high | 8.8 | 8.8 | 1mo ago | In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: fix 22000 series SMEM parsing If the firmware were to report three LMACs (which doesn't exist in hardware) then us… | |||
| CVE-2026-43158 | high | 8.8 | 8.8 | 1mo ago | In the Linux kernel, the following vulnerability has been resolved: xfs: fix freemap adjustments when adding xattrs to leaf blocks xfs/592 and xfs/794 both trip this assertion in the leaf block fre… | |||
| CVE-2026-43113 | high | 8.8 | 8.8 | 1mo ago | In the Linux kernel, the following vulnerability has been resolved: wifi: wl1251: validate packet IDs before indexing tx_frames wl1251_tx_packet_cb() uses the firmware completion ID directly to ind… | |||
| CVE-2026-43112 | high | 8.8 | 8.8 | 1mo ago | In the Linux kernel, the following vulnerability has been resolved: fs/smb/client: fix out-of-bounds read in cifs_sanitize_prepath When cifs_sanitize_prepath is called with an empty string or a str… | |||
| CVE-2026-43110 | high | 8.8 | 8.8 | 1mo ago | In the Linux kernel, the following vulnerability has been resolved: wifi: brcmfmac: validate bsscfg indices in IF events brcmf_fweh_handle_if_event() validates the firmware-provided interface index… | |||
| CVE-2026-7841 | high | 8.8 | 8.8 | 1mo ago | A remote code execution vulnerability exists in Notification Settings on GeoVision GV-ASWeb 6.2.0. An authenticated user with System Setting permissions can execute arbitrary commands on the server b… | |||
| CVE-2026-42843 | high | 8.8 | 8.8 | 1mo ago | Grav API Privilege Escalation to Super Admin | |||
| CVE-2026-40068 | high | 8.8 | 8.8 | 1mo ago | Claude Code: Trust Dialog Bypass via Git Worktree Spoofing Allows Arbitrary Code Execution | |||
| CVE-2026-39849 | high | 8.8 | 8.8 | 1mo ago | Pi-hole FTL is the core engine of the Pi-hole network-level advertisement and tracker blocker. In versions before 6.6.1, the `dns.interface` configuration field in Pi-hole FTL accepted newline charac… | |||
| CVE-2026-42266 | high | 8.8 | 8.8 | 1mo ago | JupyterLab has an Extension Manager API/GUI Policy Discrepancy, allowing 3rd party (malicious) extensions install via POST request | |||
| CVE-2026-34464 | high | 8.8 | 8.8 | 1mo ago | Sandboxie-Plus is an open source sandbox-based isolation software for Windows. In versions 1.17.2 and earlier, NamedPipeServer::OpenHandler copies the server field from NAMED_PIPE_OPEN_REQ into a fix… | |||
| CVE-2026-34459 | high | 8.8 | 8.8 | 1mo ago | Sandboxie-Plus is an open source sandbox-based isolation software for Windows. In versions 1.17.2 and earlier, the SbieSvc proxy service's GetRawInputDeviceInfoSlave handler contains two vulnerabilit… | |||
| CVE-2026-34458 | high | 8.8 | 8.8 | 1mo ago | Sandboxie-Plus is an open source sandbox-based isolation software for Windows. In versions 1.17.2 and earlier, an INI injection vulnerability allows any standard local user to bypass configuration re… | |||
| CVE-2026-33324 | high | 8.8 | 8.8 | 1mo ago | SQLBot is an intelligent Text-to-SQL system based on large language models and RAG. In versions 1.7.0 and earlier, the Text2SQL chat interface is vulnerable to prompt injection. The user-provided que… | |||
| CVE-2026-25589 | high | 8.8 | 8.8 | 1mo ago | RedisBloom is a probabilistic data structures module for Redis. In all versions of RedisBloom before 2.8.20, the module does not properly validate serialized values processed through the Redis RESTOR… | |||
| CVE-2026-25588 | high | 8.8 | 8.8 | 1mo ago | RedisTimeSeries is a time-series module for Redis. In all versions before 1.12.14 of RedisTimeSeries, the module does not properly validate serialized values processed through the Redis RESTORE comma… | |||
| CVE-2026-25243 | high | 8.8 | 8.8 | 1mo ago | RHSA-2026:23229: redis security update (Important) | |||
| CVE-2026-23479 | high | 8.8 | 8.8 | 1mo ago | Redis is an in-memory data structure store. In redis-server from 7.2.0 until 8.6.3, the unblock client flow does not handle an error return from `processCommandAndResetClient` when re-executing a blo… | |||
| CVE-2026-35397 | high | 8.8 | 8.8 | 1mo ago | Jupyter Server is the backend for Jupyter web applications. In versions 2.17.0 and earlier, a path traversal vulnerability in the REST API allows an authenticated user to escape the configured root_d… | |||
| CVE-2026-31196 | high | 8.8 | 8.8 | 1mo ago | The traceroute diagnostic handler in /bin/httpd_clientside for ALTICE LABS / SFR France GR140DG and GR140IG fibre CPE/Router/Gateway, inserts unsanitized user input into a system() call, allowing aut… | |||
| CVE-2026-31195 | high | 8.8 | 8.8 | 1mo ago | The ping diagnostic handler in /bin/httpd_clientside for ALTICE LABS / SFR France GR140DG and GR140IG fibre CPE/Router/Gateway, inserts unsanitized user input into a system() call, allowing authentic… | |||
| CVE-2026-6261 | high | 8.8 | 8.8 | 1mo ago | The Betheme theme for WordPress is vulnerable to Arbitrary File Upload in versions up to, and including, 28.4. This is due to the upload_icons() function workflow moving and unzipping user-controlled… | |||
| CVE-2026-43571 | high | 8.8 | 8.8 | 1mo ago | OpenClaw: Channel setup catalog lookups could include untrusted workspace plugin shadows | |||
| CVE-2026-43569 | high | 8.8 | 8.8 | 1mo ago | OpenClaw: Workspace provider auth choices could auto-enable untrusted provider plugins | |||
| CVE-2026-43531 | high | 8.8 | 8.8 | 1mo ago | OpenClaw: Workspace .env could inject OpenClaw runtime-control variables | |||
| CVE-2026-43530 | high | 8.8 | 8.8 | 1mo ago | OpenClaw: busybox and toybox applet execution weakened exec approval binding | |||
| CVE-2026-42435 | high | 8.8 | 8.8 | 1mo ago | OpenClaw: Shell-wrapper detection missed env-argv assignment injection forms | |||
| CVE-2026-42434 | high | 8.8 | 8.8 | 1mo ago | OpenClaw: Sandboxed agents could escape exec routing via host=node override | |||
| CVE-2026-42606 | high | 8.8 | 8.8 | 1mo ago | AzuraCast has Password Reset Poisoning via Untrusted X-Forwarded-Host Header that Leads to Account Takeover and 2FA Bypass | |||
| CVE-2026-42605 | high | 8.8 | 8.8 | 1mo ago | AzuraCast has Path Traversal in `currentDirectory` Parameter that Enables Remote Code Execution via Media Upload | |||
| CVE-2026-42237 | high | 8.8 | 8.8 | 1mo ago | n8n has SQL Injection in Snowflake and MySQL Nodes | |||
| CVE-2026-42234 | high | 8.8 | 8.8 | 1mo ago | n8n has a Python Task Runner Sandbox Escape Vulnerability | |||
| CVE-2026-42232 | high | 8.8 | 8.8 | 1mo ago | n8n has XML Node Prototype Pollution that to RCE | |||
| CVE-2026-42231 | high | 8.8 | 8.8 | 1mo ago | n8n has Prototype Pollution in XML Webhook Body Parser that Leads to RCE | |||
| CVE-2026-42229 | high | 8.8 | 8.8 | 1mo ago | n8n has SQL Injection in SeaTable Node | |||
| CVE-2026-0073 | high | 8.8 | 8.8 | 1mo ago | In adbd_tls_verify_cert of auth.cpp, there is a possible bypass of wireless ADB mutual authentication due to a logic error in the code. This could lead to remote (proximal/adjacent) code execution as… | |||
| CVE-2026-42375 | high | 8.8 | 8.8 | 1mo ago | D-Link DIR-600L Hardware Revision A1 (End-of-Life) contains a hardcoded telnet backdoor. The device starts a telnet daemon at boot via /bin/telnetd.sh with the username "Alphanetworks" and the static… | |||
| CVE-2026-42374 | high | 8.8 | 8.8 | 1mo ago | D-Link DIR-600L Hardware Revision B1 (End-of-Life) contains a hardcoded telnet backdoor. The device starts a telnet daemon at boot via /bin/telnetd.sh with the username "Alphanetworks" and the static… | |||
| CVE-2026-42373 | high | 8.8 | 8.8 | 1mo ago | D-Link DIR-605L Hardware Revision B2 (End-of-Life, EOL) contains a hardcoded telnet backdoor. The device starts a telnet daemon at boot via /bin/telnetd.sh with the username "Alphanetworks" and the s… | |||
| CVE-2026-42372 | high | 8.8 | 8.8 | 1mo ago | D-Link DIR-605L Hardware Revision A1 (End-of-Life, EOL) contains a hardcoded telnet backdoor. The device starts a telnet daemon at boot via /bin/telnetd.sh with the username "Alphanetworks" and the s… | |||
| CVE-2026-29514 | high | 8.8 | 8.8 | 1mo ago | NetBox versions 4.3.5 through 4.5.4 contain a remote code execution vulnerability in the RenderTemplateMixin.get_environment_params() method that allows authenticated users with exporttemplate or con… | |||
| CVE-2026-24072 | high | 8.8 | 8.8 | 1mo ago | An escalation of privilege bug in various modules in Apache HTTP 2.4.66 and earlier allows local .htaccess authors to read files with the privileges of the httpd user. Users are recommended to upgra… | |||
| CVE-2026-7750 | high | 8.8 | 8.8 | 1mo ago | A vulnerability was detected in Totolink N300RH 3.2.4-B20220812. This vulnerability affects the function setMacFilterRules of the file /cgi-bin/cstecgi.cgi of the component POST Request Handler. The … | |||
| CVE-2026-7749 | high | 8.8 | 8.8 | 1mo ago | A security vulnerability has been detected in Totolink N300RH 3.2.4-B20220812. This affects the function setWanConfig of the file /cgi-bin/cstecgi.cgi of the component POST Request Handler. The manip… | |||
| CVE-2026-7748 | high | 8.8 | 8.8 | 1mo ago | A weakness has been identified in Totolink N300RH 3.2.4-B20220812. Affected by this issue is the function setUpgradeFW of the file /cgi-bin/cstecgi.cgi of the component POST Request Handler. Executin… | |||
| CVE-2026-7717 | high | 8.8 | 8.8 | 1mo ago | A vulnerability was determined in Totolink WA300 5.2cu.7112_B20190227. This issue affects the function UploadCustomModule of the file /cgi-bin/cstecgi.cgi of the component POST Request Handler. Execu… | |||
| CVE-2026-42364 | high | 8.8 | 8.8 | 1mo ago | An os command injection vulnerability exists in the DdnsSetting.cgi functionality of GeoVision LPC2011/LPC2211 1.10. A specially crafted DDNS configuration can lead to arbitrary command execution. An… | |||
| CVE-2026-7685 | high | 8.8 | 8.8 | 1mo ago | A vulnerability was detected in Edimax BR-6208AC up to 1.02. Affected is an unknown function of the file /goform/setWAN. Performing a manipulation of the argument pptpDfGateway results in buffer ove… | |||
| CVE-2026-7684 | high | 8.8 | 8.8 | 1mo ago | A security vulnerability has been detected in Edimax BR-6428nC up to 1.16. This impacts an unknown function of the file /goform/setWAN. Such manipulation of the argument pptpDfGateway leads to buffe… | |||
| CVE-2026-7675 | high | 8.8 | 8.8 | 1mo ago | A vulnerability has been found in Shenzhen Libituo Technology LBT-T300-HW1 up to 1.2.8. Impacted is the function start_lan of the file /apply.cgi. The manipulation of the argument Channel/ApCliSsid l… | |||
| CVE-2026-7674 | high | 8.8 | 8.8 | 1mo ago | A flaw has been found in Shenzhen Libituo Technology LBT-T300-HW1 up to 1.2.8. This issue affects the function start_single_service of the component Web Management Interface. Executing a manipulation… | |||
| CVE-2026-7609 | high | 8.8 | 8.8 | 1mo ago | A flaw has been found in TRENDnet TEW-821DAP up to 1.12B01. The impacted element is the function tools_diagnostic of the file /tmp/diagnostic of the component Firmware Udpate. This manipulation cause… | |||
| CVE-2026-7489 | high | 8.8 | 8.8 | 1mo ago | CTMS developed by Sunnet has a SQL Injection vulnerability, allowing authenticated remote attackers to inject arbitrary SQL commands to read, modify, and delete database contents. | |||
| CVE-2026-7607 | high | 8.8 | 8.8 | 1mo ago | A security vulnerability has been detected in TRENDnet TEW-821DAP 1.12B01. Impacted is the function auto_update_firmware of the component Firmware Udpate. The manipulation of the argument str leads t… | |||
| CVE-2026-2052 | high | 8.8 | 8.8 | 1mo ago | The Widget Options – Advanced Conditional Visibility for Gutenberg Blocks & Classic Widgets plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 4.2.2 via… | |||
| CVE-2026-7641 | high | 8.8 | 8.8 | 1mo ago | The Import and export users and customers plugin for WordPress is vulnerable to Privilege Escalation in all versions up to and including 2.0.8 via the `save_extra_user_profile_fields()` function. Thi… | |||
| CVE-2026-6963 | high | 8.8 | 8.8 | 1mo ago | The WP Mail Gateway plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the wmg_save_provider_config AJAX action in all versions up to, and including, 1.8. … | |||
| CVE-2026-42468 | high | 8.8 | 8.8 | 1mo ago | Buffer overflow vulnerability in Open Vehicle Monitoring System 3 (OVMS3) 3.3.005. In canformat_pcap.cpp , the parser's phdr.len field is not properly validated, allowing remote attackers to cause a … | |||
| CVE-2026-37536 | high | 8.8 | 8.8 | 1mo ago | miaofng/uds-c commit e506334e270d77b20c0bc259ac6c7d8c9b702b7a (2016-10-05) contains a stack buffer overflow in send_diagnostic_request. A 6-byte stack buffer (MAX_DIAGNOSTIC_PAYLOAD_SIZE=6) receives … | |||
| CVE-2026-43048 | high | 8.8 | 8.8 | 1mo ago | In the Linux kernel, the following vulnerability has been resolved: HID: core: Mitigate potential OOB by removing bogus memset() The memset() in hid_report_raw_event() has the good intention of cle… | |||
| CVE-2026-43018 | high | 8.8 | 8.8 | 1mo ago | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_event: fix potential UAF in hci_le_remote_conn_param_req_evt hci_conn lookup and field access must be covered by h… | |||
| CVE-2026-31773 | high | 8.8 | 8.8 | 1mo ago | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: SMP: derive legacy responder STK authentication from MITM state The legacy responder path in smp_random() currently la… | |||
| CVE-2026-31739 | high | 8.8 | 8.8 | 1mo ago | In the Linux kernel, the following vulnerability has been resolved: crypto: tegra - Add missing CRYPTO_ALG_ASYNC The tegra crypto driver failed to set the CRYPTO_ALG_ASYNC on its asynchronous algor… | |||
| CVE-2026-31735 | high | 8.8 | 8.8 | 1mo ago | In the Linux kernel, the following vulnerability has been resolved: iommupt: Fix short gather if the unmap goes into a large mapping unmap has the odd behavior that it can unmap more than requested… | |||
| CVE-2026-31717 | high | 8.8 | 8.8 | 1mo ago | In the Linux kernel, the following vulnerability has been resolved: ksmbd: validate owner of durable handle on reconnect Currently, ksmbd does not verify if the user attempting to reconnect to a du… | |||
| CVE-2026-31709 | high | 8.8 | 8.8 | 1mo ago | In the Linux kernel, the following vulnerability has been resolved: smb: client: validate the whole DACL before rewriting it in cifsacl build_sec_desc() and id_mode_to_cifs_acl() derive a DACL poin… | |||
| CVE-2026-31706 | high | 8.8 | 8.8 | 1mo ago | In the Linux kernel, the following vulnerability has been resolved: ksmbd: validate num_aces and harden ACE walk in smb_inherit_dacl() smb_inherit_dacl() trusts the on-disk num_aces value from the … | |||
| CVE-2026-3772 | high | 8.8 | 8.8 | 1mo ago | The WP Editor plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2.9.2. This is due to missing nonce verification in the 'add_plugins_page' and '… | |||
| CVE-2026-7548 | high | 8.8 | 8.8 | 1mo ago | A vulnerability was detected in Totolink NR1800X 9.1.0u.6279_B20210910. This affects the function sub_41A68C of the file /cgi-bin/cstecgi.cgi. Performing a manipulation of the argument setUssd result… | |||
| CVE-2026-7513 | high | 8.8 | 8.8 | 1mo ago | A vulnerability has been found in UTT HiPER 1200GW up to 2.5.3-170306. The impacted element is the function strcpy of the file /goform/formRemoteControl. The manipulation leads to buffer overflow. Th… | |||
| CVE-2026-7512 | high | 8.8 | 8.8 | 1mo ago | A flaw has been found in UTT HiPER 1200GW up to 2.5.3-1703. The affected element is the function strcpy of the file /goform/formUser. Executing a manipulation can lead to buffer overflow. The attack … | |||
| CVE-2026-7551 | high | 8.8 | 8.8 | 1mo ago | HKUDS OpenHarness contains a remote code execution vulnerability in the /bridge slash command that allows remote senders accepted by configuration to execute arbitrary operating system commands. Atta… | |||
| CVE-2026-7503 | high | 8.8 | 8.8 | 1mo ago | A vulnerability was detected in code-projects for Plugin 4.1.2cu.5137. The impacted element is the function setWiFiMultipleConfig in the library /lib/cste_modules/wireless.so of the file /cgi-bin/cst… | |||
| CVE-2026-6543 | high | 8.8 | 8.8 | 1mo ago | IBM Langflow Desktop 1.0.0 through 1.8.4 Langflow allows an attacker to execute arbitrary commands with the privileges of the process running Langflow. This allows reading sensitive environment varia… | |||
| CVE-2026-36765 | high | 8.8 | 8.8 | 1mo ago | An XML external entity (XXE) vulnerability in the /designer/loadReport endpoint of SpringBlade v4.8.0 allows authenticated attackers to execute arbitrary code via injecting a crafted payload. | |||
| CVE-2026-36762 | high | 8.8 | 8.8 | 1mo ago | An issue in the fileEntityId parameter in the /a/file/upload endpoint of JeeSite v5.15.1 allows authenticated attackers with file upload permissions to execute a path traversal and write arbitrary fi… | |||
| CVE-2026-5174 | high | 8.8 | 8.8 | 1mo ago | Improper input validation vulnerability in Progress Software MOVEit Automation allows Privilege Escalation. This issue affects MOVEit Automation: from 2025.1.0 before 2025.1.5, from 2025.0.0 before … | |||
| CVE-2026-36960 | high | 8.8 | 8.8 | 1mo ago | A Cross-Site Request Forgery (CSRF) vulnerability exists in the web management interface of the U-SPEED N300 Rounter V1.0.0. The device does not implement CSRF protection mechanisms such as anti-CSRF… | |||
| CVE-2026-36956 | high | 8.8 | 8.8 | 1mo ago | A Cross-Site Request Forgery (CSRF) vulnerability exists in the web management interface of the Dbit N300 T1 Pro wireless router V1.0.0. The router fails to implement proper CSRF protection mechanism… | |||
| CVE-2026-5402 | high | 8.8 | 8.8 | 1mo ago | TLS protocol dissector heap overflow in Wireshark 4.6.0 to 4.6.4 allows denial of service and possible code execution | |||
| CVE-2026-7470 | high | 8.8 | 8.8 | 1mo ago | A flaw has been found in Tenda 4G300 US_4G300V1.0Mt_V1.01.42_CN_TDC01. Affected is the function sub_427C3C of the file /goform/SafeMacFilter. This manipulation of the argument page causes stack-based… | |||
| CVE-2026-7420 | high | 8.8 | 8.8 | 1mo ago | A security flaw has been discovered in UTT HiPER 1250GW up to 3.2.7-210907-180535. Impacted is the function strcpy of the file route/goform/ConfigAdvideo. The manipulation of the argument Profile res… | |||
| CVE-2026-7419 | high | 8.8 | 8.8 | 1mo ago | A vulnerability was identified in UTT HiPER 1250GW up to 3.2.7-210907-180535. This issue affects the function strcpy of the file route/goform/formTaskEdit_ap. The manipulation of the argument Profile… | |||
| CVE-2026-7418 | high | 8.8 | 8.8 | 1mo ago | A vulnerability was determined in UTT HiPER 1250GW up to 3.2.7-210907-180535. This vulnerability affects the function strcpy of the file route/goform/NTP. Executing a manipulation of the argument Pro… | |||
| CVE-2026-34965 | high | 8.8 | 8.8 | 1mo ago | Cockpit CMS contains an authenticated remote code execution vulnerability in the /cockpit/collections/save_collection endpoint that allows authenticated attackers with collection management privilege… | |||
| CVE-2026-7466 | high | 8.8 | 8.8 | 1mo ago | AgentFlow contains an arbitrary code execution vulnerability that allows attackers to execute local Python pipeline files by supplying a user-controlled pipeline_path parameter to the POST /api/runs … | |||
| CVE-2026-38991 | high | 8.8 | 8.8 | 1mo ago | Cockpit Vulnerable to Unrestricted Upload of File with Dangerous Type | |||
| CVE-2026-5712 | high | 8.8 | 8.8 | 1mo ago | This vulnerability impacts all versions of IdentityIQ and allows an authenticated identity that is the requestor or assignee of a work item to edit the definition of a role without having an assigned… | |||
| CVE-2026-6849 | high | 8.8 | 8.8 | 1mo ago | Improper neutralization of special elements used in an OS command ('OS command injection') vulnerability in TUBITAK BILGEM Software Technologies Research Institute Pardus OS My Computer allows OS Com… | |||
| CVE-2026-5161 | high | 8.8 | 8.8 | 1mo ago | Improper link resolution before file access ('link following') vulnerability in TUBITAK BILGEM Software Technologies Research Institute Pardus About allows Symlink Attack. This issue affects Pardus … | |||
| CVE-2026-5141 | high | 8.8 | 8.8 | 1mo ago | Improper Privilege Management, Improper Access Control, Incorrect privilege assignment vulnerability in TUBITAK BILGEM Software Technologies Research Institute Pardus Software Center allows Hijacking… | |||
| CVE-2026-5140 | high | 8.8 | 8.8 | 1mo ago | Improper neutralization of CRLF sequences ('CRLF injection') vulnerability in TUBITAK BILGEM Software Technologies Research Institute Pardus Update allows Authentication Bypass. This issue affects P… | |||
| CVE-2026-41651 | high | 8.8 | 8.8 | 1mo ago | Important: PackageKit security update | |||
| CVE-2026-7363 | high | 8.8 | 8.8 | 1mo ago | Use after free in Canvas in Google Chrome on Linux, ChromeOS prior to 147.0.7727.138 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security s… | |||
| CVE-2026-7361 | high | 8.8 | 8.8 | 1mo ago | Use after free in iOS in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical) | |||
| CVE-2026-7359 | high | 8.8 | 8.8 | 1mo ago | Use after free in ANGLE in Google Chrome prior to 147.0.7727.138 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (C… | |||
| CVE-2026-7358 | high | 8.8 | 8.8 | 1mo ago | Use after free in Animation in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) | |||
| CVE-2026-7356 | high | 8.8 | 8.8 | 1mo ago | Use after free in Navigation in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High) | |||
| CVE-2026-7355 | high | 8.8 | 8.8 | 1mo ago | Use after free in Media in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium) | |||
| CVE-2026-7354 | high | 8.8 | 8.8 | 1mo ago | Out of bounds read and write in Angle in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: … |