|
621
|
4.3 |
MEDIUM
Network
|
-
|
-
|
SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, POST /api/tag/getTag is registered with model.CheckAuth only, omitting both model.CheckAdminRole and model.CheckReadonly…
New
|
CWE-285 CWE-862
Improper Authorization Missing Authorization
|
CVE-2026-45147
|
2026-05-15 06:22 |
2026-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
622
|
8.8 |
HIGH
Network
|
-
|
-
|
Heap buffer overflow in WebML in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Criti…
New
|
CWE-122
Heap-based Buffer Overflow
|
CVE-2026-8509
|
2026-05-15 06:19 |
2026-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
623
|
9.6 |
CRITICAL
Network
|
-
|
-
|
Use after free in UI in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
New
|
CWE-416
Use After Free
|
CVE-2026-8511
|
2026-05-15 06:19 |
2026-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
624
|
8.8 |
HIGH
Network
|
-
|
-
|
Object lifecycle issue in WebShare in Google Chrome on Mac prior to 148.0.7778.168 allowed a remote attacker who convinced a user to engage in specific UI gestures to execute arbitrary code via a cra…
New
|
CWE-664
Improper Control of a Resource Through its Lifetime
|
CVE-2026-8517
|
2026-05-15 06:19 |
2026-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
625
|
8.8 |
HIGH
Network
|
-
|
-
|
Use after free in Blink in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Critical)
New
|
CWE-416
Use After Free
|
CVE-2026-8518
|
2026-05-15 06:19 |
2026-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
626
|
7.5 |
HIGH
Adjacent
|
-
|
-
|
Use after free in Tab Groups in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to execute arbitrary code via malicious network traffic. (Chromium security severity: Critical)
New
|
CWE-416
Use After Free
|
CVE-2026-8521
|
2026-05-15 06:19 |
2026-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
627
|
8.8 |
HIGH
Network
|
-
|
-
|
Use after free in Downloads in Google Chrome on Mac prior to 148.0.7778.168 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: Critical)
New
|
CWE-416
Use After Free
|
CVE-2026-8522
|
2026-05-15 06:19 |
2026-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
628
|
8.8 |
HIGH
Network
|
-
|
-
|
Heap buffer overflow in Codecs in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted video file. (Chromium security severity: Hig…
New
|
CWE-122
Heap-based Buffer Overflow
|
CVE-2026-8529
|
2026-05-15 06:19 |
2026-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
629
|
8.8 |
HIGH
Network
|
-
|
-
|
Integer overflow in XML in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
New
|
CWE-472
External Control of Assumed-Immutable Web Parameter
|
CVE-2026-8532
|
2026-05-15 06:19 |
2026-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
630
|
8.8 |
HIGH
Network
|
-
|
-
|
Type Confusion in V8 in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
New
|
CWE-843
Type Confusion
|
CVE-2026-8540
|
2026-05-15 06:19 |
2026-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|