|
841
|
- |
|
-
|
-
|
Insufficient validation of untrusted input in Printing in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a craft…
|
CWE-20
Improper Input Validation
|
CVE-2026-9980
|
2026-05-29 11:35 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
842
|
- |
|
-
|
-
|
Inappropriate implementation in Skia in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chrom…
|
-
|
CVE-2026-9981
|
2026-05-29 11:35 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
843
|
- |
|
-
|
-
|
Inappropriate implementation in Media in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to bypass same origin policy via a crafted video file. (Chromium security severity: High)
|
-
|
CVE-2026-9989
|
2026-05-29 11:35 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
844
|
- |
|
-
|
-
|
Use after free in WebAppInstalls in Google Chrome on Mac prior to 148.0.7778.216 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruptio…
|
CWE-416
Use After Free
|
CVE-2026-9990
|
2026-05-29 11:35 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
845
|
4.7 |
MEDIUM
Network
|
-
|
-
|
typescript-utcp is a typescript implementation of UTCP. Prior to 1.1.2, the @utcp/http package is vulnerable to a blind Server-Side Request Forgery (SSRF) caused by a trust-boundary inconsistency bet…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2026-45366
|
2026-05-29 07:17 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
846
|
7.3 |
HIGH
Network
|
-
|
-
|
Better Auth is an authentication and authorization library for TypeScript. Prior to 1.4.17 and 1.5.0-beta.9, Better Auth's HTTP rate limiter keyed each request by the exact textual IP address it rece…
|
CWE-307
mproper Restriction of Excessive Authentication Attempts
|
CVE-2026-45364
|
2026-05-29 07:17 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
847
|
7.5 |
HIGH
Network
|
-
|
-
|
Lakeside SysTrack Agent versions prior to 11.2.1.28, 11.3.0.38, 11.4.0.24, 11.5.0.15 contain an out-of-bounds read vulnerability in the Command ID 30 UDP packet handler that allows remote attackers t…
|
CWE-125 CWE-754
Out-of-bounds Read Improper Check for Unusual or Exceptional Conditions
|
CVE-2026-39929
|
2026-05-29 07:16 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
848
|
6.1 |
MEDIUM
Network
|
-
|
-
|
A reflected cross-site scripting issue exists in URL handling.
|
CWE-80
Basic XSS
|
CVE-2026-9646
|
2026-05-29 06:16 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
849
|
9.9 |
CRITICAL
Network
|
-
|
-
|
Exposed methods allow authenticated users to create and execute arbitrary JavaScript code on the server. The scripts execute with full access, enabling complete system compromise as commands are exec…
|
CWE-78
OS Command
|
CVE-2026-9645
|
2026-05-29 06:16 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
850
|
9.8 |
CRITICAL
Network
|
-
|
-
|
Marten is a .NET Transactional Document DB and Event Store on PostgreSQL. Prior to 8.36.1, Marten's full-text search APIs interpolated the user-supplied regConfig parameter directly into the generate…
|
CWE-89
SQL Injection
|
CVE-2026-45288
|
2026-05-29 06:16 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|