|
791
|
8.8 |
HIGH
Network
|
-
|
-
|
Use after free in GTK in Google Chrome on Windows prior to 148.0.7778.168 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)
|
CWE-416
Use After Free
|
CVE-2026-8555
|
2026-05-15 06:19 |
2026-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
792
|
7.5 |
HIGH
Network
|
-
|
-
|
Use after free in Accessibility in Google Chrome prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to perform privilege escalation via a crafted HTML page. (C…
|
CWE-416
Use After Free
|
CVE-2026-8557
|
2026-05-15 06:19 |
2026-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
793
|
8.8 |
HIGH
Network
|
-
|
-
|
Integer overflow in Fonts in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)
|
CWE-472
External Control of Assumed-Immutable Web Parameter
|
CVE-2026-8577
|
2026-05-15 06:19 |
2026-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
794
|
9.6 |
CRITICAL
Network
|
-
|
-
|
Use after free in Mojo in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)
|
CWE-416
Use After Free
|
CVE-2026-8580
|
2026-05-15 06:19 |
2026-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
795
|
8.8 |
HIGH
Network
|
-
|
-
|
Use after free in Extensions in Google Chrome on Mac prior to 148.0.7778.168 allowed an attacker who convinced a user to install a malicious extension to execute arbitrary code via a crafted Chrome E…
|
CWE-416
Use After Free
|
CVE-2026-8587
|
2026-05-15 06:19 |
2026-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
796
|
6.5 |
MEDIUM
Network
|
hcltech
|
bigfix_webui_api bigfix_webui_application_administration bigfix_webui_cmep bigfix_webui_common bigfix_webui_content_app bigfix_webui_custom bigfix_webui_data_sync bigfix_webui_ex…
|
An improper authorization vulnerability in HCL BigFix WebUI allows an authenticated user without Master Operator privileges to access internal data (site names, versions, and configuration variables)…
|
CWE-863
Incorrect Authorization
|
CVE-2025-15633
|
2026-05-15 05:28 |
2026-05-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
797
|
4.3 |
MEDIUM
Network
|
hcltech
|
bigfix_webui_api bigfix_webui_application_administration bigfix_webui_cmep bigfix_webui_common bigfix_webui_content_app bigfix_webui_custom bigfix_webui_data_sync bigfix_webui_ex…
|
A missing authorization vulnerability in HCL BigFix WebUI allows an authenticated user without proper permissions to view sensitive environmental information via direct URL access to the unauthorized…
|
CWE-862
Missing Authorization
|
CVE-2025-15634
|
2026-05-15 05:28 |
2026-05-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
798
|
7.8 |
HIGH
Local
|
python
|
pillow
|
Pillow is a Python imaging library. From version 10.3.0 to before version 12.2.0, processing a malicious PSD file could lead to memory corruption, potentially resulting in a crash or arbitrary code e…
|
CWE-190 CWE-787
Integer Overflow or Wraparound Out-of-bounds Write
|
CVE-2026-42311
|
2026-05-15 05:27 |
2026-05-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
799
|
7.6 |
HIGH
Network
|
-
|
-
|
Heym before 0.0.21 contains a path traversal vulnerability in the file upload endpoint that allows authenticated users to write attacker-controlled files to arbitrary locations by supplying a crafted…
|
CWE-22
Path Traversal
|
CVE-2026-45225
|
2026-05-15 05:17 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
800
|
8.2 |
HIGH
Network
|
-
|
-
|
Open-WebSearch is a multi-engine MCP server, CLI, and local daemon for agent web search and content retrieval. Prior to 2.1.7, isPublicHttpUrl / assertPublicHttpUrl in src/utils/urlSafety.ts do not r…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2026-42260
|
2026-05-15 05:17 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|