|
161
|
8.3 |
HIGH
Network
|
google
|
chrome
|
Integer overflow in GPU in Google Chrome on Linux and ChromeOS prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a…
Update
|
CWE-472
External Control of Assumed-Immutable Web Parameter
|
CVE-2026-8534
|
2026-05-20 01:26 |
2026-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
162
|
5.3 |
MEDIUM
Network
|
google
|
chrome
|
Out of bounds read in Media in Google Chrome on Linux and ChromeOS prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive informati…
Update
|
CWE-125
Out-of-bounds Read
|
CVE-2026-8535
|
2026-05-20 01:26 |
2026-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
163
|
3.1 |
LOW
Network
|
google
|
chrome
|
Insufficient validation of untrusted input in ReadingMode in Google Chrome on Mac prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to bypass site Isolation v…
Update
|
CWE-20 NVD-CWE-noinfo
Improper Input Validation
|
CVE-2026-8536
|
2026-05-20 01:26 |
2026-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
164
|
9.8 |
CRITICAL
Network
|
wgdashboard
|
wgdashboard
|
WGDashboard is a dashboard for WireGuard VPN. Prior to 4.3.2, there are critical vulnerabilities affecting WGDashboard that, if exploited, could allow unauthorized parties to access the host file sys…
Update
|
CWE-20
Improper Input Validation
|
CVE-2026-44343
|
2026-05-20 01:21 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
165
|
7.6 |
HIGH
Network
|
pocketbase
|
pocketbase
|
Pocketbase is an open source web backend written in go. Prior to 0.22.42 and 0.37.4, in some situations, if an attacker knows the email address of the victim they can create and link an unverified Po…
Update
|
CWE-287
Improper Authentication
|
CVE-2026-44166
|
2026-05-20 01:20 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
166
|
5.4 |
MEDIUM
Network
|
google
|
chrome
|
Script injection in SanitizerAPI in Google Chrome on Android prior to 148.0.7778.168 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page. (Chromium security s…
Update
|
CWE-94
Code Injection
|
CVE-2026-8539
|
2026-05-20 01:18 |
2026-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
167
|
7.5 |
HIGH
Network
|
-
|
-
|
Sandbox escape in Firefox and Firefox Focus for Android. This vulnerability was fixed in Firefox 151.
New
|
CWE-693
Protection Mechanism Failure
|
CVE-2026-8945
|
2026-05-20 01:16 |
2026-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
168
|
5.5 |
MEDIUM
Local
|
-
|
-
|
In the Linux kernel, the following vulnerability has been resolved:
ptrace: slightly saner 'get_dumpable()' logic
The 'dumpability' of a task is fundamentally about the memory image of
the task - t…
Update
|
CWE-269
Improper Privilege Management
|
CVE-2026-46333
|
2026-05-20 01:16 |
2026-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
169
|
8.8 |
HIGH
Network
|
axis
|
axis_os
|
A configuration file on the local file system had improper input validation which could allow code execution and potentially lead to privilege escalation. This vulnerability can only be exploited if …
Update
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2026-1185
|
2026-05-20 01:07 |
2026-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
170
|
7.3 |
HIGH
Local
|
axis
|
axis_os
|
An ACAP configuration file lacked sufficient input validation, which could allow a path traversal attack leading to potential privilege escalation. This vulnerability can only be exploited if the Axi…
Update
|
CWE-35
Path Traversal: '.../...//'
|
CVE-2026-0804
|
2026-05-20 01:06 |
2026-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|