|
1621
|
- |
|
-
|
-
|
In the Linux kernel, the following vulnerability has been resolved:
mm/damon/core: disallow non-power of two min_region_sz on damon_start()
Commit d8f867fa0825 ("mm/damon: add damon_ctx->min_sz_reg…
|
-
|
CVE-2026-52905
|
2026-06-9 23:16 |
2026-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1622
|
- |
|
-
|
-
|
In the Linux kernel, the following vulnerability has been resolved:
drm/nouveau: fix nvkm_device leak on aperture removal failure
When aperture_remove_conflicting_pci_devices() fails during probe, …
|
-
|
CVE-2026-52904
|
2026-06-9 23:16 |
2026-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1623
|
5.3 |
MEDIUM
Network
|
-
|
-
|
The WPForms WordPress plugin before 1.10.0.5 does not verify the authenticity of incoming PayPal webhook events before processing them, allowing unauthenticated attackers to forge webhook payloads a…
|
CWE-862
Missing Authorization
|
CVE-2026-4986
|
2026-06-9 23:16 |
2026-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1624
|
- |
|
-
|
-
|
In the Linux kernel, the following vulnerability has been resolved:
erofs: handle end of filesystem properly for file-backed mounts
I/O requests beyond the end of the filesystem should be zeroed ou…
|
-
|
CVE-2026-46329
|
2026-06-9 23:16 |
2026-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1625
|
6.1 |
MEDIUM
Network
|
-
|
-
|
Multiple reflected Cross-Site Scripting (XSS) vulnerabilities in damasac thaipalliative_lte through version 3.0 allow remote attackers to inject arbitrary web script or HTML via the idFormMain parame…
|
CWE-79
Cross-site Scripting
|
CVE-2026-38579
|
2026-06-9 23:16 |
2026-06-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1626
|
- |
|
-
|
-
|
A vulnerability in the quarantine and restore workflow of the X-VPN macOS website versions 77.0 through 77.5 allow a local attacker to leverage a race condition and symlink manipulation to achieve pr…
|
CWE-367
Time-of-check Time-of-use (TOCTOU) Race Condition
|
CVE-2026-2638
|
2026-06-9 23:16 |
2026-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1627
|
8.3 |
HIGH
Network
|
-
|
-
|
Integer overflow in libyuv in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.…
|
CWE-472
External Control of Assumed-Immutable Web Parameter
|
CVE-2026-11640
|
2026-06-9 23:16 |
2026-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1628
|
8.8 |
HIGH
Network
|
-
|
-
|
Versions of the package degit before 2.8.6, from 3.0.0 and before 3.3.1 are vulnerable to Command Injection due to improper sanitisation of user input for git shell commands directly invoked with exe…
|
CWE-78 CWE-77
OS Command Command Injection
|
CVE-2026-11572
|
2026-06-9 23:16 |
2026-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1629
|
6.5 |
MEDIUM
Network
|
google
|
chrome
|
Insufficient policy enforcement in CSS in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)
|
CWE-693
Protection Mechanism Failure
|
CVE-2026-11288
|
2026-06-9 22:59 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1630
|
6.5 |
MEDIUM
Network
|
google
|
chrome
|
Side-channel information leakage in Paint in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)
|
CWE-1300 CWE-203
Improper Protection of Physical Side Channels Information Exposure Through Discrepancy
|
CVE-2026-11289
|
2026-06-9 22:58 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|