|
811
|
8.8 |
HIGH
Adjacent
|
veritas
|
infoscale_operations_manager
|
Cross-Site Request Forgery (CSRF) vulnerability in InfoScale v.9.1.3 Operations Manager (VIOM) allows an attacker to force the user with an active session into clicking a malicious HTML link, which t…
|
CWE-352
Origin Validation Error
|
CVE-2026-44925
|
2026-05-22 01:57 |
2026-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
812
|
4.2 |
MEDIUM
Network
|
google
|
chrome
|
Inappropriate implementation in UI in Google Chrome on Windows prior to 148.0.7778.179 allowed a remote attacker who had compromised the renderer process to perform UI spoofing via a crafted HTML pag…
|
CWE-451
User Interface (UI) Misrepresentation of Critical Information
|
CVE-2026-9110
|
2026-05-22 01:56 |
2026-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
813
|
8.8 |
HIGH
Network
|
google
|
chrome
|
Use after free in WebRTC in Google Chrome on Linux prior to 148.0.7778.179 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: Critical)
|
CWE-416
Use After Free
|
CVE-2026-9111
|
2026-05-22 01:56 |
2026-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
814
|
8.8 |
HIGH
Network
|
google
|
chrome
|
Use after free in GPU in Google Chrome on Windows prior to 148.0.7778.179 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Hi…
|
CWE-416
Use After Free
|
CVE-2026-9112
|
2026-05-22 01:56 |
2026-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
815
|
4.3 |
MEDIUM
Network
|
google
|
chrome
|
Out of bounds read in GPU in Google Chrome on Mac prior to 148.0.7778.179 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: High)
|
CWE-125
Out-of-bounds Read
|
CVE-2026-9113
|
2026-05-22 01:56 |
2026-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
816
|
8.8 |
HIGH
Network
|
google
|
chrome
|
Use after free in QUIC in Google Chrome on prior to 148.0.7778.179 allowed a remote attacker to execute arbitrary code inside a sandbox via malicious network traffic. (Chromium security severity: Hig…
|
CWE-416
Use After Free
|
CVE-2026-9114
|
2026-05-22 01:56 |
2026-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
817
|
4.3 |
MEDIUM
Network
|
google
|
chrome
|
Insufficient policy enforcement in Service Worker in Google Chrome on prior to 148.0.7778.179 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium security severi…
|
CWE-693
Protection Mechanism Failure
|
CVE-2026-9115
|
2026-05-22 01:56 |
2026-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
818
|
4.3 |
MEDIUM
Network
|
google
|
chrome
|
Insufficient policy enforcement in ServiceWorker in Google Chrome on prior to 148.0.7778.179 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: …
|
CWE-693
Protection Mechanism Failure
|
CVE-2026-9116
|
2026-05-22 01:56 |
2026-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
819
|
6.5 |
MEDIUM
Network
|
plane
|
plane
|
Plane is an open-source project management tool. In versions 1.3.0 and below, SavedAnalyticEndpoint passes the user-controlled segment query parameter directly to a Django F() expression without vali…
|
CWE-943
Improper Neutralization of Special Elements in Data Query Logic
|
CVE-2026-40102
|
2026-05-22 01:56 |
2026-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
820
|
6.1 |
MEDIUM
Network
|
obfuscate_project
|
obfuscate
|
Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Obfuscate allows Cross-Site Scripting (XSS).
This issue affects Obfuscate: from 0.0.0 bef…
|
CWE-79
Cross-site Scripting
|
CVE-2026-6871
|
2026-05-22 01:52 |
2026-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|