|
571
|
9.6 |
CRITICAL
Network
|
-
|
-
|
Due to improper Spring Security configuration, SAP Commerce Cloud allows an unauthenticated user to perform malicious input injection, resulting in arbitrary server-side code execution, leading to hi…
Update
|
CWE-459
Incomplete Cleanup
|
CVE-2026-34263
|
2026-05-15 21:17 |
2026-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
572
|
- |
|
-
|
-
|
In the Linux kernel, the following vulnerability has been resolved:
ksmbd: validate inherited ACE SID length
smb_inherit_dacl() walks the parent directory DACL loaded from the
security descriptor x…
New
|
-
|
CVE-2026-43490
|
2026-05-15 15:16 |
2026-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
573
|
4.2 |
MEDIUM
Network
|
-
|
-
|
Inappropriate implementation in Views in Google Chrome on iOS prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to perform UI spoofing via a crafted HTML page…
New
|
CWE-451
User Interface (UI) Misrepresentation of Critical Information
|
CVE-2026-8584
|
2026-05-15 07:16 |
2026-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
574
|
5.3 |
MEDIUM
Network
|
-
|
-
|
Insufficient policy enforcement in WebXR in Google Chrome on Android prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive informa…
New
|
CWE-693
Protection Mechanism Failure
|
CVE-2026-8583
|
2026-05-15 07:16 |
2026-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
575
|
5.3 |
MEDIUM
Network
|
-
|
-
|
Object lifecycle issue in Dawn in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium se…
New
|
CWE-664
Improper Control of a Resource Through its Lifetime
|
CVE-2026-8582
|
2026-05-15 07:16 |
2026-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
576
|
8.3 |
HIGH
Network
|
-
|
-
|
Use after free in UI in Google Chrome prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chro…
New
|
CWE-416
Use After Free
|
CVE-2026-8575
|
2026-05-15 07:16 |
2026-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
577
|
8.3 |
HIGH
Network
|
-
|
-
|
Use after free in Core in Google Chrome on Windows prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTM…
New
|
CWE-416
Use After Free
|
CVE-2026-8574
|
2026-05-15 07:16 |
2026-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
578
|
8.3 |
HIGH
Network
|
-
|
-
|
Integer overflow in Codecs in Google Chrome on Windows prior to 148.0.7778.168 allowed a remote attacker to potentially perform a sandbox escape via a crafted video file. (Chromium security severity:…
New
|
CWE-472
External Control of Assumed-Immutable Web Parameter
|
CVE-2026-8573
|
2026-05-15 07:16 |
2026-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
579
|
8.3 |
HIGH
Network
|
-
|
-
|
Insufficient policy enforcement in GPU in Google Chrome on Android prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape v…
New
|
CWE-693
Protection Mechanism Failure
|
CVE-2026-8571
|
2026-05-15 07:16 |
2026-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
580
|
6.5 |
MEDIUM
Network
|
-
|
-
|
Type Confusion in V8 in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security sev…
New
|
CWE-843
Type Confusion
|
CVE-2026-8570
|
2026-05-15 07:16 |
2026-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|