CVE Feed

    Dashboard / CVE

    8.8
    High

    CVE-2026-7902

    Last Modified: 10 May 2026

    Out of bounds memory access in V8 in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

    Published: 5 May 2026
    7.8
    High

    CVE-2026-7997

    Last Modified: 7 May 2026

    Insufficient validation of untrusted input in Updater in Google Chrome on Mac prior to 148.0.7778.96 allowed a local attacker to perform OS-level privilege escalation via a malicious file. (Chromium security severity: Low)

    Published: 5 May 2026
    8.8
    High

    CVE-2026-7995

    Last Modified: 7 May 2026

    Out of bounds read in AdFilter in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)

    Published: 5 May 2026
    8.8
    High

    CVE-2026-7992

    Last Modified: 7 May 2026

    Insufficient validation of untrusted input in UI in Google Chrome on Linux, ChromeOS prior to 148.0.7778.96 allowed a remote attacker who convinced a user to engage in specific UI gestures to execute arbitrary code via a crafted HTML page. (Chromium security severity: Medium)

    Published: 5 May 2026
    8.8
    High

    CVE-2026-7991

    Last Modified: 7 May 2026

    Use after free in UI in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)

    Published: 5 May 2026
    7.8
    High

    CVE-2026-7990

    Last Modified: 7 May 2026

    Insufficient validation of untrusted input in Updater in Google Chrome on Windows prior to 148.0.7778.96 allowed a local attacker to perform OS-level privilege escalation via a malicious file. (Chromium security severity: Medium)

    Published: 5 May 2026
    4.2
    Medium

    CVE-2026-7989

    Last Modified: 8 May 2026

    Insufficient data validation in DataTransfer in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to perform arbitrary read/write via a crafted HTML page. (Chromium security severity: Medium)

    Published: 5 May 2026
    8.8
    High

    CVE-2026-7988

    Last Modified: 7 May 2026

    Type Confusion in WebRTC in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)

    Published: 5 May 2026
    8.8
    High

    CVE-2026-7987

    Last Modified: 7 May 2026

    Use after free in WebRTC in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)

    Published: 5 May 2026
    8.3
    High

    CVE-2026-7985

    Last Modified: 7 May 2026

    Use after free in GPU in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)

    Published: 5 May 2026
    8.8
    High

    CVE-2026-7984

    Last Modified: 7 May 2026

    Use after free in ReadingMode in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)

    Published: 5 May 2026
    8.8
    High

    CVE-2026-7980

    Last Modified: 7 May 2026

    Use after free in WebAudio in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)

    Published: 5 May 2026
    4.3
    Medium

    CVE-2026-7979

    Last Modified: 7 May 2026

    Inappropriate implementation in Media in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)

    Published: 5 May 2026
    8.3
    High

    CVE-2026-7975

    Last Modified: 7 May 2026

    Use after free in DevTools in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)

    Published: 5 May 2026
    8.8
    High

    CVE-2026-7974

    Last Modified: 7 May 2026

    Use after free in Blink in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)

    Published: 5 May 2026
    6.3
    Medium

    CVE-2026-7971

    Last Modified: 7 May 2026

    Inappropriate implementation in ORB in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium)

    Published: 5 May 2026
    8.3
    High

    CVE-2026-7970

    Last Modified: 7 May 2026

    Use after free in TopChrome in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)

    Published: 5 May 2026
    8.3
    High

    CVE-2026-7967

    Last Modified: 7 May 2026

    Insufficient validation of untrusted input in Navigation in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)

    Published: 5 May 2026
    8.3
    High

    CVE-2026-7956

    Last Modified: 7 May 2026

    Use after free in Navigation in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)

    Published: 5 May 2026
    8.8
    High

    CVE-2026-7951

    Last Modified: 7 May 2026

    Out of bounds write in WebRTC in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)

    Published: 5 May 2026
    7.5
    High

    CVE-2026-7948

    Last Modified: 7 May 2026

    Race in Chromoting in Google Chrome on Windows prior to 148.0.7778.96 allowed a local attacker to perform privilege escalation via a malicious file. (Chromium security severity: Medium)

    Published: 5 May 2026
    4.3
    Medium

    CVE-2026-7946

    Last Modified: 9 May 2026

    Insufficient policy enforcement in WebUI in Google Chrome on Linux, Mac, Windows, ChromeOS prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium)

    Published: 5 May 2026
    8.8
    High

    CVE-2026-7940

    Last Modified: 7 May 2026

    Use after free in V8 in Google Chrome prior to 148.0.7778.96 allowed an attacker who convinced a user to install a malicious extension to execute arbitrary code inside a sandbox via a crafted Chrome Extension. (Chromium security severity: Medium)

    Published: 5 May 2026
    7.5
    High

    CVE-2026-7929

    Last Modified: 7 May 2026

    Use after free in MediaRecording in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who convinced a user to engage in specific UI gestures to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)

    Published: 5 May 2026
    8.8
    High

    CVE-2026-7928

    Last Modified: 7 May 2026

    Use after free in WebRTC in Google Chrome on Windows prior to 148.0.7778.96 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

    Published: 5 May 2026
    8.8
    High

    CVE-2026-7927

    Last Modified: 7 May 2026

    Type Confusion in Runtime in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

    Published: 5 May 2026
    8.8
    High

    CVE-2026-7926

    Last Modified: 7 May 2026

    Use after free in PresentationAPI in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

    Published: 5 May 2026
    7.8
    High

    CVE-2026-7925

    Last Modified: 7 May 2026

    Use after free in Chromoting in Google Chrome on Windows prior to 148.0.7778.96 allowed a local attacker to perform OS-level privilege escalation via a malicious file. (Chromium security severity: High)

    Published: 5 May 2026
    8.3
    High

    CVE-2026-7923

    Last Modified: 7 May 2026

    Out of bounds write in Skia in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

    Published: 5 May 2026
    8.8
    High

    CVE-2026-7921

    Last Modified: 7 May 2026

    Use after free in Passwords in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)

    Published: 5 May 2026
    8.3
    High

    CVE-2026-7920

    Last Modified: 7 May 2026

    Use after free in Skia in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

    Published: 5 May 2026
    8.3
    High

    CVE-2026-7919

    Last Modified: 7 May 2026

    Use after free in Aura in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

    Published: 5 May 2026
    8.3
    High

    CVE-2026-7918

    Last Modified: 7 May 2026

    Use after free in GPU in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

    Published: 5 May 2026
    8.3
    High

    CVE-2026-7917

    Last Modified: 7 May 2026

    Use after free in Fullscreen in Google Chrome on Windows prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

    Published: 5 May 2026
    8.3
    High

    CVE-2026-7914

    Last Modified: 7 May 2026

    Type Confusion in Accessibility in Google Chrome on Windows prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

    Published: 5 May 2026
    7.8
    High

    CVE-2026-7913

    Last Modified: 7 May 2026

    Insufficient policy enforcement in DevTools in Google Chrome on Android prior to 148.0.7778.96 allowed a local attacker to perform privilege escalation via a malicious file. (Chromium security severity: High)

    Published: 5 May 2026
    8.8
    High

    CVE-2026-7907

    Last Modified: 7 May 2026

    Use after free in DOM in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

    Published: 5 May 2026
    8.8
    High

    CVE-2026-7906

    Last Modified: 7 May 2026

    Use after free in SVG in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

    Published: 5 May 2026
    8.8
    High

    CVE-2026-7901

    Last Modified: 7 May 2026

    Use after free in ANGLE in Google Chrome on Mac prior to 148.0.7778.96 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

    Published: 5 May 2026
    8.3
    High

    CVE-2026-7900

    Last Modified: 7 May 2026

    Heap buffer overflow in ANGLE in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

    Published: 5 May 2026
    7.5
    High

    CVE-2026-7897

    Last Modified: 7 May 2026

    Use after free in Mobile in Google Chrome on iOS prior to 148.0.7778.96 allowed a remote attacker who convinced a user to engage in specific UI gestures to execute arbitrary code via a crafted HTML page. (Chromium security severity: Critical)

    Published: 5 May 2026
    8.8
    High

    CVE-2026-7896

    Last Modified: 7 May 2026

    Integer overflow in Blink in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)

    Published: 5 May 2026
    9.8
    Critical

    CVE-2026-38428

    Last Modified: 8 May 2026

    Kestra v1.3.3 and before is vulnerable to SQL Injection. The vulnerability occurs because user-controlled input from a GET parameter is directly concatenated into an SQL query without proper sanitization or parameterization. As a result, attackers can inject arbitrary SQL expressions into the database query.

    Published: 5 May 2026
    6.1
    Medium

    CVE-2026-38432

    Last Modified: 8 May 2026

    ERPNext v15.103.1 and before is vulnerable to Cross Site Scripting (XSS) in the Email Template engine. An attacker with permission to create or edit email templates can inject malicious JavaScript code that are executed on the victim's browser when the template is applied.

    Published: 5 May 2026
    9.8
    Critical

    CVE-2026-43067

    Last Modified: 20 May 2026

    In the Linux kernel, the following vulnerability has been resolved: ext4: handle wraparound when searching for blocks for indirect mapped blocks Commit 4865c768b563 ("ext4: always allocate blocks only from groups inode can use") restricts what blocks will be allocated for indirect block based files to block numbers that fit within 32-bit block numbers. However, when using a review bot running on the latest Gemini LLM to check this commit when backporting into an LTS based kernel, it raised this concern: If ac->ac_g_ex.fe_group is >= ngroups (for instance, if the goal group was populated via stream allocation from s_mb_last_groups), then start will be >= ngroups. Does this allow allocating blocks beyond the 32-bit limit for indirect block mapped files? The commit message mentions that ext4_mb_scan_groups_linear() takes care to not select unsupported groups. However, its loop uses group = *start, and the very first iteration will call ext4_mb_scan_group() with this unsupported group because next_linear_group() is only called at the end of the iteration. After reviewing the code paths involved and considering the LLM review, I determined that this can happen when there is a file system where some files/directories are extent-mapped and others are indirect-block mapped. To address this, add a safety clamp in ext4_mb_scan_groups().

    Published: 5 May 2026
    7.8
    High

    CVE-2026-43063

    Last Modified: 29 May 2026

    In the Linux kernel, the following vulnerability has been resolved: xfs: don't irele after failing to iget in xfs_attri_recover_work xlog_recovery_iget* never set @ip to a valid pointer if they return an error, so this irele will walk off a dangling pointer. Fix that.

    Published: 5 May 2026
    9.6
    Critical

    CVE-2026-7910

    Last Modified: 12 May 2026

    Use after free in Views in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: High)

    Published: 5 May 2026
    8.8
    High

    CVE-2026-7973

    Last Modified: 7 May 2026

    Integer overflow in Dawn in Google Chrome on Windows prior to 148.0.7778.96 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)

    Published: 5 May 2026
    8.8
    High

    CVE-2026-7938

    Last Modified: 7 May 2026

    Use after free in CSS in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)

    Published: 5 May 2026
    4.3
    Medium

    CVE-2026-7936

    Last Modified: 16 Jun 2026

    Determined not a vulnerability

    Published: 5 May 2026