CVE Feed

    Dashboard / CVE

    8.8
    High

    CVE-2026-10957

    Last Modified: 6 Jun 2026

    Use after free in Glic in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

    Published: 2 Jun 2026
    8.8
    High

    CVE-2026-10965

    Last Modified: 6 Jun 2026

    Integer overflow in DevTools in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

    Published: 2 Jun 2026
    9.6
    Critical

    CVE-2026-10990

    Last Modified: 7 Jun 2026

    Use after free in Glic in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)

    Published: 2 Jun 2026
    8.8
    High

    CVE-2026-11000

    Last Modified: 6 Jun 2026

    Use after free in Fonts in Google Chrome on Linux prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)

    Published: 2 Jun 2026
    9.6
    Critical

    CVE-2026-11002

    Last Modified: 7 Jun 2026

    Use after free in Autofill in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)

    Published: 2 Jun 2026
    8.8
    High

    CVE-2026-11028

    Last Modified: 6 Jun 2026

    Use after free in Media in Google Chrome on Linux and ChromeOS prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)

    Published: 2 Jun 2026
    8.8
    High

    CVE-2026-11050

    Last Modified: 6 Jun 2026

    Use after free in V8 in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)

    Published: 2 Jun 2026
    8.8
    High

    CVE-2026-11068

    Last Modified: 6 Jun 2026

    Use after free in WebSockets in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)

    Published: 2 Jun 2026
    8.8
    High

    CVE-2026-11074

    Last Modified: 6 Jun 2026

    Use after free in WebRTC in Google Chrome on Linux prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: Medium)

    Published: 2 Jun 2026
    8.8
    High

    CVE-2026-11077

    Last Modified: 6 Jun 2026

    Bad cast in Dawn in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)

    Published: 2 Jun 2026
    8.8
    High

    CVE-2026-11117

    Last Modified: 6 Jun 2026

    Use after free in Views in Google Chrome on Windows prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: Medium)

    Published: 2 Jun 2026
    8.8
    High

    CVE-2026-11118

    Last Modified: 6 Jun 2026

    Use after free in WebRTC in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)

    Published: 2 Jun 2026
    8.8
    High

    CVE-2026-11130

    Last Modified: 6 Jun 2026

    Use after free in Media in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)

    Published: 2 Jun 2026
    8.8
    High

    CVE-2026-11136

    Last Modified: 6 Jun 2026

    Use after free in Canvas in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)

    Published: 2 Jun 2026
    8.8
    High

    CVE-2026-11164

    Last Modified: 6 Jun 2026

    Use after free in Blink in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)

    Published: 2 Jun 2026
    8.8
    High

    CVE-2026-11173

    Last Modified: 6 Jun 2026

    Out of bounds write in V8 in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)

    Published: 2 Jun 2026
    6.8
    Medium

    CVE-2026-11218

    Last Modified: 6 Jun 2026

    Inappropriate implementation in PlatformIntegration in Google Chrome on Windows prior to 149.0.7827.53 allowed a remote attacker who convinced a user to engage in specific UI gestures to execute arbitrary code via a malicious file. (Chromium security severity: Low)

    Published: 2 Jun 2026
    8.1
    High

    CVE-2026-11224

    Last Modified: 6 Jun 2026

    Use after free in Chromoting in Google Chrome on Linux prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code via malicious network traffic. (Chromium security severity: Low)

    Published: 2 Jun 2026
    8.8
    High

    CVE-2026-11307

    Last Modified: 8 Jun 2026

    Use after free in PDFium in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted PDF file. (Chromium security severity: Low)

    Published: 2 Jun 2026
    9.6
    Critical

    CVE-2026-11167

    Last Modified: 8 Jun 2026

    Inappropriate implementation in WebView in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)

    Published: 2 Jun 2026
    6.5
    Medium

    CVE-2026-11227

    Last Modified: 7 Jun 2026

    Incorrect security UI in Tab Hover Cards in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to perform domain spoofing via a crafted domain name. (Chromium security severity: Low)

    Published: 2 Jun 2026
    5.4
    Medium

    CVE-2026-11243

    Last Modified: 7 Jun 2026

    Inappropriate implementation in Downloads in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Low)

    Published: 2 Jun 2026
    8.3
    High

    CVE-2026-11010

    Last Modified: 8 Jun 2026

    Use after free in WebShare in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)

    Published: 2 Jun 2026
    8.3
    High

    CVE-2026-11012

    Last Modified: 8 Jun 2026

    Use after free in Serial in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)

    Published: 2 Jun 2026
    6.5
    Medium

    CVE-2026-11032

    Last Modified: 8 Jun 2026

    Inappropriate implementation in Password Manager in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)

    Published: 2 Jun 2026
    7.3
    High

    CVE-2026-11035

    Last Modified: 8 Jun 2026

    Inappropriate implementation in Custom Tabs in Google Chrome on Android prior to 149.0.7827.53 allowed a local attacker to perform privilege escalation via a crafted XML file. (Chromium security severity: Medium)

    Published: 2 Jun 2026
    8.8
    High

    CVE-2026-11041

    Last Modified: 8 Jun 2026

    Insufficient validation of untrusted input in Media in Google Chrome on Windows prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)

    Published: 2 Jun 2026
    9.6
    Critical

    CVE-2026-11043

    Last Modified: 8 Jun 2026

    Out of bounds write in ANGLE in Google Chrome on Mac prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)

    Published: 2 Jun 2026
    9.6
    Critical

    CVE-2026-11082

    Last Modified: 8 Jun 2026

    Race in GPU in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)

    Published: 2 Jun 2026
    6.5
    Medium

    CVE-2026-11089

    Last Modified: 8 Jun 2026

    Uninitialized Use in Media in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)

    Published: 2 Jun 2026
    8.3
    High

    CVE-2026-11237

    Last Modified: 9 Jun 2026

    Insufficient validation of untrusted input in Media in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)

    Published: 2 Jun 2026
    6.5
    Medium

    CVE-2026-11134

    Last Modified: 8 Jun 2026

    Inappropriate implementation in Media in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)

    Published: 2 Jun 2026
    6.5
    Medium

    CVE-2026-11135

    Last Modified: 8 Jun 2026

    Insufficient policy enforcement in Autofill in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to bypass discretionary access control via a crafted HTML page. (Chromium security severity: Medium)

    Published: 2 Jun 2026
    8.8
    High

    CVE-2026-11092

    Last Modified: 8 Jun 2026

    Insufficient policy enforcement in DevTools in Google Chrome prior to 149.0.7827.53 allowed an attacker who convinced a user to install a malicious extension to perform privilege escalation via a crafted Chrome Extension. (Chromium security severity: Medium)

    Published: 2 Jun 2026
    6.5
    Medium

    CVE-2026-11137

    Last Modified: 8 Jun 2026

    Uninitialized Use in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)

    Published: 2 Jun 2026
    6.5
    Medium

    CVE-2026-11139

    Last Modified: 8 Jun 2026

    Inappropriate implementation in Paint in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)

    Published: 2 Jun 2026
    6.5
    Medium

    CVE-2026-11160

    Last Modified: 8 Jun 2026

    Out of bounds read in Input in Google Chrome on Linux prior to 149.0.7827.53 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)

    Published: 2 Jun 2026
    4.3
    Medium

    CVE-2026-11107

    Last Modified: 8 Jun 2026

    Inappropriate implementation in Downloads in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)

    Published: 2 Jun 2026
    8.8
    High

    CVE-2026-11108

    Last Modified: 8 Jun 2026

    Inappropriate implementation in NFC in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker to perform privilege escalation via a crafted HTML page. (Chromium security severity: Medium)

    Published: 2 Jun 2026
    6.5
    Medium

    CVE-2026-11110

    Last Modified: 8 Jun 2026

    Uninitialized Use in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)

    Published: 2 Jun 2026
    8.8
    High

    CVE-2026-11116

    Last Modified: 8 Jun 2026

    Use after free in Chromoting in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code via malicious network traffic. (Chromium security severity: Medium)

    Published: 2 Jun 2026
    6.5
    Medium

    CVE-2026-11132

    Last Modified: 8 Jun 2026

    Insufficient policy enforcement in Paint in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium security severity: Medium)

    Published: 2 Jun 2026
    4.3
    Medium

    CVE-2026-11162

    Last Modified: 8 Jun 2026

    Inappropriate implementation in CSS in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)

    Published: 2 Jun 2026
    6.8
    Medium

    CVE-2026-11166

    Last Modified: 8 Jun 2026

    Inappropriate implementation in SVG in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page. (Chromium security severity: Medium)

    Published: 2 Jun 2026
    8.8
    High

    CVE-2026-30650

    Last Modified: 3 Jun 2026

    A post-authentication remote buffer overflow vulnerability exists in the /cgi-bin/admin/eventtask.cgi endpoint of the admin interface of Vivotek FD8136 cameras running firmware version FD8136-VVTK-0300a. This flaw allows an authenticated attacker to execute arbitrary code as root on the device remotely.

    Published: 2 Jun 2026
    8.8
    High

    CVE-2026-30652

    Last Modified: 3 Jun 2026

    A remote buffer overflow vulnerability exists in the /cgi-bin/dido/setdo.cgi endpoint of the admin interface of Vivotek FD8136 cameras running firmware version FD8136-VVTK-0300a. This flaw allows an authenticated attacker to execute arbitrary code as root on the device.

    Published: 2 Jun 2026
    7.3
    High

    CVE-2026-30649

    Last Modified: 3 Jun 2026

    Buffer Overflow vulnerability in VIVOTEK INC FD8136-VVTK-0300a allows a remote attacker to execute arbitrary code via the set_getparam.cgi component

    Published: 2 Jun 2026
    5.3
    Medium

    CVE-2026-38978

    Last Modified: 5 Jun 2026

    transmission through 4.1.1 was found to have a clickjacking weakness in the browser-facing WebUI and RPC response paths.

    Published: 2 Jun 2026
    6.1
    Medium

    CVE-2026-30586

    Last Modified: 3 Jun 2026

    Cross Site Scripting vulnerability in usememos Memos v.0.26.0 allows a remote attacker to obtain sensitive information via the SANITIZE_SCHEMA, Memo Rendering Component, and Public/Private Memo View pages

    Published: 2 Jun 2026
    6.1
    Medium

    CVE-2026-33553

    Last Modified: 3 Jun 2026

    Northern.tech CFEngine Enterprise 3.24.3 before 3.24.4 and 3.27.0 before 3.27.1 allows XSS.

    Published: 2 Jun 2026