|
571
|
9.1 |
CRITICAL
Network
|
-
|
-
|
Crabbox prior to v0.12.0 contains an environment variable exposure vulnerability that allows attackers with access to a malicious or compromised repository to forward local secrets such as API tokens…
|
CWE-94
Code Injection
|
CVE-2026-8634
|
2026-05-16 00:16 |
2026-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
572
|
7.5 |
HIGH
Network
|
-
|
-
|
Inappropriate implementation in Media in Google Chrome on iOS prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to perform an out of bounds memory read via a …
|
CWE-693
Protection Mechanism Failure
|
CVE-2026-8585
|
2026-05-16 00:16 |
2026-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
573
|
3.1 |
LOW
Network
|
-
|
-
|
Insufficient validation of untrusted input in Skia in Google Chrome prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to perform an out of bounds memory write…
|
CWE-20
Improper Input Validation
|
CVE-2026-8579
|
2026-05-16 00:16 |
2026-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
574
|
3.1 |
LOW
Network
|
-
|
-
|
Out of bounds read in GPU in Google Chrome on Linux prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chro…
|
CWE-125
Out-of-bounds Read
|
CVE-2026-8578
|
2026-05-16 00:16 |
2026-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
575
|
4.3 |
MEDIUM
Network
|
-
|
-
|
Inappropriate implementation in CORS in Google Chrome on Linux and ChromeOS prior to 148.0.7778.168 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security sev…
|
CWE-942
Permissive Cross-domain Policy with Untrusted Domains
|
CVE-2026-8576
|
2026-05-16 00:16 |
2026-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
576
|
3.1 |
LOW
Network
|
-
|
-
|
Insufficient policy enforcement in Network in Google Chrome on Android prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a craft…
|
CWE-693
Protection Mechanism Failure
|
CVE-2026-8572
|
2026-05-16 00:16 |
2026-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
577
|
3.1 |
LOW
Network
|
-
|
-
|
Insufficient policy enforcement in AI in Google Chrome prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to bypass Site Isolation via a crafted HTML page. (Ch…
|
CWE-693
Protection Mechanism Failure
|
CVE-2026-8568
|
2026-05-16 00:16 |
2026-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
578
|
3.1 |
LOW
Network
|
-
|
-
|
Inappropriate implementation in ANGLE in Google Chrome on Windows prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HT…
|
CWE-119 CWE-284
Incorrect Access of Indexable Resource ('Range Error') Improper Access Control
|
CVE-2026-8556
|
2026-05-16 00:16 |
2026-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
579
|
3.1 |
LOW
Network
|
-
|
-
|
Type Confusion in ANGLE in Google Chrome on Windows prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to perform an out of bounds memory write via a crafted H…
|
CWE-843
Type Confusion
|
CVE-2026-8554
|
2026-05-16 00:16 |
2026-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
580
|
3.1 |
LOW
Network
|
-
|
-
|
Object corruption in Compositing in Google Chrome prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromi…
|
CWE-119 CWE-284
Incorrect Access of Indexable Resource ('Range Error') Improper Access Control
|
CVE-2026-8545
|
2026-05-16 00:16 |
2026-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|