|
901
|
8.8 |
HIGH
Network
|
google
|
chrome
|
Use after free in Bluetooth in Google Chrome on Mac prior to 149.0.7827.103 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
New
|
CWE-416
Use After Free
|
CVE-2026-11699
|
2026-06-9 23:51 |
2026-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
902
|
9.6 |
CRITICAL
Network
|
google
|
chrome
|
Insufficient validation of untrusted input in UI in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security…
New
|
CWE-20
Improper Input Validation
|
CVE-2026-11697
|
2026-06-9 23:51 |
2026-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
903
|
5.3 |
MEDIUM
Network
|
google
|
chrome
|
Uninitialized Use in Video in Google Chrome on Windows prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from proc…
New
|
CWE-457
Use of Uninitialized Variable
|
CVE-2026-11696
|
2026-06-9 23:51 |
2026-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
904
|
4.3 |
MEDIUM
Network
|
google
|
chrome
|
Inappropriate implementation in Passwords in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)
New
|
CWE-693
Protection Mechanism Failure
|
CVE-2026-11695
|
2026-06-9 23:50 |
2026-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
905
|
8.8 |
HIGH
Network
|
google
|
chrome
|
Use after free in Bluetooth in Google Chrome on Mac prior to 149.0.7827.103 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
New
|
CWE-416
Use After Free
|
CVE-2026-11698
|
2026-06-9 23:50 |
2026-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
906
|
5.3 |
MEDIUM
Network
|
checkmk
|
checkmk
|
Incorrect authorization in the User Messages dashboard widget in Checkmk <2.5.0p5 causes the message-fetching endpoints to return the dashboard creator's messages rather than the viewer's, allowing a…
New
|
CWE-863
Incorrect Authorization
|
CVE-2026-7765
|
2026-06-9 23:49 |
2026-06-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
907
|
5.4 |
MEDIUM
Network
|
checkmk
|
checkmk
|
Improper neutralization of HTML-encoded characters in the URL validation function in Checkmk <2.5.0p5, <2.4.0p31, <2.3.0p48, and all 2.2.0 versions allows an authenticated user to bypass URL validati…
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-8833
|
2026-06-9 23:49 |
2026-06-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
908
|
- |
|
-
|
-
|
The Electron preload script in Logseq exposes an API method that allows the renderer process to invoke IPC handlers without proper path validation. An attacker with JavaScript execution in the render…
New
|
CWE-749
Exposed Dangerous Method or Function
|
CVE-2026-47899
|
2026-06-9 23:47 |
2026-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
909
|
- |
|
-
|
-
|
Logseq is vulnerable to a stored cross-site scripting (XSS). A malicious plugin can include a JavaScript payload in the "name" field of its "package.json" file, which is rendered using "innerHTML" wi…
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-47900
|
2026-06-9 23:47 |
2026-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
910
|
- |
|
-
|
-
|
Logseq is vulnerable to a sandbox escape flaw where plugins running in sandboxed iframes can inject arbitrary HTML attributes, such as event handlers, into their container element in the host DOM. Du…
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-47901
|
2026-06-9 23:47 |
2026-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|