|
111
|
8.8 |
HIGH
Network
|
google
|
chrome
|
Type Confusion in Skia in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
New
|
CWE-843
Type Confusion
|
CVE-2026-9983
|
2026-05-30 01:42 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
112
|
8.8 |
HIGH
Network
|
google
|
chrome
|
Use after free in UI in Google Chrome on Windows prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)
New
|
CWE-416
Use After Free
|
CVE-2026-9984
|
2026-05-30 01:42 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
113
|
7.8 |
HIGH
Local
|
google
|
chrome
|
Insufficient validation of untrusted input in WebAppInstalls in Google Chrome on Android prior to 148.0.7778.216 allowed a local attacker to execute arbitrary code via a malicious file. (Chromium sec…
New
|
CWE-20
Improper Input Validation
|
CVE-2026-9987
|
2026-05-30 01:41 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
114
|
8.8 |
HIGH
Network
|
google
|
chrome
|
Use after free in Network in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
New
|
CWE-416
Use After Free
|
CVE-2026-9992
|
2026-05-30 01:41 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
115
|
8.8 |
HIGH
Network
|
google
|
chrome
|
Use after free in WebXR in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
New
|
CWE-416
Use After Free
|
CVE-2026-9995
|
2026-05-30 01:40 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
116
|
4.3 |
MEDIUM
Network
|
gitlab
|
gitlab
|
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.9 before 18.10.7, 18.11 before 18.11.4, and 19.0 before 19.0.1 that under certain conditions could have allowed a blocked…
New
|
CWE-863
Incorrect Authorization
|
CVE-2026-9807
|
2026-05-30 01:40 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
117
|
6.3 |
MEDIUM
Network
|
-
|
-
|
A security flaw has been discovered in TRENDnet TEW-432BRP 3.10B20. This affects the function formSetPortTr of the file /goform/formSetPortTr. Performing a manipulation of the argument special_name r…
New
|
CWE-119 CWE-121
Incorrect Access of Indexable Resource ('Range Error') Stack-based Buffer Overflow
|
CVE-2026-10064
|
2026-05-30 01:33 |
2026-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
118
|
9.9 |
CRITICAL
Network
|
-
|
-
|
Plesk contains an XPath injection vulnerability in the APS Application Catalog search functionality, where user-supplied input is interpolated into XPath queries without proper sanitization. This all…
New
|
CWE-643
XPath Injection
|
CVE-2026-44962
|
2026-05-30 01:33 |
2026-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
119
|
7.4 |
HIGH
Network
|
-
|
-
|
GitHub CLI (gh) is GitHub’s official command line tool. Prior to 2.93.0, GitHub CLI incorrectly includes authorization header in API requests to TUF repository mirrors via gh attestation, gh release …
New
|
CWE-863
Incorrect Authorization
|
CVE-2026-48501
|
2026-05-30 01:33 |
2026-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
120
|
2.0 |
LOW
Network
|
-
|
-
|
AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. Prior to 1.13.0, the AnythingLLM agent filesystem copy tool validates only …
New
|
CWE-59
Link Following
|
CVE-2026-45403
|
2026-05-30 01:32 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|