|
1621
|
6.5 |
MEDIUM
Network
|
7-zip
|
7-zip
|
7-Zip is a file archiver with a high compression ratio. Versions 9.21 through 26.00 contain an An uninitialized memory disclosure vulnerability in the UEFI capsule (.scap) parser in 7-Zip. The OpenCa…
|
CWE-908
Use of Uninitialized Resource
|
CVE-2026-48101
|
2026-06-8 22:41 |
2026-06-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1622
|
8.8 |
HIGH
Network
|
7-zip
|
7-zip
|
7-Zip is a file archiver with a high compression ratio. Versions 26.00 and prior contain a heap buffer overflow vulnerability caused by an under-allocation in the NTFS compressed stream buffer (GetCu…
|
CWE-190 CWE-787
Integer Overflow or Wraparound Out-of-bounds Write
|
CVE-2026-48095
|
2026-06-8 22:40 |
2026-06-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1623
|
4.3 |
MEDIUM
Network
|
google
|
chrome
|
Insufficient validation of untrusted input in Password Manager in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to perform UI spoofing via malicious network traffic. (Chromium securi…
|
CWE-20 NVD-CWE-noinfo
Improper Input Validation
|
CVE-2026-11031
|
2026-06-8 22:40 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1624
|
6.5 |
MEDIUM
Network
|
google
|
chrome
|
Inappropriate implementation in Password Manager in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medi…
|
CWE-346
Origin Validation Error
|
CVE-2026-11032
|
2026-06-8 22:39 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1625
|
6.5 |
MEDIUM
Network
|
google
|
chrome
|
Uninitialized Use in WebML in Google Chrome on Mac prior to 149.0.7827.53 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium …
|
CWE-457
Use of Uninitialized Variable
|
CVE-2026-11033
|
2026-06-8 22:39 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1626
|
6.1 |
MEDIUM
Network
|
google
|
chrome
|
Insufficient validation of untrusted input in Tab Group Sync in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via malicious netw…
|
CWE-20
Improper Input Validation
|
CVE-2026-11034
|
2026-06-8 22:38 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1627
|
6.1 |
MEDIUM
Network
|
cisco
|
webex_meetings
|
A vulnerability in the web-based user interface of Cisco Webex Meetings could have allowed an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack. Cisco has addressed this…
|
CWE-79
Cross-site Scripting
|
CVE-2026-20233
|
2026-06-8 22:36 |
2026-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1628
|
8.1 |
HIGH
Network
|
misp
|
misp
|
A security issue was fixed in the correlations over-correlation endpoint where the order query parameter was accepted from user-controlled named request parameters. This allowed an authenticated user…
|
CWE-20
Improper Input Validation
|
CVE-2026-10863
|
2026-06-8 22:35 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1629
|
7.3 |
HIGH
Local
|
google
|
chrome
|
Inappropriate implementation in Custom Tabs in Google Chrome on Android prior to 149.0.7827.53 allowed a local attacker to perform privilege escalation via a crafted XML file. (Chromium security seve…
|
CWE-20 NVD-CWE-noinfo
Improper Input Validation
|
CVE-2026-11035
|
2026-06-8 22:34 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1630
|
6.5 |
MEDIUM
Network
|
google
|
chrome
|
Inappropriate implementation in DOM in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium security severity: Medium)
|
CWE-346
Origin Validation Error
|
CVE-2026-11036
|
2026-06-8 22:34 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|