|
1361
|
4.6 |
MEDIUM
Physics
|
-
|
-
|
GNCC GP5 v7.1.76 was discovered to store sensitive wireless network information in plaintext during routine operations to the serial console. This issue allows physically-proximate attackers to obtai…
Update
|
CWE-256
Plaintext Storage of a Password
|
CVE-2026-36174
|
2026-06-9 00:16 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1362
|
9.8 |
CRITICAL
Network
|
-
|
-
|
T3 Technology CPE models T625Pro v1.0.07, T6825G v1.0.03, and T7281 v1.0.03 were discovered to contain a hardcoded password for root access under the "superadmin" account.
Update
|
CWE-259
Use of Hard-coded Password
|
CVE-2026-35905
|
2026-06-9 00:16 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1363
|
9.8 |
CRITICAL
Network
|
-
|
-
|
Incorrect access control in the web management interface of T3 Technology CPE models T625Pro v1.0.07, T6825G v1.0.03, and T7281 v1.0.03 allows unauthorized attackers to enable the Telnet service via …
Update
|
CWE-284
Improper Access Control
|
CVE-2026-35904
|
2026-06-9 00:16 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1364
|
8.4 |
HIGH
Local
|
-
|
-
|
clash-verge-service-ipc before 2.3.0 has a world-reachable IPC endpoint, leading to local privilege escalation.
New
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2026-26422
|
2026-06-9 00:16 |
2026-06-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1365
|
3.5 |
LOW
Network
|
-
|
-
|
A weakness has been identified in Bolt CMS up to 3.7.5. This vulnerability affects unknown code of the file src/Storage/Field/Type/TextType.php of the component HTML Attribute Handler. Executing a ma…
New
|
CWE-74 CWE-80
Injection Basic XSS
|
CVE-2026-11511
|
2026-06-9 00:16 |
2026-06-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1366
|
7.1 |
HIGH
Local
|
-
|
-
|
Markdown Preview Enhanced 0.8.x with crossnote engine 0.9.28 contains a code injection vulnerability in the WaveDrom rendering pipeline that allows attackers to execute arbitrary JavaScript by embedd…
Update
|
CWE-95
Eval Injection
|
CVE-2026-11422
|
2026-06-9 00:16 |
2026-06-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1367
|
9.6 |
CRITICAL
Network
|
google
|
chrome
|
Type Confusion in GPU in Google Chrome on Windows prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML …
Update
|
CWE-843
Type Confusion
|
CVE-2026-11052
|
2026-06-9 00:08 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1368
|
6.5 |
MEDIUM
Network
|
google
|
chrome
|
Out of bounds read in ANGLE in Google Chrome on Linux prior to 149.0.7827.53 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromi…
Update
|
CWE-125
Out-of-bounds Read
|
CVE-2026-11051
|
2026-06-9 00:08 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1369
|
6.5 |
MEDIUM
Network
|
google
|
chrome
|
Inappropriate implementation in Extensions in Google Chrome prior to 149.0.7827.53 allowed an attacker who convinced a user to install a malicious extension to bypass same origin policy via a crafted…
Update
|
CWE-346
Origin Validation Error
|
CVE-2026-11048
|
2026-06-9 00:04 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1370
|
9.6 |
CRITICAL
Network
|
google
|
chrome
|
Inappropriate implementation in Base in Google Chrome on Windows prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via …
Update
|
CWE-20
Improper Input Validation
|
CVE-2026-11047
|
2026-06-9 00:03 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|