|
111
|
8.8 |
HIGH
Network
|
google
|
chrome
|
Inappropriate implementation in Codecs in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially perform a sandbox escape via a crafted video file. (Chromium security severity:…
New
|
CWE-20
Improper Input Validation
|
CVE-2026-10966
|
2026-06-6 13:17 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
112
|
8.8 |
HIGH
Network
|
-
|
-
|
Type Confusion in ANGLE in Google Chrome on Windows prior to 149.0.7827.53 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page. (Chromium security sev…
New
|
CWE-843
Type Confusion
|
CVE-2026-10955
|
2026-06-6 13:17 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
113
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The Master Addons For Elementor – Widgets, Extensions, Theme Builder, Popup Builder & Template Kits plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'jtlma_custom_js' Page Settin…
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-9281
|
2026-06-6 11:16 |
2026-06-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
114
|
4.3 |
MEDIUM
Network
|
-
|
-
|
The Page-list plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 6.2. This is due to the pagelist_unqprfx_ext_shortcode() function (the [pagelist_ext] /…
New
|
CWE-862
Missing Authorization
|
CVE-2026-9008
|
2026-06-6 11:16 |
2026-06-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
115
|
7.2 |
HIGH
Network
|
-
|
-
|
The Integration for Freshsales – Contact Form 7, WPForms, Elementor, Gravity Forms and More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Form Submission Data in all versions …
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-8901
|
2026-06-6 11:16 |
2026-06-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
116
|
7.2 |
HIGH
Network
|
-
|
-
|
The All-In-One Security (AIOS) – Security and Firewall plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to and including 5.4.7. This is due to insufficient input sanit…
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-8438
|
2026-06-6 11:16 |
2026-06-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
117
|
5.5 |
MEDIUM
Local
|
samsung
|
android
|
Improper handling of insufficient privileges in SecTelephonyProvider prior to SMR Jun-2026 Release 1 allows local attackers to access privileged files.
New
|
NVD-CWE-Other
|
CVE-2026-21017
|
2026-06-6 11:01 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
118
|
5.5 |
MEDIUM
Local
|
samsung
|
android
|
Incorrect privilege assignment in Telephony prior to SMR Jun-2026 Release 1 allows local attackers to access sensitive information.
New
|
NVD-CWE-Other
|
CVE-2026-21025
|
2026-06-6 11:01 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
119
|
5.5 |
MEDIUM
Local
|
samsung
|
android
|
Improper export of android application components in SpriteWallpaper prior to SMR Jun-2026 Release 1 allows local attackers to access to sensitive information.
New
|
NVD-CWE-Other
|
CVE-2026-21026
|
2026-06-6 11:00 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
120
|
3.3 |
LOW
Local
|
samsung
|
android
|
Improper export of android application components in ImsSettings prior to SMR Jun-2026 Release 1 allows local attackers to trigger logging function.
New
|
NVD-CWE-Other
|
CVE-2026-21027
|
2026-06-6 11:00 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|