|
261
|
7.5 |
HIGH
Network
|
-
|
-
|
ipmi-oem in FreeIPMI before 1.6.18 has exploitable buffer overflows on response messages. The Intelligent Platform Management Interface (IPMI) specification defines a set of interfaces for platform m…
New
|
CWE-121
Stack-based Buffer Overflow
|
CVE-2026-50031
|
2026-06-3 15:16 |
2026-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
262
|
9.0 |
CRITICAL
Network
|
-
|
-
|
A flaw was found in Samba. A remote attacker can exploit a misconfiguration in Samba file servers and classic domain controllers that use the "check password script" feature. If this script is config…
Update
|
CWE-78
OS Command
|
CVE-2026-4408
|
2026-06-3 15:16 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
263
|
8.0 |
HIGH
Adjacent
|
-
|
-
|
A flaw was found in Samba’s certificate auto-enrollment Group Policy handling. When certificate auto-enrollment is enabled, Samba may retrieve a CA certificate over an unencrypted HTTP connection and…
Update
|
CWE-345
Insufficient Verification of Data Authenticity
|
CVE-2026-3012
|
2026-06-3 15:16 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
264
|
8.8 |
HIGH
Network
|
-
|
-
|
@pensar/apex <= 0.0.58 is vulnerable to OS command injection via the smart_enumerate tool. The createSmartEnumerateTool() function in src/core/agent/tools.ts constructs a shell command by concatenati…
Update
|
CWE-78
OS Command
|
CVE-2026-36044
|
2026-06-3 13:17 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265
|
8.3 |
HIGH
Network
|
google
|
chrome
|
Use after free in Passwords in Google Chrome on Windows prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafte…
Update
|
CWE-416
Use After Free
|
CVE-2026-10000
|
2026-06-3 11:32 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266
|
6.5 |
MEDIUM
Network
|
google
|
chrome
|
Uninitialized Use in GPU in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromi…
Update
|
CWE-457
Use of Uninitialized Variable
|
CVE-2026-10008
|
2026-06-3 11:31 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267
|
5.0 |
MEDIUM
Network
|
google
|
chrome
|
Inappropriate implementation in Input in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTM…
Update
|
CWE-346
Origin Validation Error
|
CVE-2026-10010
|
2026-06-3 11:31 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268
|
3.1 |
LOW
Network
|
google
|
chrome
|
Inappropriate implementation in Skia in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Ch…
Update
|
CWE-200
Information Exposure
|
CVE-2026-10011
|
2026-06-3 11:30 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269
|
8.3 |
HIGH
Network
|
google
|
chrome
|
Out of bounds read in Headless in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML p…
Update
|
CWE-125
Out-of-bounds Read
|
CVE-2026-10017
|
2026-06-3 11:30 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270
|
9.0 |
CRITICAL
Network
|
google
|
chrome
|
Use after free in Bluetooth in Google Chrome on Mac prior to 148.0.7778.216 allowed an attacker who convinced a user to install a malicious extension to potentially perform a sandbox escape via a cra…
Update
|
CWE-416
Use After Free
|
CVE-2026-9881
|
2026-06-3 11:30 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|