|
1521
|
- |
|
-
|
-
|
TYPO3's cache frontend (VariableFrontend) and persistent key-value store (Registry) deserialized PHP payloads without integrity validation or class restrictions. An attacker with write access to the …
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2026-49740
|
2026-06-9 22:46 |
2026-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1522
|
- |
|
-
|
-
|
Backend users with write access to the form_definition database table were able to directly create, update, or delete form definition records via DataHandler, bypassing the Form Framework's persisten…
|
CWE-89 CWE-862
SQL Injection Missing Authorization
|
CVE-2026-49741
|
2026-06-9 22:46 |
2026-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1523
|
- |
|
-
|
-
|
Backend users with file download permissions were able to download files from the fallback storage of the file abstraction layer (FAL) via the Media Module. Since the fallback storage resolves paths …
|
CWE-22 CWE-200
Path Traversal Information Exposure
|
CVE-2026-49742
|
2026-06-9 22:46 |
2026-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1524
|
7.5 |
HIGH
Network
|
google
|
chrome
|
Inappropriate implementation in ImageCapture in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to perform privilege escalation via a crafted H…
|
CWE-269
Improper Privilege Management
|
CVE-2026-11296
|
2026-06-9 22:45 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1525
|
4.3 |
MEDIUM
Network
|
google
|
chrome
|
Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 149.0.7827.53 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium security severi…
|
CWE-346
Origin Validation Error
|
CVE-2026-11298
|
2026-06-9 22:44 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1526
|
6.5 |
MEDIUM
Network
|
google
|
chrome
|
Integer overflow in Fonts in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security…
|
CWE-125 CWE-190
Out-of-bounds Read Integer Overflow or Wraparound
|
CVE-2026-11299
|
2026-06-9 22:43 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1527
|
6.3 |
MEDIUM
Local
|
-
|
-
|
Permission management vulnerability in the network management module. Impact: Successful exploitation of this vulnerability may affect service integrity.
|
CWE-701
Weaknesses Introduced During Design
|
CVE-2026-41975
|
2026-06-9 22:34 |
2026-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1528
|
4.4 |
MEDIUM
Local
|
-
|
-
|
Permission control vulnerability in the clone module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
|
CWE-275
Permission Issues
|
CVE-2026-41978
|
2026-06-9 22:34 |
2026-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1529
|
5.5 |
MEDIUM
Local
|
-
|
-
|
Permission control vulnerability in the print module. Impact: Successful exploitation of this vulnerability may affect integrity and confidentiality.
|
CWE-701
Weaknesses Introduced During Design
|
CVE-2026-41979
|
2026-06-9 22:34 |
2026-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1530
|
5.5 |
MEDIUM
Local
|
-
|
-
|
Permission control vulnerability in the file preview module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
|
CWE-200
Information Exposure
|
CVE-2026-41980
|
2026-06-9 22:34 |
2026-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|