|
91
|
8.8 |
HIGH
Network
|
google
|
chrome
|
Type Confusion in V8 in Google Chrome prior to 148.0.7778.216 allowed an attacker who convinced a user to install a malicious extension to execute arbitrary code inside a sandbox via a crafted Chrome…
New
|
CWE-843
Type Confusion
|
CVE-2026-10022
|
2026-05-30 02:08 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
92
|
6.5 |
MEDIUM
Network
|
hono
|
hono
|
Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.21, the jwt and jwk middlewares do not verify that the Authorization header value uses theBearer sc…
New
|
CWE-285
Improper Authorization
|
CVE-2026-47673
|
2026-05-30 02:05 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
93
|
8.8 |
HIGH
Network
|
google
|
chrome
|
Use after free in Network in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Critical)
New
|
CWE-416
Use After Free
|
CVE-2026-9873
|
2026-05-30 02:05 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
94
|
9.6 |
CRITICAL
Network
|
google
|
chrome
|
Use after free in Dawn in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
New
|
CWE-416
Use After Free
|
CVE-2026-9874
|
2026-05-30 02:04 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
95
|
8.3 |
HIGH
Network
|
google
|
chrome
|
Use after free in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (C…
New
|
CWE-416
Use After Free
|
CVE-2026-9877
|
2026-05-30 02:00 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
96
|
5.3 |
MEDIUM
Network
|
hono
|
hono
|
Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.21, the ip-restriction middleware (hono/ip-restriction) compares incoming IP addresses against conf…
New
|
CWE-185 CWE-1289
Incorrect Regular Expression Improper Validation of Unsafe Equivalence in Input
|
CVE-2026-47674
|
2026-05-30 01:57 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
97
|
8.8 |
HIGH
Network
|
google
|
chrome
|
Use after free in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Critical)
New
|
CWE-416
Use After Free
|
CVE-2026-9878
|
2026-05-30 01:57 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
98
|
5.3 |
MEDIUM
Network
|
hono
|
hono
|
Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.21, the serialize() function in hono/cookie validates domain and path options against characters th…
New
|
CWE-113 CWE-1287
HTTP Response Splitting Improper Validation of Specified Type of Input
|
CVE-2026-47675
|
2026-05-30 01:56 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
99
|
5.3 |
MEDIUM
Network
|
hono
|
hono
|
Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.21, app.mount() strips the mount prefix from the incoming request path using the raw URL pathname, …
New
|
CWE-444 CWE-693
HTTP Request Smuggling Protection Mechanism Failure
|
CVE-2026-47676
|
2026-05-30 01:55 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
100
|
8.3 |
HIGH
Network
|
google
|
chrome
|
Use after free in GFX in Google Chrome on Mac prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML pag…
New
|
CWE-416
Use After Free
|
CVE-2026-9936
|
2026-05-30 01:52 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|