|
1411
|
9.6 |
CRITICAL
Network
|
google
|
chrome
|
Use after free in WebGL in Google Chrome on Android prior to 149.0.7827.197 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Cri…
|
CWE-416
Use After Free
|
CVE-2026-13032
|
2026-06-26 03:12 |
2026-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1412
|
8.8 |
HIGH
Network
|
google
|
chrome
|
Out of bounds read and write in Blink>InterestGroups in Google Chrome prior to 149.0.7827.197 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity:…
|
CWE-125 CWE-787
Out-of-bounds Read Out-of-bounds Write
|
CVE-2026-13033
|
2026-06-26 03:11 |
2026-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1413
|
5.4 |
MEDIUM
Network
|
-
|
-
|
Gogs is an open source self-hosted Git service. Prior to 0.14.3, an open redirect vulnerability exists in Gogs where attacker-controlled redirect_to parameters can bypass validation, allowing redirec…
|
CWE-601
Open Redirect
|
CVE-2026-52802
|
2026-06-26 02:16 |
2026-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1414
|
7.5 |
HIGH
Network
|
messagepack
|
messagepack
|
MessagePack for C# is a MessagePack serializer for C#. Prior to 2.5.301 and 3.1.7, MessagePack-CSharp's typeless deserialization includes MessagePackSerializerOptions.ThrowIfDeserializingTypeIsDisall…
|
CWE-470 CWE-502
Unsafe Reflection Deserialization of Untrusted Data
|
CVE-2026-48517
|
2026-06-26 02:16 |
2026-06-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1415
|
7.5 |
HIGH
Network
|
messagepack
|
messagepack
|
MessagePack for C# is a MessagePack serializer for C#. Prior to 2.5.301 and 3.1.7, InterfaceLookupFormatter<TKey,TElement> constructs an internal Dictionary<TKey, IGrouping<TKey,TElement>> with the d…
|
CWE-407
Inefficient Algorithmic Complexity
|
CVE-2026-48516
|
2026-06-26 02:16 |
2026-06-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1416
|
7.5 |
HIGH
Network
|
messagepack
|
messagepack
|
MessagePack for C# is a MessagePack serializer for C#. Prior to 2.5.301 and 3.1.7, MessagePack-CSharp's multi-dimensional array formatters read dimension lengths directly from the payload and allocat…
|
CWE-770
Allocation of Resources Without Limits or Throttling
|
CVE-2026-48515
|
2026-06-26 02:16 |
2026-06-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1417
|
8.6 |
HIGH
Network
|
-
|
-
|
Mastodon is a free, open-source social network server based on ActivityPub. Prior to 4.5.10, 4.4.17, and 4.3.23, when using Ruby versions older than 3.4, PrivateAddressCheck.private_address? returns …
|
CWE-184 CWE-200 CWE-918
Incomplete Blacklist Information Exposure Server-Side Request Forgery (SSRF)
|
CVE-2026-47389
|
2026-06-26 02:16 |
2026-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1418
|
7.5 |
HIGH
Network
|
-
|
-
|
The Tourfic – AI Powered Travel Booking, Hotel Booking & Car Rental WordPress Plugin plugin for WordPress is vulnerable to generic SQL Injection via the 'post_id' parameter in all versions up to, and…
|
CWE-89
SQL Injection
|
CVE-2026-12937
|
2026-06-26 02:16 |
2026-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1419
|
3.7 |
LOW
Network
|
openbsd redhat
|
openssh hardened_images enterprise_linux
|
A flaw was found in OpenSSH. This vulnerability, a heap out-of-bounds read, occurs during the cleanup of GSSAPI (Generic Security Service Application Programming Interface) indicators when a trailing…
|
CWE-125
Out-of-bounds Read
|
CVE-2026-55654
|
2026-06-26 01:59 |
2026-06-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1420
|
6.5 |
MEDIUM
Network
|
openbsd redhat
|
openssh hardened_images openshift_container_platform enterprise_linux
|
A flaw was found in OpenSSH. A malicious SSH server can exploit a double free vulnerability in the Diffie-Hellman Group Exchange (DH-GEX) client path. This occurs during FIPS (Federal Information Pro…
|
CWE-415
Double Free
|
CVE-2026-55653
|
2026-06-26 01:57 |
2026-06-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|