|
1831
|
9.8 |
CRITICAL
Network
|
-
|
-
|
T3 Technology CPE models T625Pro v1.0.07, T6825G v1.0.03, and T7281 v1.0.03 were discovered to contain a hardcoded password for root access under the "superadmin" account.
|
CWE-259
Use of Hard-coded Password
|
CVE-2026-35905
|
2026-06-9 00:16 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1832
|
9.8 |
CRITICAL
Network
|
-
|
-
|
Incorrect access control in the web management interface of T3 Technology CPE models T625Pro v1.0.07, T6825G v1.0.03, and T7281 v1.0.03 allows unauthorized attackers to enable the Telnet service via …
|
CWE-284
Improper Access Control
|
CVE-2026-35904
|
2026-06-9 00:16 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1833
|
8.4 |
HIGH
Local
|
-
|
-
|
clash-verge-service-ipc before 2.3.0 has a world-reachable IPC endpoint, leading to local privilege escalation.
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2026-26422
|
2026-06-9 00:16 |
2026-06-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1834
|
3.5 |
LOW
Network
|
-
|
-
|
A weakness has been identified in Bolt CMS up to 3.7.5. This vulnerability affects unknown code of the file src/Storage/Field/Type/TextType.php of the component HTML Attribute Handler. Executing a ma…
|
CWE-74 CWE-80
Injection Basic XSS
|
CVE-2026-11511
|
2026-06-9 00:16 |
2026-06-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1835
|
7.1 |
HIGH
Local
|
-
|
-
|
Markdown Preview Enhanced 0.8.x with crossnote engine 0.9.28 contains a code injection vulnerability in the WaveDrom rendering pipeline that allows attackers to execute arbitrary JavaScript by embedd…
|
CWE-95
Eval Injection
|
CVE-2026-11422
|
2026-06-9 00:16 |
2026-06-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1836
|
9.6 |
CRITICAL
Network
|
google
|
chrome
|
Type Confusion in GPU in Google Chrome on Windows prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML …
|
CWE-843
Type Confusion
|
CVE-2026-11052
|
2026-06-9 00:08 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1837
|
6.5 |
MEDIUM
Network
|
google
|
chrome
|
Out of bounds read in ANGLE in Google Chrome on Linux prior to 149.0.7827.53 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromi…
|
CWE-125
Out-of-bounds Read
|
CVE-2026-11051
|
2026-06-9 00:08 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1838
|
6.5 |
MEDIUM
Network
|
google
|
chrome
|
Inappropriate implementation in Extensions in Google Chrome prior to 149.0.7827.53 allowed an attacker who convinced a user to install a malicious extension to bypass same origin policy via a crafted…
|
CWE-346
Origin Validation Error
|
CVE-2026-11048
|
2026-06-9 00:04 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1839
|
9.6 |
CRITICAL
Network
|
google
|
chrome
|
Inappropriate implementation in Base in Google Chrome on Windows prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via …
|
CWE-20
Improper Input Validation
|
CVE-2026-11047
|
2026-06-9 00:03 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1840
|
7.5 |
HIGH
Network
|
-
|
-
|
Comodo Internet Security's firewall driver Inspect.sys contains an integer underflow in its IPv6 packet parser. The parser decrements an unsigned 64-bit payload-length value (taken from the IPv6 fixe…
|
CWE-191
Integer Underflow (Wrap or Wraparound)
|
CVE-2026-49494
|
2026-06-9 00:03 |
2026-06-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|