|
511
|
3.3 |
LOW
Local
|
-
|
-
|
Ubuntu Linux 6.8 contains SAUCE patches with a possible use of an uninitialized variable in AppArmor AF_INET/AF_INET6 socket mediation code. The bug can be triggered by an unprivileged local user and…
New
|
CWE-457
Use of Uninitialized Variable
|
CVE-2026-47336
|
2026-05-29 11:45 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
512
|
3.3 |
LOW
Local
|
-
|
-
|
Ubuntu Linux 6.8, 6.17 and 7.0 contain SAUCE patches with a possible NULL pointer dereference in the handling of AF_INET/AF_INET6 socket mediation. The bug can be triggered by an unprivileged local u…
New
|
CWE-476
NULL Pointer Dereference
|
CVE-2026-47337
|
2026-05-29 11:45 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
513
|
- |
|
-
|
-
|
LinkAce is a self-hosted archive to collect website links. Prior to 2.5.6, LinkAce contains a stored cross-site scripting vulnerability that allows a low-privilege user to execute arbitrary JavaScrip…
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-45343
|
2026-05-29 11:44 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
514
|
8.1 |
HIGH
Network
|
-
|
-
|
LinkAce is a self-hosted archive to collect website links. Prior to 2.5.6, the setup database configuration flow on uninitialized LinkAce instances accepts attacker-controlled database credential fie…
New
|
CWE-74
Injection
|
CVE-2026-45344
|
2026-05-29 11:44 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
515
|
9.8 |
CRITICAL
Network
|
-
|
-
|
The Advanced Custom Fields: Extended plugin for WordPress is vulnerable to Privilege Escalation via Validation Bypass in all versions up to and including 0.9.2.5. The vulnerability exists due to the …
New
|
CWE-269
Improper Privilege Management
|
CVE-2026-8809
|
2026-05-29 11:40 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
516
|
- |
|
-
|
-
|
Inappropriate implementation in Input in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTM…
New
|
-
|
CVE-2026-10010
|
2026-05-29 11:36 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
517
|
- |
|
-
|
-
|
Insufficient validation of untrusted input in Site Isolation in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a…
New
|
CWE-20
Improper Input Validation
|
CVE-2026-9903
|
2026-05-29 11:35 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
518
|
- |
|
-
|
-
|
Integer overflow in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: High)
New
|
CWE-472
External Control of Assumed-Immutable Web Parameter
|
CVE-2026-9911
|
2026-05-29 11:35 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
519
|
- |
|
-
|
-
|
Use after free in Skia in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
New
|
CWE-416
Use After Free
|
CVE-2026-9923
|
2026-05-29 11:35 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
520
|
- |
|
-
|
-
|
Out of bounds write in Dawn in Google Chrome on Mac prior to 148.0.7778.216 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: Hi…
New
|
CWE-787
Out-of-bounds Write
|
CVE-2026-9930
|
2026-05-29 11:35 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|