|
861
|
5.3 |
MEDIUM
Network
|
hono
|
hono
|
Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.21, app.mount() strips the mount prefix from the incoming request path using the raw URL pathname, …
|
CWE-444 CWE-693
HTTP Request Smuggling Protection Mechanism Failure
|
CVE-2026-47676
|
2026-05-30 01:55 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
862
|
8.3 |
HIGH
Network
|
google
|
chrome
|
Use after free in GFX in Google Chrome on Mac prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML pag…
|
CWE-416
Use After Free
|
CVE-2026-9936
|
2026-05-30 01:52 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
863
|
8.3 |
HIGH
Network
|
google
|
chrome
|
Use after free in UI in Google Chrome on Windows prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML …
|
CWE-416
Use After Free
|
CVE-2026-9937
|
2026-05-30 01:52 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
864
|
8.3 |
HIGH
Network
|
google
|
chrome
|
Use after free in Views in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted PDF file. (Ch…
|
CWE-416
Use After Free
|
CVE-2026-9993
|
2026-05-30 01:52 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
865
|
8.3 |
HIGH
Network
|
google
|
chrome
|
Use after free in Core in Google Chrome on Windows prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTM…
|
CWE-416
Use After Free
|
CVE-2026-9994
|
2026-05-30 01:51 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
866
|
8.3 |
HIGH
Network
|
google
|
chrome
|
Use after free in Input in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (C…
|
CWE-416
Use After Free
|
CVE-2026-9997
|
2026-05-30 01:51 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
867
|
7.5 |
HIGH
Network
|
google
|
chrome
|
Use after free in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to execute arbitrary code via a crafted HTML page. (Chromium securi…
|
CWE-416
Use After Free
|
CVE-2026-9901
|
2026-05-30 01:47 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
868
|
7.5 |
HIGH
Network
|
google
|
chrome
|
Use after free in GPU in Google Chrome on Mac prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to execute arbitrary code via a crafted HTML page. (Chromium s…
|
CWE-416
Use After Free
|
CVE-2026-9922
|
2026-05-30 01:46 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
869
|
8.8 |
HIGH
Network
|
google
|
chrome
|
Integer overflow in V8 in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
|
CWE-472
External Control of Assumed-Immutable Web Parameter
|
CVE-2026-9968
|
2026-05-30 01:44 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
870
|
8.8 |
HIGH
Network
|
google
|
chrome
|
Out of bounds write in V8 in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
|
CWE-787
Out-of-bounds Write
|
CVE-2026-9973
|
2026-05-30 01:44 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|