|
481
|
9.8 |
CRITICAL
Network
|
-
|
-
|
The Piotnet Addons for Elementor Pro plugin for WordPress is vulnerable to arbitrary file upload due to missing file type validation in the 'pafe_ajax_form_builder' function in all versions up to, an…
New
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2026-4885
|
2026-05-19 23:38 |
2026-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
482
|
9.8 |
CRITICAL
Network
|
-
|
-
|
The Piotnet Forms plugin for WordPress is vulnerable to arbitrary file upload due to missing file type validation in the 'piotnetforms_ajax_form_builder' function in all versions up to, and including…
New
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2026-4883
|
2026-05-19 23:38 |
2026-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
483
|
7.5 |
HIGH
Network
|
-
|
-
|
The Contest Gallery plugin for WordPress is vulnerable to SQL Injection via the 'form_input' parameter in versions up to, and including, 28.1.6. This is due to insufficient escaping on the user suppl…
New
|
CWE-89
SQL Injection
|
CVE-2026-8912
|
2026-05-19 23:38 |
2026-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
484
|
6.3 |
MEDIUM
Network
|
tencent
|
weknora
|
A vulnerability has been found in Tencent WeKnora up to 0.3.6. Affected by this issue is the function getKnowledgeBaseForInitialization of the file internal/handler/initialization.go of the component…
New
|
CWE-285 CWE-639
Improper Authorization Authorization Bypass Through User-Controlled Key
|
CVE-2026-8786
|
2026-05-19 23:30 |
2026-05-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
485
|
5.3 |
MEDIUM
Network
|
google
|
chrome
|
Object lifecycle issue in Dawn in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium se…
Update
|
CWE-664
Improper Control of a Resource Through its Lifetime
|
CVE-2026-8582
|
2026-05-19 23:30 |
2026-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
486
|
7.5 |
HIGH
Network
|
vercel
|
ai
|
A vulnerability has been found in vercel ai up to 3.0.97. Impacted is the function run of the file .github/workflows/prettier-on-automerge.yml of the component PR Branch Name Interpolation. The manip…
New
|
CWE-77 CWE-78
Command Injection OS Command
|
CVE-2026-8767
|
2026-05-19 23:29 |
2026-05-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
487
|
4.3 |
MEDIUM
Network
|
google
|
chrome
|
Heap buffer overflow in GPU in Google Chrome on Android prior to 148.0.7778.168 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity…
Update
|
CWE-122
Heap-based Buffer Overflow
|
CVE-2026-8552
|
2026-05-19 23:27 |
2026-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
488
|
3.1 |
LOW
Network
|
google
|
chrome
|
Type Confusion in ANGLE in Google Chrome on Windows prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to perform an out of bounds memory write via a crafted H…
Update
|
CWE-843
Type Confusion
|
CVE-2026-8554
|
2026-05-19 23:27 |
2026-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
489
|
4.3 |
MEDIUM
Network
|
google
|
chrome
|
Heap buffer overflow in SwiftShader in Google Chrome on Mac and iOS prior to 148.0.7778.168 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium securi…
Update
|
CWE-122
Heap-based Buffer Overflow
|
CVE-2026-8560
|
2026-05-19 23:27 |
2026-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
490
|
4.3 |
MEDIUM
Network
|
google
|
chrome
|
Integer overflow in Internationalization in Google Chrome on Windows prior to 148.0.7778.168 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium secu…
Update
|
CWE-472
External Control of Assumed-Immutable Web Parameter
|
CVE-2026-8559
|
2026-05-19 23:26 |
2026-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|