|
401
|
8.8 |
HIGH
Network
|
-
|
-
|
Insufficient validation of untrusted input in DevTools in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who convinced a user to engage in specific UI gestures to bypass same origin p…
New
|
CWE-20
Improper Input Validation
|
CVE-2026-10922
|
2026-06-6 01:16 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
402
|
8.8 |
HIGH
Network
|
-
|
-
|
Inappropriate implementation in GPU in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Cri…
New
|
CWE-787
Out-of-bounds Write
|
CVE-2026-10897
|
2026-06-6 01:16 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
403
|
8.8 |
HIGH
Network
|
-
|
-
|
Use after free in Chromoting in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code via malicious network traffic. (Chromium security severity: Critical)
New
|
CWE-416
Use After Free
|
CVE-2026-10893
|
2026-06-6 01:16 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
404
|
9.6 |
CRITICAL
Network
|
-
|
-
|
Out of bounds write in GPU in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: C…
New
|
CWE-787
Out-of-bounds Write
|
CVE-2026-10892
|
2026-06-6 01:16 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
405
|
- |
|
-
|
-
|
sanic-cors version 2.2.0 and prior contains an improper regular expression in the try_match() function in sanic_cors/core.py that uses re.match without end-anchoring. This allows an attacker to bypas…
New
|
-
|
CVE-2026-37737
|
2026-06-6 01:07 |
2026-06-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
406
|
- |
|
-
|
-
|
The linqi application contains hardcoded cryptographic keys. Additionally, the application uses a weak algorithm with a limited ASCII charset to dynamically generate Initialization Vectors (IVs) for …
New
|
CWE-321 CWE-338
Use of Hard-coded Cryptographic Key Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)
|
CVE-2026-11347
|
2026-06-6 01:07 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
407
|
- |
|
-
|
-
|
An Improper Authentication vulnerability in the /api/Cdn/GetFile endpoint of linqi allows unauthenticated, remote attackers to bypass file access controls. The ValidateAnonFileAccess function incorre…
New
|
CWE-287
Improper Authentication
|
CVE-2026-11345
|
2026-06-6 01:07 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
408
|
- |
|
-
|
-
|
A Server-Side Request Forgery (SSRF) vulnerability in the custom process creation feature of linqi allows an authenticated attacker to probe internal network components. By crafting a specific proces…
New
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2026-11346
|
2026-06-6 01:07 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
409
|
- |
|
-
|
-
|
The Comment API (GET /api/Comment and POST /api/Comment) in the affected application fails to perform authorization checks to verify that the requesting user has access to the object identified by th…
New
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2026-11369
|
2026-06-6 01:07 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
410
|
6.5 |
MEDIUM
Network
|
-
|
-
|
A missing upper-bound check in the udpif_set_threads() function of Open vSwitch v3.6.90 allows an attacker with OVSDB write access to request an excessive number of handler or revalidation threads. T…
New
|
CWE-770
Allocation of Resources Without Limits or Throttling
|
CVE-2026-36499
|
2026-06-6 01:06 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|