|
2091
|
4.3 |
MEDIUM
Network
|
google
|
chrome
|
Insufficient validation of untrusted input in Password Manager in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to perform UI spoofing via malicious network traffic. (Chromium securi…
|
CWE-20 NVD-CWE-noinfo
Improper Input Validation
|
CVE-2026-11031
|
2026-06-8 22:40 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2092
|
6.5 |
MEDIUM
Network
|
google
|
chrome
|
Inappropriate implementation in Password Manager in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medi…
|
CWE-346
Origin Validation Error
|
CVE-2026-11032
|
2026-06-8 22:39 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2093
|
6.5 |
MEDIUM
Network
|
google
|
chrome
|
Uninitialized Use in WebML in Google Chrome on Mac prior to 149.0.7827.53 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium …
|
CWE-457
Use of Uninitialized Variable
|
CVE-2026-11033
|
2026-06-8 22:39 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2094
|
6.1 |
MEDIUM
Network
|
google
|
chrome
|
Insufficient validation of untrusted input in Tab Group Sync in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via malicious netw…
|
CWE-20
Improper Input Validation
|
CVE-2026-11034
|
2026-06-8 22:38 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2095
|
6.1 |
MEDIUM
Network
|
cisco
|
webex_meetings
|
A vulnerability in the web-based user interface of Cisco Webex Meetings could have allowed an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack. Cisco has addressed this…
|
CWE-79
Cross-site Scripting
|
CVE-2026-20233
|
2026-06-8 22:36 |
2026-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2096
|
8.1 |
HIGH
Network
|
misp
|
misp
|
A security issue was fixed in the correlations over-correlation endpoint where the order query parameter was accepted from user-controlled named request parameters. This allowed an authenticated user…
|
CWE-20
Improper Input Validation
|
CVE-2026-10863
|
2026-06-8 22:35 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2097
|
7.3 |
HIGH
Local
|
google
|
chrome
|
Inappropriate implementation in Custom Tabs in Google Chrome on Android prior to 149.0.7827.53 allowed a local attacker to perform privilege escalation via a crafted XML file. (Chromium security seve…
|
CWE-20 NVD-CWE-noinfo
Improper Input Validation
|
CVE-2026-11035
|
2026-06-8 22:34 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2098
|
6.5 |
MEDIUM
Network
|
google
|
chrome
|
Inappropriate implementation in DOM in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium security severity: Medium)
|
CWE-346
Origin Validation Error
|
CVE-2026-11036
|
2026-06-8 22:34 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2099
|
6.5 |
MEDIUM
Network
|
google
|
chrome
|
Uninitialized Use in Skia in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
|
CWE-457
Use of Uninitialized Variable
|
CVE-2026-11039
|
2026-06-8 22:31 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2100
|
8.8 |
HIGH
Network
|
google
|
chrome
|
Insufficient validation of untrusted input in Media in Google Chrome on Windows prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sand…
|
CWE-20 NVD-CWE-noinfo
Improper Input Validation
|
CVE-2026-11041
|
2026-06-8 22:31 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|