CVE Feed

    Dashboard / CVE

    9.8
    Critical

    CVE-2026-38967

    Last Modified: 3 Jun 2026

    CrowCpp Crow through v1.3.1 HTTP is vulnerable to response header injection via unvalidated response header values.

    Published: 2 Jun 2026
    6.3
    Medium

    CVE-2026-35717

    Last Modified: 3 Jun 2026

    A stack-based buffer overflow in the export_language.cgi binary in VIVOTEK FD8136 firmware FD8136-VVTK-0300a allows authenticated remote attackers to execute arbitrary code as root via a crafted POST request to the /cgi-bin/admin/export_language.cgi endpoint. The handler passes the attacker-controlled Content-Length value directly to fread() as the read size into a fixed-size 0x60-byte stack buffer, overwriting the saved link register. The binary is compiled without stack canaries.

    Published: 2 Jun 2026
    6.3
    Medium

    CVE-2026-35716

    Last Modified: 3 Jun 2026

    A stack-based buffer overflow in the motion_privacy.cgi binary in VIVOTEK FD8136 firmware FD8136-VVTK-0300a allows authenticated remote attackers to execute arbitrary code as root via an oversized n1 parameter in a POST request to the /cgi-bin/admin/setpm.cgi, /cgi-bin/admin/setmd.cgi, or /cgi-bin/admin/setmd_profile.cgi endpoint (all symlinks to the same binary). The parameter value is copied into a fixed-size 0xa4-byte stack buffer without bounds checking, overwriting the saved link register. The binary is compiled without stack canaries.

    Published: 2 Jun 2026
    5.9
    Medium

    CVE-2026-48682

    Last Modified: 4 Jun 2026

    FastNetMon Community Edition through 1.2.9 contains an out-of-bounds read in the IPv4 packet parser. In src/simple_packet_parser_ng.cpp, after validating that the packet contains at least sizeof(ipv4_header_t) bytes (20 bytes), the code advances the local_pointer by '4 * ipv4_header->get_ihl()' (line 164) without validating that (a) IHL >= 5 (the minimum valid value per RFC 791), or (b) 4 * IHL bytes are actually available in the packet. The IHL field is 4 bits, allowing values 0-15, so the advance can be 0-60 bytes. An IHL value of 15 with only 20 bytes validated causes a 40-byte over-read. An IHL of 0-4 causes the pointer to not advance past the IP header, resulting in the TCP/UDP header being parsed from IP header data (type confusion). This vulnerability is reachable via any packet capture interface.

    Published: 2 Jun 2026
    8.3
    High

    CVE-2026-10953

    Last Modified: 8 Jun 2026

    Use after free in Core in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

    Published: 2 Jun 2026
    8.8
    High

    CVE-2026-10962

    Last Modified: 6 Jun 2026

    Type Confusion in Media in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

    Published: 2 Jun 2026
    8.8
    High

    CVE-2026-11060

    Last Modified: 6 Jun 2026

    Use after free in Media in Google Chrome on Windows prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)

    Published: 2 Jun 2026
    8.3
    High

    CVE-2026-10940

    Last Modified: 8 Jun 2026

    Race in Codecs in Google Chrome on Windows prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

    Published: 2 Jun 2026
    5.4
    Medium

    CVE-2026-11232

    Last Modified: 10 Jun 2026

    Inappropriate implementation in TabGroups in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to perform UI spoofing via malicious network traffic. (Chromium security severity: Low)

    Published: 2 Jun 2026
    8.8
    High

    CVE-2026-10943

    Last Modified: 9 Jun 2026

    Use after free in WebRTC in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

    Published: 2 Jun 2026
    8.8
    High

    CVE-2026-10945

    Last Modified: 9 Jun 2026

    Use after free in PDF in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who convinced a user to engage in specific UI gestures to execute arbitrary code inside a sandbox via a crafted PDF file. (Chromium security severity: High)

    Published: 2 Jun 2026
    8.8
    High

    CVE-2026-10947

    Last Modified: 9 Jun 2026

    Use after free in WebRTC in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

    Published: 2 Jun 2026
    8.8
    High

    CVE-2026-10954

    Last Modified: 9 Jun 2026

    Use after free in Actor in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

    Published: 2 Jun 2026
    8.8
    High

    CVE-2026-10956

    Last Modified: 9 Jun 2026

    Use after free in MimeHandlerView in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

    Published: 2 Jun 2026
    8.8
    High

    CVE-2026-10959

    Last Modified: 6 Jun 2026

    Use after free in Input in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

    Published: 2 Jun 2026
    7.4
    High

    CVE-2026-10968

    Last Modified: 6 Jun 2026

    Insufficient validation of untrusted input in Dawn in Google Chrome on Windows prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)

    Published: 2 Jun 2026
    9.6
    Critical

    CVE-2026-10972

    Last Modified: 6 Jun 2026

    Use after free in Ozone in Google Chrome on Linux prior to 149.0.7827.53 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

    Published: 2 Jun 2026
    8.8
    High

    CVE-2026-10975

    Last Modified: 6 Jun 2026

    Use after free in WebRTC in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

    Published: 2 Jun 2026
    6.5
    Medium

    CVE-2026-11081

    Last Modified: 8 Jun 2026

    Inappropriate implementation in Canvas in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium security severity: Medium)

    Published: 2 Jun 2026
    6.5
    Medium

    CVE-2026-11090

    Last Modified: 8 Jun 2026

    Uninitialized Use in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)

    Published: 2 Jun 2026
    6.5
    Medium

    CVE-2026-10996

    Last Modified: 8 Jun 2026

    Inappropriate implementation in Workers in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium security severity: Medium)

    Published: 2 Jun 2026
    8.8
    High

    CVE-2026-11003

    Last Modified: 6 Jun 2026

    Use after free in WebRTC in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)

    Published: 2 Jun 2026
    6.5
    Medium

    CVE-2026-11007

    Last Modified: 8 Jun 2026

    Insufficient validation of untrusted input in WebView in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)

    Published: 2 Jun 2026
    6.5
    Medium

    CVE-2026-11013

    Last Modified: 8 Jun 2026

    Insufficient validation of untrusted input in Network in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)

    Published: 2 Jun 2026
    8.1
    High

    CVE-2026-11011

    Last Modified: 8 Jun 2026

    Insufficient policy enforcement in Password Manager in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium)

    Published: 2 Jun 2026
    8.8
    High

    CVE-2026-11172

    Last Modified: 8 Jun 2026

    Incorrect security UI in Contact Picker in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)

    Published: 2 Jun 2026
    8.1
    High

    CVE-2026-11015

    Last Modified: 8 Jun 2026

    Out of bounds read in WebGPU in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: Medium)

    Published: 2 Jun 2026
    6.5
    Medium

    CVE-2026-11017

    Last Modified: 8 Jun 2026

    Inappropriate implementation in Link Preview in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Medium)

    Published: 2 Jun 2026
    6.5
    Medium

    CVE-2026-11022

    Last Modified: 8 Jun 2026

    Insufficient validation of untrusted input in DevTools in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to bypass same origin policy via a crafted HTML page. (Chromium security severity: Medium)

    Published: 2 Jun 2026
    8.3
    High

    CVE-2026-11236

    Last Modified: 9 Jun 2026

    Insufficient policy enforcement in Web Bluetooth in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low)

    Published: 2 Jun 2026
    6.5
    Medium

    CVE-2026-11027

    Last Modified: 8 Jun 2026

    Insufficient validation of untrusted input in Glic in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)

    Published: 2 Jun 2026
    4.3
    Medium

    CVE-2026-11031

    Last Modified: 8 Jun 2026

    Insufficient validation of untrusted input in Password Manager in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to perform UI spoofing via malicious network traffic. (Chromium security severity: Medium)

    Published: 2 Jun 2026
    6.5
    Medium

    CVE-2026-11033

    Last Modified: 8 Jun 2026

    Uninitialized Use in WebML in Google Chrome on Mac prior to 149.0.7827.53 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)

    Published: 2 Jun 2026
    6.5
    Medium

    CVE-2026-11036

    Last Modified: 8 Jun 2026

    Inappropriate implementation in DOM in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium security severity: Medium)

    Published: 2 Jun 2026
    6.5
    Medium

    CVE-2026-11044

    Last Modified: 8 Jun 2026

    Integer overflow in ANGLE in Google Chrome on Mac prior to 149.0.7827.53 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)

    Published: 2 Jun 2026
    9.6
    Critical

    CVE-2026-11047

    Last Modified: 8 Jun 2026

    Inappropriate implementation in Base in Google Chrome on Windows prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)

    Published: 2 Jun 2026
    8.8
    High

    CVE-2026-11049

    Last Modified: 6 Jun 2026

    Use after free in Password Manager in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)

    Published: 2 Jun 2026
    8.8
    High

    CVE-2026-11054

    Last Modified: 6 Jun 2026

    Use after free in WebRTC in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)

    Published: 2 Jun 2026
    9.6
    Critical

    CVE-2026-11056

    Last Modified: 8 Jun 2026

    Insufficient validation of untrusted input in SiteIsolation in Google Chrome on Windows prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)

    Published: 2 Jun 2026
    6.5
    Medium

    CVE-2026-11057

    Last Modified: 8 Jun 2026

    Uninitialized Use in Skia in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)

    Published: 2 Jun 2026
    9.6
    Critical

    CVE-2026-11063

    Last Modified: 8 Jun 2026

    Insufficient validation of untrusted input in WebNN in Google Chrome on Windows prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)

    Published: 2 Jun 2026
    6.5
    Medium

    CVE-2026-11180

    Last Modified: 8 Jun 2026

    Inappropriate implementation in SVG in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)

    Published: 2 Jun 2026
    6.5
    Medium

    CVE-2026-11067

    Last Modified: 8 Jun 2026

    Uninitialized Use in Dawn in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)

    Published: 2 Jun 2026
    8.8
    High

    CVE-2026-11071

    Last Modified: 8 Jun 2026

    Use after free in Base in Google Chrome on Linux prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)

    Published: 2 Jun 2026
    6.5
    Medium

    CVE-2026-11073

    Last Modified: 8 Jun 2026

    Use after free in WebGL in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)

    Published: 2 Jun 2026
    8.8
    High

    CVE-2026-11076

    Last Modified: 6 Jun 2026

    Type Confusion in CSS in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)

    Published: 2 Jun 2026
    8.8
    High

    CVE-2026-11086

    Last Modified: 6 Jun 2026

    Inappropriate implementation in Dawn in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)

    Published: 2 Jun 2026
    8.8
    High

    CVE-2026-11085

    Last Modified: 8 Jun 2026

    Integer overflow in GPU in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page. (Chromium security severity: Medium)

    Published: 2 Jun 2026
    1.9
    Low

    CVE-2026-10514

    Last Modified: 2 Jun 2026

    A vulnerability has been found in 1Panel-dev CordysCRM up to 1.6.2. This affects an unknown function of the file backend/framework/src/main/java/cn/cordys/config/RequestParamTrimConfig.java. The manipulation leads to cross site scripting. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used. Upgrading to version 1.7.0 mitigates this issue. The identifier of the patch is c87682afa8df79853299f75489c9d333f7bc5fce. It is suggested to upgrade the affected component.

    Published: 1 Jun 2026
    2.1
    Low

    CVE-2026-10302

    Last Modified: 2 Jun 2026

    A flaw has been found in itsourcecode Fees Management System 1.0. The impacted element is an unknown function of the file /manage_fee.php. Executing a manipulation of the argument ID can lead to sql injection. The attack may be launched remotely. The exploit has been published and may be used.

    Published: 1 Jun 2026