|
1291
|
8.8 |
HIGH
Network
|
-
|
-
|
@pensar/apex <= 0.0.58 is vulnerable to OS command injection via the smart_enumerate tool. The createSmartEnumerateTool() function in src/core/agent/tools.ts constructs a shell command by concatenati…
|
CWE-78
OS Command
|
CVE-2026-36044
|
2026-06-3 13:17 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1292
|
8.3 |
HIGH
Network
|
google
|
chrome
|
Use after free in Passwords in Google Chrome on Windows prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafte…
|
CWE-416
Use After Free
|
CVE-2026-10000
|
2026-06-3 11:32 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1293
|
6.5 |
MEDIUM
Network
|
google
|
chrome
|
Uninitialized Use in GPU in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromi…
|
CWE-457
Use of Uninitialized Variable
|
CVE-2026-10008
|
2026-06-3 11:31 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1294
|
5.0 |
MEDIUM
Network
|
google
|
chrome
|
Inappropriate implementation in Input in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTM…
|
CWE-346
Origin Validation Error
|
CVE-2026-10010
|
2026-06-3 11:31 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1295
|
3.1 |
LOW
Network
|
google
|
chrome
|
Inappropriate implementation in Skia in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Ch…
|
CWE-200
Information Exposure
|
CVE-2026-10011
|
2026-06-3 11:30 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1296
|
8.3 |
HIGH
Network
|
google
|
chrome
|
Out of bounds read in Headless in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML p…
|
CWE-125
Out-of-bounds Read
|
CVE-2026-10017
|
2026-06-3 11:30 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1297
|
9.0 |
CRITICAL
Network
|
google
|
chrome
|
Use after free in Bluetooth in Google Chrome on Mac prior to 148.0.7778.216 allowed an attacker who convinced a user to install a malicious extension to potentially perform a sandbox escape via a cra…
|
CWE-416
Use After Free
|
CVE-2026-9881
|
2026-06-3 11:30 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1298
|
8.3 |
HIGH
Network
|
google
|
chrome
|
Insufficient validation of untrusted input in UI in Google Chrome on Mac prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox es…
|
CWE-20
Improper Input Validation
|
CVE-2026-9885
|
2026-06-3 11:29 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1299
|
9.6 |
CRITICAL
Network
|
google
|
chrome
|
Use after free in Base in Google Chrome on Mac prior to 148.0.7778.216 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
|
CWE-416
Use After Free
|
CVE-2026-9886
|
2026-06-3 11:29 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1300
|
8.3 |
HIGH
Network
|
google
|
chrome
|
Use after free in XR in Google Chrome on Windows prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML …
|
CWE-416
Use After Free
|
CVE-2026-9890
|
2026-06-3 11:25 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|