|
611
|
8.3 |
HIGH
Network
|
-
|
-
|
Use after free in HID in Google Chrome prior to 148.0.7778.168 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially perform a sandbox escape via a crafted H…
New
|
CWE-416
Use After Free
|
CVE-2026-8515
|
2026-05-15 07:16 |
2026-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
612
|
8.3 |
HIGH
Network
|
-
|
-
|
Use after free in Aura in Google Chrome prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Ch…
New
|
CWE-416
Use After Free
|
CVE-2026-8514
|
2026-05-15 07:16 |
2026-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
613
|
8.3 |
HIGH
Network
|
-
|
-
|
Use after free in Input in Google Chrome on Android prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HT…
New
|
CWE-416
Use After Free
|
CVE-2026-8513
|
2026-05-15 07:16 |
2026-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
614
|
8.3 |
HIGH
Network
|
-
|
-
|
Use after free in FileSystem in Google Chrome prior to 148.0.7778.168 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially perform a sandbox escape via a cr…
New
|
CWE-416
Use After Free
|
CVE-2026-8512
|
2026-05-15 07:16 |
2026-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
615
|
7.5 |
HIGH
Network
|
-
|
-
|
Integer overflow in Skia in Google Chrome on Windows prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to perform an out of bounds memory write via a crafted …
New
|
CWE-472
External Control of Assumed-Immutable Web Parameter
|
CVE-2026-8510
|
2026-05-15 07:16 |
2026-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
616
|
- |
|
-
|
-
|
Fleet is open source device management software. Prior to version 4.82.0, a vulnerability in Fleet's Windows MDM enrollment flow allows authentication tokens from any Azure AD tenant to be accepted. …
New
|
CWE-290
Authentication Bypass by Spoofing
|
CVE-2026-24899
|
2026-05-15 06:24 |
2026-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
617
|
- |
|
-
|
-
|
Fleet is open source device management software. Prior to version 4.81.0, Fleet contained a denial-of-service (DoS) issue in the gRPC Launcher `PublishLogs` endpoint. In affected versions, certain un…
New
|
CWE-20
Improper Input Validation
|
CVE-2026-26062
|
2026-05-15 06:24 |
2026-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
618
|
- |
|
-
|
-
|
Fleet is open source device management software. Prior to version 4.81.0, a vulnerability in Fleet's software installer pipeline could allow a crafted software package to execute arbitrary commands a…
New
|
CWE-78
OS Command
|
CVE-2026-26191
|
2026-05-15 06:24 |
2026-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
619
|
- |
|
-
|
-
|
Fleet is open source device management software. Prior to version 4.80.1, a vulnerability in Fleet's IP extraction logic allows unauthenticated attackers to bypass API rate limiting by spoofing clien…
New
|
CWE-290
Authentication Bypass by Spoofing
|
CVE-2026-46356
|
2026-05-15 06:24 |
2026-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
620
|
8.3 |
HIGH
Network
|
-
|
-
|
SiYuan is an open-source personal knowledge management system. From 2.1.12 to before 3.7.0. SiYuan's Bazaar marketplace renders package author metadata from the public bazaar stage feed into HTML wit…
New
|
CWE-79 CWE-94
Cross-site Scripting Code Injection
|
CVE-2026-44586
|
2026-05-15 06:22 |
2026-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|