|
941
|
7.3 |
HIGH
Network
|
-
|
-
|
A vulnerability was identified in xiandafu beetl up to 3.20.2. Affected is an unknown function of the file beetl-classic-integration/beetl-spring-classic/src/main/java/org/beetl/ext/spring/SpELFuncti…
|
CWE-20 CWE-917
Improper Input Validation Improper Neutralization of Special Elements used in an Expression Language Statement ('Expression Language Injection')
|
CVE-2026-8759
|
2026-05-19 04:22 |
2026-05-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
942
|
5.3 |
MEDIUM
Network
|
google
|
chrome
|
Insufficient validation of untrusted input in DataTransfer in Google Chrome prior to 148.0.7778.168 allowed a remote attacker who convinced a user to engage in specific UI gestures to obtain potentia…
|
CWE-20
Improper Input Validation
|
CVE-2026-8516
|
2026-05-19 04:17 |
2026-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
943
|
8.8 |
HIGH
Network
|
google
|
chrome
|
Use after free in Blink in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Critical)
|
CWE-416
Use After Free
|
CVE-2026-8518
|
2026-05-19 04:17 |
2026-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
944
|
8.3 |
HIGH
Network
|
google
|
chrome
|
Race in Payments in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
|
CWE-362
Race Condition
|
CVE-2026-8520
|
2026-05-19 04:17 |
2026-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
945
|
7.5 |
HIGH
Adjacent
|
google
|
chrome
|
Use after free in Tab Groups in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to execute arbitrary code via malicious network traffic. (Chromium security severity: Critical)
|
CWE-416
Use After Free
|
CVE-2026-8521
|
2026-05-19 04:16 |
2026-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
946
|
8.3 |
HIGH
Network
|
google
|
chrome
|
Use after free in Mojo in Google Chrome prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Ch…
|
CWE-416
Use After Free
|
CVE-2026-8523
|
2026-05-19 04:14 |
2026-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
947
|
10.0 |
CRITICAL
Network
|
dhtmlx
|
pdf_export_module
|
PDF Export Module used in DHTMLX's products Gantt and Scheduler is vulnerable to Remote Code Execution due to lack of "data" parameter sanitization. An unauthenticated attacker can inject the malicio…
|
CWE-78
OS Command
|
CVE-2026-41553
|
2026-05-19 03:40 |
2026-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
948
|
8.7 |
HIGH
Network
|
mattermost
|
mattermost_server
|
Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13, 11.4.x <= 11.4.3 fail to sanitize sensitive configuration fields before including them in support packet generation, which allows a Mattermo…
|
CWE-200
Information Exposure
|
CVE-2026-6346
|
2026-05-19 03:39 |
2026-05-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
949
|
7.6 |
HIGH
Network
|
mattermost
|
mattermost_server
|
Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13, 11.4.x <= 11.4.3 fail to sanitize sensitive configuration fields in the Mattermost Calls plugin which allows an attacker with access to a su…
|
CWE-200
Information Exposure
|
CVE-2026-6347
|
2026-05-19 03:39 |
2026-05-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
950
|
9.8 |
CRITICAL
Network
|
radare
|
radare2
|
radare2 6.1.5 contains a use-after-free vulnerability in the gdbr_threads_list() function that allows remote attackers to trigger memory corruption by sending a valid qfThreadInfo response followed b…
|
CWE-416
Use After Free
|
CVE-2026-8695
|
2026-05-19 03:38 |
2026-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|