|
941
|
7.2 |
HIGH
Network
|
-
|
-
|
A flaw has been found in Shibby Tomato 1.28.0000. This affects the function start_dhcpc of the file /sbin/rc of the component Web UI. This manipulation causes os command injection. It is possible to …
Update
|
CWE-77 CWE-78
Command Injection OS Command
|
CVE-2026-10870
|
2026-06-9 01:16 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
942
|
- |
|
-
|
-
|
In the Linux kernel, the following vulnerability has been resolved:
drm/vkms: Convert to DRM's vblank timer
Replace vkms' vblank timer with the DRM implementation. The DRM
code is identical in conc…
New
|
-
|
CVE-2025-71315
|
2026-06-9 01:16 |
2026-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
943
|
4.8 |
MEDIUM
Network
|
checkmk
|
checkmk
|
Stored cross-site scripting in the global settings change log in Checkmk <2.5.0p5, <2.4.0p31, <2.3.0p48, and all 2.2.0 versions allows an administrator who can change global settings to store malicio…
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-8078
|
2026-06-9 00:53 |
2026-06-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
944
|
5.4 |
MEDIUM
Network
|
checkmk
|
checkmk
|
Stored cross-site scripting in the URL dashboard widget in Checkmk <2.5.0p5, <2.4.0p31, <2.3.0p48, and all 2.2.0 versions allows a user with dashboard editing permissions to store a URL with a danger…
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-7186
|
2026-06-9 00:53 |
2026-06-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
945
|
4.8 |
MEDIUM
Network
|
checkmk
|
checkmk
|
Stored cross-site scripting in the service discovery active check output in Checkmk <2.5.0p5, <2.4.0p31, <2.3.0p48, and all 2.2.0 versions allows an administrator who can configure active or custom c…
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-9549
|
2026-06-9 00:53 |
2026-06-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
946
|
9.6 |
CRITICAL
Network
|
google
|
chrome
|
Insufficient validation of untrusted input in SiteIsolation in Google Chrome on Windows prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perfor…
Update
|
CWE-20
Improper Input Validation
|
CVE-2026-11056
|
2026-06-9 00:52 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
947
|
6.5 |
MEDIUM
Network
|
google
|
chrome
|
Insufficient validation of untrusted input in Cast in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium security severity:…
Update
|
CWE-20
Improper Input Validation
|
CVE-2026-11069
|
2026-06-9 00:52 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
948
|
9.6 |
CRITICAL
Network
|
google
|
chrome
|
Insufficient validation of untrusted input in Chromoting in Google Chrome on Windows prior to 149.0.7827.53 allowed a remote attacker who had compromised the network process to potentially perform a …
Update
|
CWE-20
Improper Input Validation
|
CVE-2026-11070
|
2026-06-9 00:52 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
949
|
8.8 |
HIGH
Network
|
google
|
chrome
|
Use after free in Base in Google Chrome on Linux prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process mem…
Update
|
CWE-416
Use After Free
|
CVE-2026-11071
|
2026-06-9 00:51 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
950
|
7.8 |
HIGH
Local
|
google
|
chrome
|
Use after free in WebView in Google Chrome on Android prior to 149.0.7827.53 allowed a local attacker to execute arbitrary code via a malicious file. (Chromium security severity: Medium)
Update
|
CWE-416
Use After Free
|
CVE-2026-11072
|
2026-06-9 00:51 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|