|
611
|
8.8 |
HIGH
Network
|
google
|
chrome
|
Out of bounds write in WebAudio in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Hig…
Update
|
CWE-787
Out-of-bounds Write
|
CVE-2026-8524
|
2026-05-19 04:43 |
2026-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
612
|
8.8 |
HIGH
Network
|
google
|
chrome
|
Out of bounds write in WebRTC in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
Update
|
CWE-787
Out-of-bounds Write
|
CVE-2026-8526
|
2026-05-19 04:43 |
2026-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
613
|
8.8 |
HIGH
Network
|
google
|
chrome
|
Insufficient validation of untrusted input in Downloads in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severi…
Update
|
CWE-20
Improper Input Validation
|
CVE-2026-8527
|
2026-05-19 04:42 |
2026-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
614
|
4.3 |
MEDIUM
Network
|
google
|
chrome
|
Insufficient validation of untrusted input in SiteIsolation in Google Chrome prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to bypass Site Isolation via a …
Update
|
CWE-20
Improper Input Validation
|
CVE-2026-8528
|
2026-05-19 04:42 |
2026-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
615
|
6.2 |
MEDIUM
Local
|
-
|
-
|
Internet Download Manager 6.38.12 contains a buffer overflow vulnerability in the Scheduler component that allows local attackers to crash the application by supplying oversized input. Attackers can …
Update
|
CWE-120
Classic Buffer Overflow
|
CVE-2020-37234
|
2026-05-19 04:42 |
2026-05-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
616
|
6.4 |
MEDIUM
Network
|
-
|
-
|
NewsLister contains an authenticated persistent cross-site scripting vulnerability that allows authenticated administrators to inject malicious scripts through the title parameter in the news additio…
Update
|
CWE-79
Cross-site Scripting
|
CVE-2020-37236
|
2026-05-19 04:42 |
2026-05-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
617
|
8.2 |
HIGH
Network
|
-
|
-
|
EgavilanMedia PHPCRUD 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the firstname parameter. Attackers…
Update
|
CWE-89
SQL Injection
|
CVE-2021-47956
|
2026-05-19 04:42 |
2026-05-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
618
|
9.8 |
CRITICAL
Network
|
-
|
-
|
ACL Analytics versions 11.x through 13.0.0.579 contain an arbitrary code execution vulnerability that allows attackers to execute arbitrary commands by leveraging the EXECUTE function. Attackers can …
New
|
CWE-94
Code Injection
|
CVE-2018-25320
|
2026-05-19 04:42 |
2026-05-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
619
|
6.1 |
MEDIUM
Network
|
-
|
-
|
Zenar Content Management System contains a cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by manipulating form parameters in POST requests. Attac…
New
|
CWE-79
Cross-site Scripting
|
CVE-2018-25331
|
2026-05-19 04:42 |
2026-05-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
620
|
6.1 |
MEDIUM
Network
|
-
|
-
|
DumbAssets through 1.0.11 contains a stored cross-site scripting vulnerability in asset fields including name, description, modelNumber, serialNumber, and tags that are stored without server-side san…
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-45231
|
2026-05-19 04:42 |
2026-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|