|
281
|
8.3 |
HIGH
Network
|
-
|
-
|
Inappropriate implementation in DevTools in Google Chrome prior to 149.0.7827.115 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a craf…
New
|
CWE-20
Improper Input Validation
|
CVE-2026-12016
|
2026-06-12 22:08 |
2026-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
282
|
3.1 |
LOW
Network
|
-
|
-
|
Inappropriate implementation in Extensions in Google Chrome prior to 149.0.7827.115 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page…
New
|
CWE-20
Improper Input Validation
|
CVE-2026-12017
|
2026-06-12 22:08 |
2026-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283
|
8.8 |
HIGH
Network
|
-
|
-
|
Inappropriate implementation in Mojo in Google Chrome on Windows prior to 149.0.7827.115 allowed a local attacker to perform OS-level privilege escalation via a malicious file. (Chromium security sev…
New
|
CWE-269
Improper Privilege Management
|
CVE-2026-12018
|
2026-06-12 22:08 |
2026-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284
|
8.3 |
HIGH
Network
|
-
|
-
|
Heap buffer overflow in Codecs in Google Chrome on Linux and ChromeOS prior to 149.0.7827.115 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escap…
New
|
CWE-787
Out-of-bounds Write
|
CVE-2026-12019
|
2026-06-12 22:08 |
2026-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285
|
8.8 |
HIGH
Network
|
-
|
-
|
Use after free in Autofill in Google Chrome on Mac prior to 149.0.7827.115 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
New
|
CWE-416
Use After Free
|
CVE-2026-12020
|
2026-06-12 22:08 |
2026-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
286
|
8.3 |
HIGH
Network
|
-
|
-
|
Race in Safe Browsing in Google Chrome on Mac prior to 149.0.7827.115 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a malicious file. …
New
|
CWE-362
Race Condition
|
CVE-2026-12022
|
2026-06-12 22:08 |
2026-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287
|
- |
|
-
|
-
|
Out of bounds read in Video in Google Chrome on ChromeOS prior to 149.0.7827.115 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from pr…
New
|
CWE-125
Out-of-bounds Read
|
CVE-2026-12026
|
2026-06-12 22:08 |
2026-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
288
|
- |
|
-
|
-
|
Apache CXF's EndpointReferenceUtils and W3CMultiSchemaFactory classes construct a SAXParserFactory without the necessary JAXP hardening configurations, enabling out-of-band (OOB)
external entity res…
New
|
CWE-611
XXE
|
CVE-2026-49875
|
2026-06-12 22:08 |
2026-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
289
|
- |
|
-
|
-
|
The JwtAccessTokenValidator class in Apache CXF fails to validate the 'aud' (Audience) claims of incoming JWT access tokens. This allows a JWT issued for one Resource Server to be successfully replay…
New
|
CWE-289
Authentication Bypass by Alternate Name
|
CVE-2026-50627
|
2026-06-12 22:08 |
2026-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
290
|
- |
|
-
|
-
|
A logic error in OAuthRequestFilter rejects legitimate requests originating from the bound IP address, while blindly allowing requests from any other IP address. Enabling this
security feature inadv…
New
|
CWE-20
Improper Input Validation
|
CVE-2026-50628
|
2026-06-12 22:08 |
2026-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|