<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – Remote Code Execution (High+Critical)</title>
  <link>https://cvedaily.com/pages/tags/rce.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/rce-severe.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – Remote Code Execution (High+Critical)</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:28 +0000</lastBuildDate>
  <item>
    <title>[High] CVE-2026-5241 – A vulnerability in the LightGlue model loading path of huggingface/transformers ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-5241</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-5241</guid>
    <pubDate>Wed, 03 Jun 2026 14:16:46 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-5241</strong></p>
  <p>A vulnerability in the LightGlue model loading path of huggingface/transformers version 5.2.0 allows an attacker-controlled model repository to execute arbitrary code during model initialization. The issue arises because the `trust_remote_code` parameter, intended to prevent remote code execution, is overridden by untrusted serialized configuration data in a nested code path. Specifically, when l…</p>
  <p><strong>CVSS:</strong> 8.0 · <strong>CWE:</strong> CWE-829</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-5241">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-49042 – An inclusion of functionality from untrusted control sphere vulnerability in Min...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-49042</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-49042</guid>
    <pubDate>Wed, 03 Jun 2026 14:16:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-49042</strong></p>
  <p>An inclusion of functionality from untrusted control sphere vulnerability in MinGW DLL component in Synology Hyper Backup Explorer before 3.0.1-0156 allows local users to execute arbitrary code via unspecified vectors.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-829</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-49042">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-49036 – An inclusion of functionality from untrusted control sphere vulnerability in Ope...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-49036</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-49036</guid>
    <pubDate>Wed, 03 Jun 2026 14:16:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-49036</strong></p>
  <p>An inclusion of functionality from untrusted control sphere vulnerability in OpenSSL configuration in Synology Active Backup for Business Recovery Media Creator before 2.5.0-2081 allows local users to execute arbitrary code via unspecified vectors.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-829</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-49036">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-4035 – A vulnerability in mlflow/mlflow versions prior to 3.11.0 allows for the resolut...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-4035</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-4035</guid>
    <pubDate>Wed, 03 Jun 2026 09:16:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-4035</strong></p>
  <p>A vulnerability in mlflow/mlflow versions prior to 3.11.0 allows for the resolution of environment variables in AI Gateway secrets, which can be exploited to exfiltrate sensitive server-side environment credentials to an attacker-controlled endpoint. This issue arises because the `api_key` field in gateway secrets can accept `$ENV_VAR` references, which are resolved against the MLflow server's en…</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-201</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-4035">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-4481 – Dräger Protector Software prior to version 6.4.2 contains a local privilege esca...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-4481</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-4481</guid>
    <pubDate>Tue, 02 Jun 2026 22:16:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-4481</strong></p>
  <p>Dräger Protector Software prior to version 6.4.2 contains a local privilege escalation vulnerability due to insecure file system permissions that allows local attackers to execute arbitrary code with elevated privileges. Attackers can replace binaries or loaded modules on the host system to execute code with NT SYSTEM privileges.</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-732</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-4481">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-4480 – Dräger Protector Software prior to version 6.4.2 contains a local privilege esca...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-4480</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-4480</guid>
    <pubDate>Tue, 02 Jun 2026 22:16:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-4480</strong></p>
  <p>Dräger Protector Software prior to version 6.4.2 contains a local privilege escalation vulnerability due to insecure file system permissions that allows local attackers to execute arbitrary code with elevated privileges. Attackers can replace binaries or loaded modules on the host system to execute code with NT SYSTEM privileges.</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-732</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-4480">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-49143 – BrowserStack Runner through 0.9.5 contains a remote code execution vulnerability...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-49143</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-49143</guid>
    <pubDate>Tue, 02 Jun 2026 21:16:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-49143</strong></p>
  <p>BrowserStack Runner through 0.9.5 contains a remote code execution vulnerability in the /_log HTTP handler that allows unauthenticated network-adjacent attackers to execute arbitrary code by submitting crafted JSON request bodies to the handler, which passes user-supplied data to vm.runInNewContext() combined with eval(). Attackers can escape the Node.js vm sandbox by leveraging a host-context Fu…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-49143">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-42211 – React Router is a router for React. In versions 7.0.0 through 7.14.1, when using...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-42211</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-42211</guid>
    <pubDate>Tue, 02 Jun 2026 20:16:36 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-42211</strong></p>
  <p>React Router is a router for React. In versions 7.0.0 through 7.14.1, when using Framework Mode, a combination of steps could potentially allow unauthorized remote code execution (RCE) through external requests. This attack requires the application code to have an existing prototype pollution vulnerability, which can then be leveraged in a 2-step attack where the second step triggers unauthorized…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42211">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-1829 – The Content Visibility for Divi Builder plugin for WordPress is vulnerable to Re...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-1829</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-1829</guid>
    <pubDate>Tue, 02 Jun 2026 20:16:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-1829</strong></p>
  <p>The Content Visibility for Divi Builder plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 4.02 via the 'et_pb_text' shortcode 'cvdb_content_visibility_check' parameter. This makes it possible for authenticated attackers, with Contributor-level access and above, to execute code on the server.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-1829">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-42074 – OpenClaude is an open-source coding-agent command line interface for cloud and l...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-42074</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-42074</guid>
    <pubDate>Tue, 02 Jun 2026 17:16:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-42074</strong></p>
  <p>OpenClaude is an open-source coding-agent command line interface for cloud and local model providers. Prior to version 0.5.1, the dangerouslyDisableSandbox parameter is exposed as part of the BashTool input schema, meaning the LLM (an untrusted principal per the project's own threat model) can set it to true in any tool_use response. Combined with the default allowUnsandboxedCommands: true settin…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42074">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-24237 – NVIDIA NVTabular contains a vulnerability where an attacker could cause improper...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-24237</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-24237</guid>
    <pubDate>Tue, 02 Jun 2026 17:16:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-24237</strong></p>
  <p>NVIDIA NVTabular contains a vulnerability where an attacker could cause improper deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-24237">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-24221 – NVIDIA NVTabular contains a vulnerability where an attacker could cause improper...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-24221</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-24221</guid>
    <pubDate>Tue, 02 Jun 2026 17:16:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-24221</strong></p>
  <p>NVIDIA NVTabular contains a vulnerability where an attacker could cause improper deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering and information disclosure.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-24221">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-0611 – Spacelabs Healthcare Sentinel versions 10.5.x and higher and 11.x.x before 11.6...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-0611</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-0611</guid>
    <pubDate>Tue, 02 Jun 2026 17:16:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-0611</strong></p>
  <p>Spacelabs Healthcare Sentinel versions 10.5.x and higher and 11.x.x before 11.6.0 contain an unauthenticated remote code execution vulnerability through a deprecated .NET Remoting HTTP channel exposed on port 8989 that allows attackers to perform arbitrary file read and write operations by supplying valid .NET URI endpoints. Attackers can write ASPX webshells to the IIS wwwroot directory to achie…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-306</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-0611">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-47117 – OpenMed before 1.5.2 contains a remote code execution vulnerability in the PII p...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-47117</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-47117</guid>
    <pubDate>Tue, 02 Jun 2026 16:16:43 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-47117</strong></p>
  <p>OpenMed before 1.5.2 contains a remote code execution vulnerability in the PII privacy-filter model loading path. The privacy-filter dispatcher used broad substring matching on the user-supplied model_name parameter, allowing a value such as attacker/foo-privacy-filter-bar to route through a path that loads Hugging Face models with trust_remote_code=True. An unauthenticated attacker can supply a…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-47117">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-30652 – A remote buffer overflow vulnerability exists in the /cgi-bin/dido/setdo.cgi end...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-30652</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-30652</guid>
    <pubDate>Tue, 02 Jun 2026 16:16:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-30652</strong></p>
  <p>A remote buffer overflow vulnerability exists in the /cgi-bin/dido/setdo.cgi endpoint of the admin interface of Vivotek FD8136 cameras running firmware version FD8136-VVTK-0300a. This flaw allows an authenticated attacker to execute arbitrary code as root on the device.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-120</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-30652">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-30650 – A post-authentication remote buffer overflow vulnerability exists in the /cgi-bi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-30650</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-30650</guid>
    <pubDate>Tue, 02 Jun 2026 16:16:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-30650</strong></p>
  <p>A post-authentication remote buffer overflow vulnerability exists in the /cgi-bin/admin/eventtask.cgi endpoint of the admin interface of Vivotek FD8136 cameras running firmware version FD8136-VVTK-0300a. This flaw allows an authenticated attacker to execute arbitrary code as root on the device remotely.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-120</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-30650">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-30649 – Buffer Overflow vulnerability in VIVOTEK INC FD8136-VVTK-0300a allows a remote a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-30649</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-30649</guid>
    <pubDate>Tue, 02 Jun 2026 16:16:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-30649</strong></p>
  <p>Buffer Overflow vulnerability in VIVOTEK INC FD8136-VVTK-0300a allows a remote attacker to execute arbitrary code via the set_getparam.cgi component</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-121</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-30649">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-34906 – Server-Side Template Injection (SSTI) in Wirtualna Uczelnia allows an unauthenti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-34906</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-34906</guid>
    <pubDate>Tue, 02 Jun 2026 10:16:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-34906</strong></p>
  <p>Server-Side Template Injection (SSTI) in Wirtualna Uczelnia allows an unauthenticated attacker to perform Remote Code Execution (RCE). In the endpoint redirectToUrl and parameter redirectUrlParameter, insufficient input validation permits injection of arbitrary template expressions that are executed on the server. Successful exploitation can allow an attacker to run remote commands, including est…</p>
  <p><strong>CVSS:</strong> 9.3 · <strong>CWE:</strong> CWE-1336</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-34906">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-53345 – Missing Authorization vulnerability leading to code execution after installing m...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-53345</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-53345</guid>
    <pubDate>Tue, 02 Jun 2026 10:16:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-53345</strong></p>
  <p>Missing Authorization vulnerability leading to code execution after installing malicious vulnerable plugin in ThimPress Thim Core.  This issue affects Thim Core: from n/a through 2.3.3.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-53345">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-25879 – Langroid is a framework for building large-language-model-powered applications. ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-25879</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-25879</guid>
    <pubDate>Mon, 01 Jun 2026 23:16:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-25879</strong></p>
  <p>Langroid is a framework for building large-language-model-powered applications. Prior to version 0.63.0, SQLChatAgent executes SQL produced by an LLM, which is influenceable by prompt injection. When configured with a database role that has privileges enabling code execution or filesystem access (e.g., PostgreSQL pg_execute_server_program, MySQL FILE, MSSQL xp_cmdshell), an attacker who can shape…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-25879">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-0059 – In multiple functions of sdp_discovery.cc, there is a possible way to achieve co...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-0059</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-0059</guid>
    <pubDate>Mon, 01 Jun 2026 22:16:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-0059</strong></p>
  <p>In multiple functions of sdp_discovery.cc, there is a possible way to achieve code execution due to a heap buffer overflow. This could lead to remote (proximal/adjacent) code execution with no additional execution privileges needed. User interaction is not needed for exploitation.</p>
  <p><strong>CVSS:</strong> 8.0 · <strong>CWE:</strong> CWE-122</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-0059">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-48595 – In multiple locations, there is a possible way to achieve code execution due to ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-48595</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-48595</guid>
    <pubDate>Mon, 01 Jun 2026 22:16:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-48595</strong></p>
  <p>In multiple locations, there is a possible way to achieve code execution due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.</p>
  <p><strong>CVSS:</strong> 8.4 · <strong>CWE:</strong> CWE-190</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-48595">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-25432 – Arm Whois 3.11 contains a buffer overflow vulnerability that allows local attack...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-25432</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-25432</guid>
    <pubDate>Mon, 01 Jun 2026 22:16:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-25432</strong></p>
  <p>Arm Whois 3.11 contains a buffer overflow vulnerability that allows local attackers to execute arbitrary code by overwriting the structured exception handler. Attackers can craft a malicious input file with a 672-byte offset to overwrite the nSEH and SEH pointers, enabling code execution through exception handler hijacking.</p>
  <p><strong>CVSS:</strong> 8.4 · <strong>CWE:</strong> CWE-120</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-25432">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2018-25427 – Arm Whois 3.11 contains a stack-based buffer overflow vulnerability that allows ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-25427</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-25427</guid>
    <pubDate>Mon, 01 Jun 2026 22:16:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2018-25427</strong></p>
  <p>Arm Whois 3.11 contains a stack-based buffer overflow vulnerability that allows remote attackers to execute arbitrary code by supplying oversized input to the IP address or domain field. Attackers can craft malicious input exceeding 658 bytes with shellcode to overwrite the structured exception handler and gain command execution when the application processes the input.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-121</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-25427">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-9330 – IBM WebSphere Application Server 9.0, and 8.5 is affected by an improper validat...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9330</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9330</guid>
    <pubDate>Mon, 01 Jun 2026 19:16:55 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-9330</strong></p>
  <p>IBM WebSphere Application Server 9.0, and 8.5 is affected by an improper validation of user-supplied data during deserialization using the SAML Web Single Sign-On component. This could result in remote code execution via a crafted HTTP request when combined with a suitable gadget chain.</p>
  <p><strong>CVSS:</strong> 8.5 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9330">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-9319 – IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to potential remote ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9319</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9319</guid>
    <pubDate>Mon, 01 Jun 2026 19:16:55 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-9319</strong></p>
  <p>IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to potential remote code execution due to deserialization of untrusted data via JAX-WS endpoints with WS-Security.</p>
  <p><strong>CVSS:</strong> 9.0 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9319">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-9311 – IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to remote code execu...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9311</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9311</guid>
    <pubDate>Mon, 01 Jun 2026 19:16:55 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-9311</strong></p>
  <p>IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to remote code execution caused by the bypass of security controls.</p>
  <p><strong>CVSS:</strong> 9.0 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9311">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-7770 – IBM i Access Family 1.1.5.0 through 1.1.9.12 IBM i Access Client Solutions (ACS)...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-7770</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-7770</guid>
    <pubDate>Mon, 01 Jun 2026 19:16:54 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-7770</strong></p>
  <p>IBM i Access Family 1.1.5.0 through 1.1.9.12 IBM i Access Client Solutions (ACS) is vulnerable to remote code execution when configured to listen for requests from IBM i Navigator.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-7770">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-49121 – AI Tensor Engine for ROCm (AITER) through 0.1.14 contains an unauthenticated rem...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-49121</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-49121</guid>
    <pubDate>Mon, 01 Jun 2026 19:16:54 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-49121</strong></p>
  <p>AI Tensor Engine for ROCm (AITER) through 0.1.14 contains an unauthenticated remote code execution vulnerability in the MessageQueue.recv() function within shm_broadcast.py that allows unauthenticated remote attackers to execute arbitrary code by sending a malicious pickle payload to a ZMQ SUB socket with no authentication, HMAC, or format validation. Attackers who can reach the writer XPUB endpo…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-49121">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-43958 – A flaw was found in rrdcached, a component of rrdtool. A local attacker with acc...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-43958</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-43958</guid>
    <pubDate>Mon, 01 Jun 2026 19:16:47 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-43958</strong></p>
  <p>A flaw was found in rrdcached, a component of rrdtool. A local attacker with access to a rrdcached socket can exploit a stack-based buffer overflow by sending an oversized CREATE request. This vulnerability can lead to a denial of service by crashing the daemon or potentially allow for arbitrary code execution, impacting the integrity and confidentiality of data.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-121</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43958">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-38950 – An issue in ESA AnomalyMatch before 1.3.1 allow attackers to execute arbitrary c...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-38950</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-38950</guid>
    <pubDate>Mon, 01 Jun 2026 17:16:59 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-38950</strong></p>
  <p>An issue in ESA AnomalyMatch before 1.3.1 allow attackers to execute arbitrary code via crafted model checkpoint files. The affected components load model files from session directories using torch.load() with unrestricted deserialization.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-38950">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-10118 – A flaw was found in Poppler's Splash backend. A remote attacker could exploit th...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10118</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10118</guid>
    <pubDate>Mon, 01 Jun 2026 17:16:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-10118</strong></p>
  <p>A flaw was found in Poppler's Splash backend. A remote attacker could exploit this vulnerability by crafting a malicious PDF file that, when rendered, triggers an integer overflow in the `tilingPatternFill` function. This overflow leads to an undersized heap memory allocation, allowing a subsequent out-of-bounds write. Successful exploitation could result in arbitrary code execution, information…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-190</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10118">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-4991 – Tychon includes an OpenSSL component that specifies an OPENSSLDIR variable as a ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-4991</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-4991</guid>
    <pubDate>Mon, 01 Jun 2026 17:16:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-4991</strong></p>
  <p>Tychon includes an OpenSSL component that specifies an OPENSSLDIR variable as a subdirectory that may be controllable by an unprivileged user on Windows. Tychon contains a privileged service that uses this OpenSSL component. A user who can place a specially-crafted openssl.cnf file at an appropriate path may be able to achieve arbitrary code execution with SYSTEM privileges.</p>
  <p><strong>CVSS:</strong> 7.4 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-4991">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-8931 – A critical Remote Code Execution (RCE) vulnerability exists in Disig Web Signer ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8931</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8931</guid>
    <pubDate>Mon, 01 Jun 2026 15:16:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-8931</strong></p>
  <p>A critical Remote Code Execution (RCE) vulnerability exists in Disig Web Signer versions 2.0.3 through 2.5.3.</p>
  <p><strong>CVSS:</strong> 9.4 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8931">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-0826 – In certain scenarios when the admin has enabled Interactive Connectivity Establi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-0826</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-0826</guid>
    <pubDate>Mon, 01 Jun 2026 15:16:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-0826</strong></p>
  <p>In certain scenarios when the admin has enabled Interactive Connectivity Establishment (ICE), a buffer overflow could enable                remote code execution on Poly Voice products on the Linux platform.</p>
  <p><strong>CVSS:</strong> 9.2 · <strong>CWE:</strong> CWE-121</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-0826">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-7858 – A Deserialization of Untrusted Data vulnerability affecting Teamwork Cloud from ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-7858</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-7858</guid>
    <pubDate>Mon, 01 Jun 2026 09:16:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-7858</strong></p>
  <p>A Deserialization of Untrusted Data vulnerability affecting Teamwork Cloud from No Magic Release 2022x through No Magic Release 2026x and Magic Collaboration Studio from CATIA Magic Release 2022x through CATIA Magic Release 2026x could lead to an unauthenticated remote code execution.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-7858">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-45505 – Improper Input Validation, Improper Control of Generation of Code ('Code Injecti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-45505</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-45505</guid>
    <pubDate>Mon, 01 Jun 2026 09:16:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-45505</strong></p>
  <p>Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ.   Non-parenthesized discovery wrappers such as `masterslave:vm://...,...` and `static:vm://...` incorrectly pass validation allowing bypass of fix in CVE-2026-34197.   Original description from CVE-2026-34197.  Apache ActiveMQ exposes…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-45505">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-42588 – Improper Input Validation, Improper Control of Generation of Code ('Code Injecti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-42588</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-42588</guid>
    <pubDate>Mon, 01 Jun 2026 09:16:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-42588</strong></p>
  <p>Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ.  Apache ActiveMQ Classic exposes the Jolokia JMX-HTTP bridge at /api/jolokia/ on the web console. The default Jolokia access policy permits exec operations on all ActiveMQ MBeans (org.apache.activemq:*), including BrokerService.addNetw…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42588">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-20452 – In wlan AP driver, there is a possible memory corruption due to a heap buffer ov...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-20452</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-20452</guid>
    <pubDate>Mon, 01 Jun 2026 04:16:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-20452</strong></p>
  <p>In wlan AP driver, there is a possible memory corruption due to a heap buffer overflow. This could lead to remote (proximal/adjacent) code execution with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00480138; Issue ID: MSV-6295.</p>
  <p><strong>CVSS:</strong> 8.0 · <strong>CWE:</strong> CWE-122</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-20452">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2018-25412 – Delta Sql 1.8.2 contains an arbitrary file upload vulnerability that allows unau...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-25412</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-25412</guid>
    <pubDate>Sat, 30 May 2026 16:17:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2018-25412</strong></p>
  <p>Delta Sql 1.8.2 contains an arbitrary file upload vulnerability that allows unauthenticated attackers to upload malicious files by sending POST requests to docs_upload.php with crafted multipart form data. Attackers can upload PHP files with arbitrary content to the upload directory and execute them on the server for remote code execution.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-306</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-25412">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-7465 – The Spectra Gutenberg Blocks – Website Builder for the Block Editor plugin for W...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-7465</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-7465</guid>
    <pubDate>Sat, 30 May 2026 10:16:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-7465</strong></p>
  <p>The Spectra Gutenberg Blocks – Website Builder for the Block Editor plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.19.25. This makes it possible for authenticated attackers, with Contributor-level access and above, to execute code on the server. Exploitation requires a two-block payload embedded in post content: the first block registers a fake…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-269</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-7465">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-44421 – FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.26.0...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44421</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44421</guid>
    <pubDate>Fri, 29 May 2026 20:16:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-44421</strong></p>
  <p>FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.26.0, a malicious RDP server can trigger a heap-buffer-overflow write in the FreeRDP client by sending crafted RDPGFX PDUs. The bug is in gdi_CacheToSurface: it validates a destination rectangle that is clamped to UINT16_MAX, but then performs the copy using the original cacheEntry->width/height. This can cause a large ou…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-122</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44421">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-44420 – FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.26.0...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44420</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44420</guid>
    <pubDate>Fri, 29 May 2026 20:16:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-44420</strong></p>
  <p>FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.26.0, a malicious RDP client can trigger a heap-buffer-overflow write in FreeRDP's server-side clipboard (cliprdr) channel by sending a CB_CLIP_CAPS PDU with a too-small capabilitySetLength. This can crash the server process (remote DoS) and may be exploitable for code execution because it corrupts heap memory. This vulne…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-122</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44420">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-49373 – In JetBrains TeamCity before 2026.1 remote code execution was possible via Perfo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-49373</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-49373</guid>
    <pubDate>Fri, 29 May 2026 19:16:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-49373</strong></p>
  <p>In JetBrains TeamCity before 2026.1 remote code execution was possible via Perforce connection settings</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-88</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-49373">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-45661 – Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.26.5 and ear...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-45661</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-45661</guid>
    <pubDate>Fri, 29 May 2026 18:17:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-45661</strong></p>
  <p>Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.26.5 and earlier, a critical path traversal vulnerability exists in Dokploy v0.26.5 that allows authenticated users to write arbitrary files to the filesystem during application deployment. When combined with Dokploy's remote server deployment feature, this vulnerability enables arbitrary file write to remote server filesystems,…</p>
  <p><strong>CVSS:</strong> 9.9 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-45661">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-25388 – HaPe PKH 1.1 contains an arbitrary file upload vulnerability that allows authent...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-25388</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-25388</guid>
    <pubDate>Fri, 29 May 2026 16:16:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-25388</strong></p>
  <p>HaPe PKH 1.1 contains an arbitrary file upload vulnerability that allows authenticated attackers to upload malicious files by bypassing file type validation. Attackers can upload PHP files through multiple endpoints including aksi_foto.php, aksi_user.php, and aksi_kecamatan.php to execute arbitrary code on the server.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-434</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-25388">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-39292 – Falco Solutions PHPPageBuilder v0.31.0 contains an unrestricted file upload vuln...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-39292</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-39292</guid>
    <pubDate>Fri, 29 May 2026 15:16:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-39292</strong></p>
  <p>Falco Solutions PHPPageBuilder v0.31.0 contains an unrestricted file upload vulnerability in the pagemanager/pagebuilder module that allows remote attackers to upload arbitrary files and achieve remote code execution. The vulnerability exists due to insufficient validation of uploaded file types and executable content.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-434</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-39292">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-10042 – manga-image-translator contains a remote code execution vulnerability in the sha...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10042</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10042</guid>
    <pubDate>Fri, 29 May 2026 15:16:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-10042</strong></p>
  <p>manga-image-translator contains a remote code execution vulnerability in the shared API server mode due to unsafe deserialization of untrusted pickle data in the share.py module, where the /execute/{method_name} and /simple_execute/{method_name} endpoints deserialize attacker-controlled HTTP request bodies using pickle.loads(). A remote attacker can supply a crafted pickle payload to these endpoi…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10042">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-45555 – Roslyn CodeLens MCP Server is a Roslyn-based MCP server providing semantic code ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-45555</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-45555</guid>
    <pubDate>Fri, 29 May 2026 14:16:30 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-45555</strong></p>
  <p>Roslyn CodeLens MCP Server is a Roslyn-based MCP server providing semantic code intelligence for .NET codebases. From 0.0.9 to 1.17.0, the get_diagnostics MCP tool loads and executes all DiagnosticAnalyzer assemblies referenced by the target solution without any allowlist, signature check, or user confirmation; includeAnalyzers defaults to true, so no explicit opt-in is required. An attacker who…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-45555">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-10072 – DreamMaker developed by Interinfo has an Arbitrary File Upload vulnerability, al...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10072</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10072</guid>
    <pubDate>Fri, 29 May 2026 14:16:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-10072</strong></p>
  <p>DreamMaker developed by Interinfo has an Arbitrary File Upload vulnerability, allowing privileged remote attackers to upload and execute web shell backdoors, thereby enabling arbitrary code execution on the server.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-434</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10072">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-10071 – DreamMaker developed by Interinfo has an Arbitrary File Upload vulnerability, al...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10071</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10071</guid>
    <pubDate>Fri, 29 May 2026 13:16:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-10071</strong></p>
  <p>DreamMaker developed by Interinfo has an Arbitrary File Upload vulnerability, allowing unauthenticated remote attackers to upload and execute web shell backdoors, thereby enabling arbitrary code execution on the server.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-434</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10071">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-9559 – A path traversal vulnerability exists in the campaign import feature of Mautic 7...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9559</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9559</guid>
    <pubDate>Fri, 29 May 2026 12:16:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-9559</strong></p>
  <p>A path traversal vulnerability exists in the campaign import feature of Mautic 7. When extracting uploaded ZIP files during campaign imports, a flaw in the validation logic allows file paths to escape the intended temporary directories. An authenticated user with campaign import privileges (campaign:imports:create) can write arbitrary PHP files to sensitive system directories. An attacker can exp…</p>
  <p><strong>CVSS:</strong> 9.9 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9559">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-9558 – A Server-Side Template Injection (SSTI) vulnerability exists in Mautic's theme e...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9558</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9558</guid>
    <pubDate>Fri, 29 May 2026 11:16:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-9558</strong></p>
  <p>A Server-Side Template Injection (SSTI) vulnerability exists in Mautic's theme engine. The platform renders uploaded Twig templates without a sandbox or strict function restrictions. Authenticated users with permissions to create or upload themes can abuse this to execute arbitrary code on the hosting server (Remote Code Execution) or access restricted system files and configuration settings.</p>
  <p><strong>CVSS:</strong> 9.9 · <strong>CWE:</strong> CWE-1336</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9558">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-49199 – Crafted MQTT messages can trigger command injection, resulting in root-level cod...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-49199</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-49199</guid>
    <pubDate>Fri, 29 May 2026 09:16:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-49199</strong></p>
  <p>Crafted MQTT messages can trigger command injection, resulting in root-level code execution on the target device.</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-49199">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-7480 – An Incorrect Permission Assignment for Critical Resource vulnerability in ASUS S...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-7480</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-7480</guid>
    <pubDate>Fri, 29 May 2026 02:16:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-7480</strong></p>
  <p>An Incorrect Permission Assignment for Critical Resource vulnerability in ASUS System Control Interface allows a local user to elevate privileges to SYSTEM and execute arbitrary code via a crafted RPC call that bypass the validation mechanism. Refer to the 'Security Update for ASUS System Control Interface' section on the ASUS Security Advisory for more information.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-732</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-7480">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-9999 – Inappropriate implementation in ANGLE in Google Chrome on Mac prior to 148.0.777...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9999</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9999</guid>
    <pubDate>Thu, 28 May 2026 23:16:58 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-9999</strong></p>
  <p>Inappropriate implementation in ANGLE in Google Chrome on Mac prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-269</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9999">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-9995 – Use after free in WebXR in Google Chrome prior to 148.0.7778.216 allowed a remot...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9995</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9995</guid>
    <pubDate>Thu, 28 May 2026 23:16:57 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-9995</strong></p>
  <p>Use after free in WebXR in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9995">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-9992 – Use after free in Network in Google Chrome prior to 148.0.7778.216 allowed a rem...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9992</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9992</guid>
    <pubDate>Thu, 28 May 2026 23:16:57 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-9992</strong></p>
  <p>Use after free in Network in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9992">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-9987 – Insufficient validation of untrusted input in WebAppInstalls in Google Chrome on...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9987</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9987</guid>
    <pubDate>Thu, 28 May 2026 23:16:56 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-9987</strong></p>
  <p>Insufficient validation of untrusted input in WebAppInstalls in Google Chrome on Android prior to 148.0.7778.216 allowed a local attacker to execute arbitrary code via a malicious file. (Chromium security severity: High)</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9987">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-9984 – Use after free in UI in Google Chrome on Windows prior to 148.0.7778.216 allowed...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9984</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9984</guid>
    <pubDate>Thu, 28 May 2026 23:16:56 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-9984</strong></p>
  <p>Use after free in UI in Google Chrome on Windows prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9984">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-9983 – Type Confusion in Skia in Google Chrome prior to 148.0.7778.216 allowed a remote...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9983</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9983</guid>
    <pubDate>Thu, 28 May 2026 23:16:56 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-9983</strong></p>
  <p>Type Confusion in Skia in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-843</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9983">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-9978 – Use after free in Glic in Google Chrome prior to 148.0.7778.216 allowed a remote...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9978</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9978</guid>
    <pubDate>Thu, 28 May 2026 23:16:56 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-9978</strong></p>
  <p>Use after free in Glic in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9978">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-9976 – Inappropriate implementation in USB in Google Chrome prior to 148.0.7778.216 all...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9976</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9976</guid>
    <pubDate>Thu, 28 May 2026 23:16:55 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-9976</strong></p>
  <p>Inappropriate implementation in USB in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9976">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-9973 – Out of bounds write in V8 in Google Chrome prior to 148.0.7778.216 allowed a rem...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9973</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9973</guid>
    <pubDate>Thu, 28 May 2026 23:16:55 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-9973</strong></p>
  <p>Out of bounds write in V8 in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9973">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-9969 – Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 14...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9969</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9969</guid>
    <pubDate>Thu, 28 May 2026 23:16:55 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-9969</strong></p>
  <p>Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9969">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-9968 – Integer overflow in V8 in Google Chrome prior to 148.0.7778.216 allowed a remote...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9968</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9968</guid>
    <pubDate>Thu, 28 May 2026 23:16:55 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-9968</strong></p>
  <p>Integer overflow in V8 in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-472</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9968">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-9964 – Use after free in Bluetooth in Google Chrome on Mac prior to 148.0.7778.216 allo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9964</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9964</guid>
    <pubDate>Thu, 28 May 2026 23:16:54 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-9964</strong></p>
  <p>Use after free in Bluetooth in Google Chrome on Mac prior to 148.0.7778.216 allowed an attacker who convinced a user to install a malicious extension to execute arbitrary code via a crafted Chrome Extension. (Chromium security severity: High)</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9964">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-9963 – Uninitialized Use in iOS in Google Chrome on iOS prior to 148.0.7778.216 allowed...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9963</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9963</guid>
    <pubDate>Thu, 28 May 2026 23:16:54 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-9963</strong></p>
  <p>Uninitialized Use in iOS in Google Chrome on iOS prior to 148.0.7778.216 allowed a remote attacker who convinced a user to engage in specific UI gestures to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-457</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9963">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-9962 – Use after free in WebRTC in Google Chrome prior to 148.0.7778.216 allowed a remo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9962</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9962</guid>
    <pubDate>Thu, 28 May 2026 23:16:54 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-9962</strong></p>
  <p>Use after free in WebRTC in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9962">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-9960 – Integer overflow in PDFium in Google Chrome prior to 148.0.7778.216 allowed a re...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9960</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9960</guid>
    <pubDate>Thu, 28 May 2026 23:16:54 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-9960</strong></p>
  <p>Integer overflow in PDFium in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to execute arbitrary code inside a sandbox via a crafted font file. (Chromium security severity: High)</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-472</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9960">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-9957 – Use after free in PDF in Google Chrome prior to 148.0.7778.216 allowed a remote ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9957</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9957</guid>
    <pubDate>Thu, 28 May 2026 23:16:53 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-9957</strong></p>
  <p>Use after free in PDF in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted PDF file. (Chromium security severity: High)</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9957">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-9956 – Use after free in iOS in Google Chrome on iOS prior to 148.0.7778.216 allowed a ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9956</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9956</guid>
    <pubDate>Thu, 28 May 2026 23:16:53 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-9956</strong></p>
  <p>Use after free in iOS in Google Chrome on iOS prior to 148.0.7778.216 allowed a remote attacker who convinced a user to engage in specific UI gestures to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9956">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-9952 – Use after free in WebAudio in Google Chrome prior to 148.0.7778.216 allowed a re...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9952</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9952</guid>
    <pubDate>Thu, 28 May 2026 23:16:53 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-9952</strong></p>
  <p>Use after free in WebAudio in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9952">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-9947 – Use after free in XML in Google Chrome prior to 148.0.7778.216 allowed a remote ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9947</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9947</guid>
    <pubDate>Thu, 28 May 2026 23:16:52 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-9947</strong></p>
  <p>Use after free in XML in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9947">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-9945 – Use after free in Media in Google Chrome on Windows prior to 148.0.7778.216 allo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9945</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9945</guid>
    <pubDate>Thu, 28 May 2026 23:16:52 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-9945</strong></p>
  <p>Use after free in Media in Google Chrome on Windows prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9945">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-9941 – Use after free in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remot...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9941</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9941</guid>
    <pubDate>Thu, 28 May 2026 23:16:52 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-9941</strong></p>
  <p>Use after free in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9941">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-9939 – Heap buffer overflow in WebCodecs in Google Chrome prior to 148.0.7778.216 allow...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9939</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9939</guid>
    <pubDate>Thu, 28 May 2026 23:16:52 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-9939</strong></p>
  <p>Heap buffer overflow in WebCodecs in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-122</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9939">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-9938 – Inappropriate implementation in V8 in Google Chrome prior to 148.0.7778.216 allo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9938</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9938</guid>
    <pubDate>Thu, 28 May 2026 23:16:51 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-9938</strong></p>
  <p>Inappropriate implementation in V8 in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9938">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-9934 – Use after free in Aura in Google Chrome prior to 148.0.7778.216 allowed a remote...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9934</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9934</guid>
    <pubDate>Thu, 28 May 2026 23:16:51 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-9934</strong></p>
  <p>Use after free in Aura in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who convinced a user to engage in specific UI gestures to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9934">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-9928 – Out of bounds read in ANGLE in Google Chrome on Windows prior to 148.0.7778.216 ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9928</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9928</guid>
    <pubDate>Thu, 28 May 2026 23:16:50 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-9928</strong></p>
  <p>Out of bounds read in ANGLE in Google Chrome on Windows prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9928">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-9927 – Use after free in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remot...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9927</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9927</guid>
    <pubDate>Thu, 28 May 2026 23:16:50 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-9927</strong></p>
  <p>Use after free in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9927">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-9922 – Use after free in GPU in Google Chrome on Mac prior to 148.0.7778.216 allowed a ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9922</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9922</guid>
    <pubDate>Thu, 28 May 2026 23:16:50 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-9922</strong></p>
  <p>Use after free in GPU in Google Chrome on Mac prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9922">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-9910 – Out of bounds memory access in ANGLE in Google Chrome prior to 148.0.7778.216 al...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9910</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9910</guid>
    <pubDate>Thu, 28 May 2026 23:16:49 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-9910</strong></p>
  <p>Out of bounds memory access in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9910">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-9909 – Integer overflow in Skia in Google Chrome prior to 148.0.7778.216 allowed a remo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9909</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9909</guid>
    <pubDate>Thu, 28 May 2026 23:16:48 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-9909</strong></p>
  <p>Integer overflow in Skia in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-472</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9909">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-9901 – Use after free in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remot...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9901</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9901</guid>
    <pubDate>Thu, 28 May 2026 23:16:48 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-9901</strong></p>
  <p>Use after free in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9901">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-9897 – Use after free in DOM in Google Chrome prior to 148.0.7778.216 allowed a remote ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9897</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9897</guid>
    <pubDate>Thu, 28 May 2026 23:16:47 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-9897</strong></p>
  <p>Use after free in DOM in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9897">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-9896 – Out of bounds write in V8 in Google Chrome prior to 148.0.7778.216 allowed a rem...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9896</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9896</guid>
    <pubDate>Thu, 28 May 2026 23:16:47 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-9896</strong></p>
  <p>Out of bounds write in V8 in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9896">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-9887 – Use after free in Proxy in Google Chrome prior to 148.0.7778.216 allowed a remot...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9887</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9887</guid>
    <pubDate>Thu, 28 May 2026 23:16:46 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-9887</strong></p>
  <p>Use after free in Proxy in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code via a crafted PAC script. (Chromium security severity: Critical)</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9887">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-9884 – Use after free in Browser in Google Chrome on Mac prior to 148.0.7778.216 allowe...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9884</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9884</guid>
    <pubDate>Thu, 28 May 2026 23:16:46 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-9884</strong></p>
  <p>Use after free in Browser in Google Chrome on Mac prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: Critical)</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9884">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-9883 – Use after free in Base in Google Chrome prior to 148.0.7778.216 allowed a remote...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9883</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9883</guid>
    <pubDate>Thu, 28 May 2026 23:16:46 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-9883</strong></p>
  <p>Use after free in Base in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: Critical)</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9883">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-9879 – Out of bounds write in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9879</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9879</guid>
    <pubDate>Thu, 28 May 2026 23:16:45 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-9879</strong></p>
  <p>Out of bounds write in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: Critical)</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9879">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-9878 – Use after free in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remot...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9878</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9878</guid>
    <pubDate>Thu, 28 May 2026 23:16:45 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-9878</strong></p>
  <p>Use after free in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Critical)</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9878">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-9873 – Use after free in Network in Google Chrome prior to 148.0.7778.216 allowed a rem...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9873</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9873</guid>
    <pubDate>Thu, 28 May 2026 23:16:45 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-9873</strong></p>
  <p>Use after free in Network in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Critical)</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9873">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-10022 – Type Confusion in V8 in Google Chrome prior to 148.0.7778.216 allowed an attacke...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10022</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10022</guid>
    <pubDate>Thu, 28 May 2026 23:16:44 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-10022</strong></p>
  <p>Type Confusion in V8 in Google Chrome prior to 148.0.7778.216 allowed an attacker who convinced a user to install a malicious extension to execute arbitrary code inside a sandbox via a crafted Chrome Extension. (Chromium security severity: Medium)</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-843</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10022">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-10021 – Insufficient validation of untrusted input in USB in Google Chrome prior to 148...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10021</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10021</guid>
    <pubDate>Thu, 28 May 2026 23:16:43 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-10021</strong></p>
  <p>Insufficient validation of untrusted input in USB in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: Medium)</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10021">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-10016 – Use after free in DOM in Google Chrome prior to 148.0.7778.216 allowed a remote ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10016</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10016</guid>
    <pubDate>Thu, 28 May 2026 23:16:43 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-10016</strong></p>
  <p>Use after free in DOM in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10016">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-10015 – Integer overflow in WTF in Google Chrome prior to 148.0.7778.216 allowed a remot...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10015</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10015</guid>
    <pubDate>Thu, 28 May 2026 23:16:43 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-10015</strong></p>
  <p>Integer overflow in WTF in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-472</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10015">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-10013 – Use after free in WebCodecs in Google Chrome prior to 148.0.7778.216 allowed a r...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10013</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10013</guid>
    <pubDate>Thu, 28 May 2026 23:16:43 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-10013</strong></p>
  <p>Use after free in WebCodecs in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10013">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-10009 – Integer overflow in Skia in Google Chrome prior to 148.0.7778.216 allowed a remo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10009</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10009</guid>
    <pubDate>Thu, 28 May 2026 23:16:42 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-10009</strong></p>
  <p>Integer overflow in Skia in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-472</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10009">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-10007 – Use after free in SVG in Google Chrome prior to 148.0.7778.216 allowed a remote ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10007</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10007</guid>
    <pubDate>Thu, 28 May 2026 23:16:42 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-10007</strong></p>
  <p>Use after free in SVG in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10007">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
