|
1081
|
9.6 |
CRITICAL
Network
|
google
|
chrome
|
Use after free in Views in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security…
New
|
CWE-416
Use After Free
|
CVE-2026-7910
|
2026-05-7 23:43 |
2026-05-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1082
|
9.8 |
CRITICAL
Network
|
-
|
-
|
Origin Validation Error vulnerability in TUBITAK BILGEM Software Technologies Research Institute Liderahenk allows Accessing Functionality Not Properly Constrained by ACLs.
This issue affects Lidera…
New
|
CWE-346
Origin Validation Error
|
CVE-2026-6508
|
2026-05-7 23:42 |
2026-05-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1083
|
8.3 |
HIGH
Network
|
-
|
-
|
Improperly controlled modification of Dynamically-Determined object attributes, Allocation of resources without limits or throttling vulnerability in DivvyDrive Information Technologies Inc. DivvyDri…
New
|
CWE-770 CWE-915
Allocation of Resources Without Limits or Throttling Improperly Controlled Modification of Dynamically-Determined Object Attributes
|
CVE-2025-14341
|
2026-05-7 23:42 |
2026-05-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1084
|
9.6 |
CRITICAL
Network
|
-
|
-
|
URL redirection to untrusted site ('open redirect') vulnerability in DivvyDrive Information Technologies Inc. DivvyDrive allows Parameter Injection.
This issue affects DivvyDrive: from 4.8.2.9 befor…
New
|
CWE-601
Open Redirect
|
CVE-2026-6795
|
2026-05-7 23:42 |
2026-05-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1085
|
8.8 |
HIGH
Network
|
-
|
-
|
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in DivvyDrive Information Technologies Inc. DivvyDrive allows Stored XSS.
This issue affects DivvyD…
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-5784
|
2026-05-7 23:42 |
2026-05-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1086
|
9.6 |
CRITICAL
Network
|
-
|
-
|
Cross-Site request forgery (CSRF) vulnerability in DivvyDrive Information Technologies Inc. DivvyDrive allows Cross Site Request Forgery.
This issue affects DivvyDrive: from 4.8.2.9 before 4.8.3.2.
New
|
CWE-352
Origin Validation Error
|
CVE-2026-5791
|
2026-05-7 23:42 |
2026-05-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1087
|
8.8 |
HIGH
Network
|
-
|
-
|
Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in DivvyDrive Information Technologies Inc. DivvyDrive allows Cross-Site Scripting (XSS).
This issue affec…
New
|
CWE-80
Basic XSS
|
CVE-2026-6002
|
2026-05-7 23:42 |
2026-05-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1088
|
7.7 |
HIGH
Network
|
openclaw
|
openclaw
|
OpenClaw before 2026.4.10 contains an incomplete navigation guard vulnerability that allows attackers to trigger navigation without complete SSRF policy enforcement. Browser press/type style interact…
New
|
CWE-862
Missing Authorization
|
CVE-2026-43580
|
2026-05-7 23:41 |
2026-05-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1089
|
9.6 |
CRITICAL
Adjacent
|
openclaw
|
openclaw
|
OpenClaw before 2026.4.10 contains an improper network binding vulnerability in the sandbox browser CDP relay that exposes Chrome DevTools Protocol on 0.0.0.0. Attackers can access the DevTools proto…
New
|
CWE-1188
Insecure Default Initialization of Resource
|
CVE-2026-43581
|
2026-05-7 23:41 |
2026-05-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1090
|
9.1 |
CRITICAL
Network
|
x.org redhat
|
x_server enterprise_linux
|
A flaw was found in the X.Org X server. This vulnerability, an out-of-bounds read, affects the XKB (X Keyboard Extension) modifier map handling. An attacker with access to the X11 server can exploit …
Update
|
CWE-805
Buffer Access with Incorrect Length Value
|
CVE-2026-34002
|
2026-05-7 23:39 |
2026-05-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|