|
41
|
8.3 |
HIGH
Network
|
google
|
chrome
|
Inappropriate implementation in Views in Google Chrome on Windows prior to 149.0.7827.115 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape vi…
New
|
CWE-693
Protection Mechanism Failure
|
CVE-2026-12031
|
2026-06-13 03:05 |
2026-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
42
|
3.1 |
LOW
Network
|
google
|
chrome
|
Inappropriate implementation in Passwords in Google Chrome on Android prior to 149.0.7827.115 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted…
New
|
CWE-346
Origin Validation Error
|
CVE-2026-12032
|
2026-06-13 03:05 |
2026-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
43
|
5.3 |
MEDIUM
Network
|
google
|
chrome
|
Out of bounds read in VideoCapture in Google Chrome prior to 149.0.7827.115 allowed a remote attacker who had compromised the GPU process to obtain potentially sensitive information from process memo…
New
|
CWE-125
Out-of-bounds Read
|
CVE-2026-12033
|
2026-06-13 03:04 |
2026-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
44
|
8.7 |
HIGH
Network
|
axios
|
axios
|
Axios is a promise based HTTP client for the browser and Node.js. From 1.0.0 to before 1.16.0, the Axios library is vulnerable to a Prototype Pollution "Gadget" attack that allows any Object.prototyp…
New
|
CWE-441 CWE-1321
Confused Deputy Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
|
CVE-2026-44494
|
2026-06-13 03:01 |
2026-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
45
|
7.5 |
HIGH
Network
|
axios
|
axios
|
Axios is a promise based HTTP client for the browser and Node.js. Axios versions before 0.32.0 on the 0.x line and before 1.16.0 on the 1.x line build a regular expression from the configured XSRF co…
New
|
CWE-400 CWE-1333
Uncontrolled Resource Consumption Inefficient Regular Expression Complexity
|
CVE-2026-44496
|
2026-06-13 03:00 |
2026-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
46
|
8.3 |
HIGH
Network
|
google
|
chrome
|
Insufficient validation of untrusted input in Linux Toolkit Theming in Google Chrome on Linux prior to 149.0.7827.115 allowed a remote attacker who had compromised the renderer process to potentially…
New
|
CWE-20
Improper Input Validation
|
CVE-2026-12034
|
2026-06-13 02:58 |
2026-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
47
|
8.8 |
HIGH
Network
|
google
|
chrome
|
Use after free in Views in Google Chrome on Windows prior to 149.0.7827.115 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
New
|
CWE-416
Use After Free
|
CVE-2026-12035
|
2026-06-13 02:58 |
2026-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
48
|
6.5 |
MEDIUM
Network
|
devolutions
|
devolutions_server
|
Improper access control in the ticketing integration settings in Devolutions Server allows an authenticated low-privileged user to obtain cleartext credentials for configured ticketing integrations v…
Update
|
CWE-312
Cleartext Storage of Sensitive Information
|
CVE-2026-10786
|
2026-06-13 02:56 |
2026-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
49
|
4.3 |
MEDIUM
Network
|
devolutions
|
devolutions_server
|
Missing authorization in the deleted user groups API in Devolutions Server allows an authenticated low-privileged user to enumerate metadata of deleted user groups via a crafted API request.
This is…
Update
|
CWE-862
Missing Authorization
|
CVE-2026-10787
|
2026-06-13 02:56 |
2026-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
50
|
9.1 |
CRITICAL
Network
|
microsoft
|
windows_10_1607 windows_10_1809 windows_10_21h2 windows_10_22h2 windows_11_23h2 windows_11_24h2 windows_11_25h2 windows_11_26h1 windows_server_2012 windows_server_2016 w…
|
No cwe for this issue in Windows DHCP Server allows an unauthorized attacker to perform tampering over a network.
Update
|
CWE-229
Improper Handling of Values
|
CVE-2026-45602
|
2026-06-13 02:56 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|