|
2531
|
7.1 |
HIGH
Local
|
-
|
-
|
Markdown Preview Enhanced 0.8.x with crossnote engine 0.9.28 contains a code injection vulnerability in the WaveDrom rendering pipeline that allows attackers to execute arbitrary JavaScript by embedd…
|
CWE-95
Eval Injection
|
CVE-2026-11422
|
2026-06-9 00:16 |
2026-06-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2532
|
9.6 |
CRITICAL
Network
|
google
|
chrome
|
Type Confusion in GPU in Google Chrome on Windows prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML …
|
CWE-843
Type Confusion
|
CVE-2026-11052
|
2026-06-9 00:08 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2533
|
6.5 |
MEDIUM
Network
|
google
|
chrome
|
Out of bounds read in ANGLE in Google Chrome on Linux prior to 149.0.7827.53 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromi…
|
CWE-125
Out-of-bounds Read
|
CVE-2026-11051
|
2026-06-9 00:08 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2534
|
6.5 |
MEDIUM
Network
|
google
|
chrome
|
Inappropriate implementation in Extensions in Google Chrome prior to 149.0.7827.53 allowed an attacker who convinced a user to install a malicious extension to bypass same origin policy via a crafted…
|
CWE-346
Origin Validation Error
|
CVE-2026-11048
|
2026-06-9 00:04 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2535
|
9.6 |
CRITICAL
Network
|
google
|
chrome
|
Inappropriate implementation in Base in Google Chrome on Windows prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via …
|
CWE-20
Improper Input Validation
|
CVE-2026-11047
|
2026-06-9 00:03 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2536
|
7.5 |
HIGH
Network
|
-
|
-
|
Comodo Internet Security's firewall driver Inspect.sys contains an integer underflow in its IPv6 packet parser. The parser decrements an unsigned 64-bit payload-length value (taken from the IPv6 fixe…
|
CWE-191
Integer Underflow (Wrap or Wraparound)
|
CVE-2026-49494
|
2026-06-9 00:03 |
2026-06-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2537
|
6.5 |
MEDIUM
Network
|
google
|
chrome
|
Insufficient validation of untrusted input in GPU in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive informatio…
|
CWE-20
Improper Input Validation
|
CVE-2026-11045
|
2026-06-9 00:02 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2538
|
8.0 |
HIGH
Network
|
termix
|
termix
|
Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. Starting in version 1.7.0, Termix Desktop (Electron) disables TLS certificate validation,…
|
CWE-295
Improper Certificate Validation
|
CVE-2026-45745
|
2026-06-9 00:02 |
2026-06-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2539
|
- |
|
-
|
-
|
Internationalized Domain Names in Applications (IDNA) for Python provides support for Internationalized Domain Names in Applications (IDNA) and Unicode IDNA Compatibility Processing. In versions prio…
|
CWE-1333
Inefficient Regular Expression Complexity
|
CVE-2026-45409
|
2026-06-9 00:02 |
2026-06-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2540
|
6.5 |
MEDIUM
Network
|
google
|
chrome
|
Integer overflow in ANGLE in Google Chrome on Mac prior to 149.0.7827.53 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium s…
|
CWE-472 CWE-190
External Control of Assumed-Immutable Web Parameter Integer Overflow or Wraparound
|
CVE-2026-11044
|
2026-06-9 00:01 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|