|
2801
|
4.9 |
MEDIUM
Network
|
acer
|
connect_m6e_5g_firmware
|
The web administration panel binds broadly to the public IPv6 address space on port [::]:8080 without default firewall limits, making internal API endpoints reachable over the WAN.
|
CWE-200
Information Exposure
|
CVE-2026-50224
|
2026-06-8 21:58 |
2026-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2802
|
9.1 |
CRITICAL
Network
|
acer
|
connect_m6e_5g_firmware
|
The registration path /v1/account/register provides no bot mitigation mechanisms, allowing malicious automated systems to flood the database.
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2026-50225
|
2026-06-8 21:58 |
2026-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2803
|
5.3 |
MEDIUM
Network
|
acer
|
connect_m6e_5g_firmware
|
Fixed AES-128-CBC keys inside the AcerConnect OTA application let attackers forge authorization credentials for arbitrary IMEI numbers. This allows unauthorized actors to list catalog items and extra…
|
CWE-321
Use of Hard-coded Cryptographic Key
|
CVE-2026-50226
|
2026-06-8 21:57 |
2026-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2804
|
9.8 |
CRITICAL
Network
|
acer
|
connect_m6e_5g_firmware
|
The /v1/Plan service relies entirely on a shared global API token for full administrative management, allowing arbitrary creation of zero-cost network access plans.
|
CWE-345
Insufficient Verification of Data Authenticity
|
CVE-2026-50214
|
2026-06-8 21:56 |
2026-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2805
|
- |
-
|
-
|
-
|
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
|
-
|
CVE-2024-56123
|
2026-06-8 19:16 |
2026-06-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2806
|
- |
-
|
-
|
-
|
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
|
-
|
CVE-2024-56122
|
2026-06-8 19:16 |
2026-06-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2807
|
- |
-
|
-
|
-
|
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
|
-
|
CVE-2024-56121
|
2026-06-8 19:16 |
2026-06-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2808
|
- |
-
|
-
|
-
|
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
|
-
|
CVE-2024-56120
|
2026-06-8 19:16 |
2026-06-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2809
|
- |
-
|
-
|
-
|
Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.
|
-
|
CVE-2026-36229
|
2026-06-7 06:16 |
2026-06-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2810
|
6.5 |
MEDIUM
Network
|
-
|
-
|
A missing upper-bound check in the udpif_set_threads() function of Open vSwitch v3.6.90 allows an attacker with OVSDB write access to request an excessive number of handler or revalidation threads. T…
|
CWE-770
Allocation of Resources Without Limits or Throttling
|
CVE-2026-36499
|
2026-06-7 05:16 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2811
|
8.3 |
HIGH
Network
|
google
|
chrome
|
Use after free in Autofill in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. …
|
CWE-416
Use After Free
|
CVE-2026-11002
|
2026-06-7 03:16 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2812
|
4.2 |
MEDIUM
Network
|
google
|
chrome
|
Inappropriate implementation in Payments in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted …
|
CWE-290 CWE-451
Authentication Bypass by Spoofing User Interface (UI) Misrepresentation of Critical Information
|
CVE-2026-11001
|
2026-06-7 02:16 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2813
|
6.5 |
MEDIUM
Network
|
google
|
chrome
|
Uninitialized Use in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium securit…
|
CWE-457
Use of Uninitialized Variable
|
CVE-2026-10994
|
2026-06-7 02:16 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2814
|
6.5 |
MEDIUM
Network
|
google
|
chrome
|
Heap buffer overflow in Skia in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium secur…
|
CWE-122
Heap-based Buffer Overflow
|
CVE-2026-10993
|
2026-06-7 02:16 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2815
|
6.5 |
MEDIUM
Network
|
google
|
chrome
|
Insufficient data validation in Animation in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (C…
|
NVD-CWE-noinfo CWE-20
Improper Input Validation
|
CVE-2026-10992
|
2026-06-7 02:16 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2816
|
8.3 |
HIGH
Network
|
google
|
chrome
|
Use after free in Glic in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chr…
|
CWE-416
Use After Free
|
CVE-2026-10990
|
2026-06-7 02:16 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2817
|
5.9 |
MEDIUM
Network
|
google
|
chrome
|
Inappropriate implementation in WebRTC in Google Chrome prior to 149.0.7827.53 allowed an attacker in a privileged network position to leak cross-origin data via malicious network traffic. (Chromium …
|
CWE-20
Improper Input Validation
|
CVE-2026-11199
|
2026-06-6 22:16 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2818
|
8.3 |
HIGH
Network
|
google
|
chrome
|
Insufficient validation of untrusted input in Printing in Google Chrome on Windows prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a s…
|
CWE-20
Improper Input Validation
|
CVE-2026-10971
|
2026-06-6 22:16 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2819
|
8.8 |
HIGH
Network
|
google
|
chrome
|
Inappropriate implementation in Isolated Web Apps in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a malicious file. (Chromium security…
|
NVD-CWE-noinfo CWE-474
Use of Function with Inconsistent Implementations
|
CVE-2026-11102
|
2026-06-6 13:17 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2820
|
5.5 |
MEDIUM
Local
|
samsung
|
android
|
Improper handling of insufficient privileges in SecTelephonyProvider prior to SMR Jun-2026 Release 1 allows local attackers to access privileged files.
|
NVD-CWE-Other
|
CVE-2026-21017
|
2026-06-6 11:01 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2821
|
5.5 |
MEDIUM
Local
|
samsung
|
android
|
Incorrect privilege assignment in Telephony prior to SMR Jun-2026 Release 1 allows local attackers to access sensitive information.
|
NVD-CWE-Other
|
CVE-2026-21025
|
2026-06-6 11:01 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2822
|
5.5 |
MEDIUM
Local
|
samsung
|
android
|
Improper export of android application components in SpriteWallpaper prior to SMR Jun-2026 Release 1 allows local attackers to access to sensitive information.
|
NVD-CWE-Other
|
CVE-2026-21026
|
2026-06-6 11:00 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2823
|
3.3 |
LOW
Local
|
samsung
|
android
|
Improper export of android application components in ImsSettings prior to SMR Jun-2026 Release 1 allows local attackers to trigger logging function.
|
NVD-CWE-Other
|
CVE-2026-21027
|
2026-06-6 11:00 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2824
|
5.5 |
MEDIUM
Local
|
samsung
|
android
|
Improper access control in AuditLogService prior to SMR Jun-2026 Release 1 allows local attackers to access sensitive information.
|
NVD-CWE-noinfo
|
CVE-2026-21028
|
2026-06-6 11:00 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2825
|
7.8 |
HIGH
Local
|
samsung
|
android
|
Improper export of android application components in Galaxy Editing Service prior to SMR Jun-2026 Release 1 allows local attacker to execute privileged operations.
|
NVD-CWE-Other
|
CVE-2026-21029
|
2026-06-6 11:00 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2826
|
7.8 |
HIGH
Local
|
samsung
|
android
|
Improper access control in MediaTek Audio HAL prior to SMR Jun-2026 Release 1 allows local attackers to trigger privileged functions.
|
NVD-CWE-noinfo
|
CVE-2026-21030
|
2026-06-6 11:00 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2827
|
7.8 |
HIGH
Local
|
samsung
|
android
|
Improper authorization in AppBlock prior to SMR Jun-2026 Release 1 allows local attacker to launch arbitrary activity. User interaction is required for triggering this vulnerability.
|
CWE-863
Incorrect Authorization
|
CVE-2026-21031
|
2026-06-6 10:59 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2828
|
6.5 |
MEDIUM
Network
|
google
|
chrome
|
Inappropriate implementation in Signin in Google Chrome on iOS prior to 149.0.7827.53 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity:…
|
CWE-284
Improper Access Control
|
CVE-2026-11204
|
2026-06-6 10:59 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2829
|
6.5 |
MEDIUM
Network
|
google
|
chrome
|
Insufficient policy enforcement in ServiceWorker in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medi…
|
CWE-693
Protection Mechanism Failure
|
CVE-2026-11206
|
2026-06-6 10:59 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2830
|
9.6 |
CRITICAL
Network
|
google
|
chrome
|
Insufficient validation of untrusted input in Autofill in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially perform a sandbox escape via malicious network traffic. (Chromi…
|
CWE-20
Improper Input Validation
|
CVE-2026-11207
|
2026-06-6 10:59 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2831
|
6.5 |
MEDIUM
Network
|
google
|
chrome
|
Use after free in Codecs in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security …
|
CWE-416
Use After Free
|
CVE-2026-11208
|
2026-06-6 10:58 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2832
|
6.5 |
MEDIUM
Network
|
google
|
chrome
|
Inappropriate implementation in Passwords in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from p…
|
CWE-200
Information Exposure
|
CVE-2026-11209
|
2026-06-6 10:58 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2833
|
6.5 |
MEDIUM
Network
|
google
|
chrome
|
Inappropriate implementation in Safe Browsing in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to bypass discretionary access control via a crafted RAR file. (Chromium security sever…
|
CWE-284
Improper Access Control
|
CVE-2026-11210
|
2026-06-6 10:58 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2834
|
4.3 |
MEDIUM
Network
|
google
|
chrome
|
Insufficient policy enforcement in DevTools in Google Chrome prior to 149.0.7827.53 allowed an attacker who convinced a user to install a malicious extension to leak cross-origin data via a crafted C…
|
CWE-284
Improper Access Control
|
CVE-2026-11212
|
2026-06-6 10:58 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2835
|
6.5 |
MEDIUM
Network
|
google
|
chrome
|
Inappropriate implementation in WebUI in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to perform domain spoofing via a crafted domain name. (Chromium security severity: Low)
|
CWE-451
User Interface (UI) Misrepresentation of Critical Information
|
CVE-2026-11225
|
2026-06-6 10:57 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2836
|
6.5 |
MEDIUM
Network
|
google
|
chrome
|
Insufficient policy enforcement in PreviewTab in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker who convinced a user to engage in specific UI gestures to bypass same origin…
|
CWE-346
Origin Validation Error
|
CVE-2026-11226
|
2026-06-6 10:57 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2837
|
6.5 |
MEDIUM
Network
|
google
|
chrome
|
Incorrect security UI in Tab Hover Cards in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to perform domain spoofing via a crafted domain name. (Chromium security severity: Low)
|
CWE-451
User Interface (UI) Misrepresentation of Critical Information
|
CVE-2026-11227
|
2026-06-6 10:57 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2838
|
8.8 |
HIGH
Network
|
google
|
chrome
|
Use after free in WebRTC in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
|
CWE-416
Use After Free
|
CVE-2026-10939
|
2026-06-6 10:56 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2839
|
8.8 |
HIGH
Network
|
google
|
chrome
|
Use after free in Chrome for iOS in Google Chrome on iOS prior to 149.0.7827.53 allowed a remote attacker who convinced a user to engage in specific UI gestures to execute arbitrary code via a crafte…
|
CWE-416
Use After Free
|
CVE-2026-10958
|
2026-06-6 10:56 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2840
|
8.8 |
HIGH
Network
|
google
|
chrome
|
Use after free in Input in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: H…
|
CWE-416
Use After Free
|
CVE-2026-10959
|
2026-06-6 10:56 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2841
|
8.8 |
HIGH
Network
|
google
|
chrome
|
Use after free in WebRTC in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)
|
CWE-416
Use After Free
|
CVE-2026-11003
|
2026-06-6 10:54 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2842
|
4.0 |
MEDIUM
Local
|
google
|
chrome
|
Out of bounds read in Media in Google Chrome prior to 149.0.7827.53 allowed an attacker on the local network segment to perform an out of bounds memory read via malicious network traffic. (Chromium s…
|
CWE-125
Out-of-bounds Read
|
CVE-2026-10998
|
2026-06-6 10:53 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2843
|
8.8 |
HIGH
Network
|
google
|
chrome
|
Use after free in V8 in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who convinced a user to engage in specific UI gestures to execute arbitrary code inside a sandbox via a crafted …
|
CWE-416
Use After Free
|
CVE-2026-10991
|
2026-06-6 10:50 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2844
|
8.8 |
HIGH
Network
|
google
|
chrome
|
Inappropriate implementation in V8 in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via …
|
CWE-122
Heap-based Buffer Overflow
|
CVE-2026-10989
|
2026-06-6 10:49 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2845
|
8.8 |
HIGH
Network
|
google
|
chrome
|
Use after free in Views in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Ch…
|
CWE-416
Use After Free
|
CVE-2026-10988
|
2026-06-6 10:49 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2846
|
8.8 |
HIGH
Network
|
google
|
chrome
|
Integer overflow in V8 in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
|
CWE-472
External Control of Assumed-Immutable Web Parameter
|
CVE-2026-10987
|
2026-06-6 10:48 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2847
|
8.8 |
HIGH
Network
|
google
|
chrome
|
Integer overflow in Media in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a malicious file. (Chromium security severity: High)
|
CWE-472
External Control of Assumed-Immutable Web Parameter
|
CVE-2026-10986
|
2026-06-6 10:48 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2848
|
8.8 |
HIGH
Network
|
google
|
chrome
|
Use after free in WebXR in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
|
CWE-416
Use After Free
|
CVE-2026-10982
|
2026-06-6 10:45 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2849
|
8.8 |
HIGH
Network
|
google
|
chrome
|
Use after free in Chromoting in Google Chrome on Windows prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code via malicious network traffic. (Chromium security severity: High)
|
CWE-416
Use After Free
|
CVE-2026-10978
|
2026-06-6 10:45 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2850
|
8.8 |
HIGH
Network
|
google
|
chrome
|
Use after free in WebRTC in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
|
CWE-416
Use After Free
|
CVE-2026-10975
|
2026-06-6 10:45 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|