Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
8.8 HIGH
CVE-2026-10013 — Google Chrome WebCodecs Use After Free Arbitrary Code Execution

Use after free in WebCodecs in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

linux_kernel chrome macos windows edge_chromium | Remote | Memory Corruption
May 28, 2026 Jun 01, 2026
May 28, 2026
Jun 01, 2026
8.3 HIGH
CVE-2026-10012 — Google Chrome Skia Use-After-Free Vulnerability

Use after free in Skia in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Ch…

linux_kernel chrome macos windows edge_chromium | Remote | Memory Corruption
May 28, 2026 May 29, 2026
May 28, 2026
May 29, 2026
3.1 LOW
CVE-2026-10011 — Google Chrome Skia Cross-Origin Data Leak Vulnerability

Inappropriate implementation in Skia in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Ch…

chrome edge_chromium | Remote | Information Disclosure
May 28, 2026 Jun 03, 2026
May 28, 2026
Jun 03, 2026
5.0 MEDIUM
CVE-2026-10010 — Google Chrome Android Site Isolation Bypass (Remote)

Inappropriate implementation in Input in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTM…

android chrome | Remote | Misconfiguration
May 28, 2026 Jun 03, 2026
May 28, 2026
Jun 03, 2026
7.5 HIGH
CVE-2026-10009 — Google Chrome Skia Integer Overflow Remote Code Execution

Integer overflow in Skia in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to execute arbitrary code inside a sandbox via a crafted HTML page…

linux_kernel chrome macos windows edge_chromium | Remote | Memory Corruption
May 28, 2026 Jun 01, 2026
May 28, 2026
Jun 01, 2026
6.5 MEDIUM
CVE-2026-10008 — Google Chrome Android GPU Uninitialized Use Information Disclosure

Uninitialized Use in GPU in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromi…

android chrome | Remote | Information Disclosure
May 28, 2026 Jun 03, 2026
May 28, 2026
Jun 03, 2026
8.8 HIGH
CVE-2026-10007 — Google Chrome SVG Use-After-Free Vulnerability

Use after free in SVG in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

linux_kernel chrome macos windows edge_chromium | Remote | Memory Corruption
May 28, 2026 Jun 01, 2026
May 28, 2026
Jun 01, 2026
7.5 HIGH
CVE-2026-10006 — Google Chrome WebAudio Remote Code Execution Vulnerability

Race in WebAudio in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

linux_kernel chrome macos windows edge_chromium | Remote | Race Condition
May 28, 2026 May 29, 2026
May 28, 2026
May 29, 2026
7.5 HIGH
CVE-2026-10005 — Google Chrome Use After Free in WebAppInstalls on Mac

Use after free in WebAppInstalls in Google Chrome on Mac prior to 148.0.7778.216 allowed a remote attacker who convinced a user to engage in specific UI gestures to execute arbitrary code via a craft…

chrome macos edge_chromium | Remote | Memory Corruption
May 28, 2026 Jun 01, 2026
May 28, 2026
Jun 01, 2026
6.5 MEDIUM
CVE-2026-10004 — Google Chrome UI Spoofing Vulnerability

Insufficient validation of untrusted input in Passwords in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity:…

linux_kernel chrome macos windows edge_chromium | Remote | Cross-Site Scripting
May 28, 2026 May 29, 2026
May 28, 2026
May 29, 2026
7.5 HIGH
CVE-2026-10003 — Google Chrome Use-After-Free in Views

Use after free in Views in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who convinced a user to engage in specific UI gestures to execute arbitrary code via a crafted HTML page. (C…

linux_kernel chrome macos windows edge_chromium | Remote | Memory Corruption
May 28, 2026 Jun 01, 2026
May 28, 2026
Jun 01, 2026
8.8 HIGH
CVE-2026-10002 — Google Chrome PDFium Use-After-Free Heap Corruption Vulnerability

Use after free in PDFium in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file. (Chromium security severity: High)

linux_kernel chrome macos windows edge_chromium | Remote | Memory Corruption
May 28, 2026 May 29, 2026
May 28, 2026
May 29, 2026
8.3 HIGH
CVE-2026-10001 — Google Chrome PerformanceManager Use After Free Vulnerability

Use after free in PerformanceManager in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted …

linux_kernel chrome macos windows edge_chromium | Remote | Memory Corruption
May 28, 2026 May 29, 2026
May 28, 2026
May 29, 2026
8.3 HIGH
CVE-2026-10000 — Google Chrome Use After Free in Windows Renderer Process

Use after free in Passwords in Google Chrome on Windows prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafte…

chrome windows edge_chromium | Remote | Memory Corruption
May 28, 2026 Jun 03, 2026
May 28, 2026
Jun 03, 2026
5.3 MEDIUM
CVE-2026-49299 — OpenStack Neutron Policy Name Confusion Vulnerability

In OpenStack Neutron before 28.0.1, the tagging controller enforces plural policy action names on single-tag write operations while the defined policy rules use singular names. The mismatched names e…

neutron | Remote | Authorization
May 28, 2026 Jun 02, 2026
May 28, 2026
Jun 02, 2026
8.8 HIGH
CVE-2026-48116 — AnythingLLM: RCE via ripgrep --pre argument injection in filesystem-search-files agent sk…

AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. Prior to 1.13.0, the filesystem-search-files agent skill passes its LLM-con…

anythingllm | Remote | Injection
May 28, 2026 May 30, 2026
May 28, 2026
May 30, 2026
4.3 MEDIUM
CVE-2026-47713 — AnythingLLM: Legacy mobile device tokens bypass multi-user workspace scoping after mode m…

AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. Prior to 1.13.0, an approved mobile device token created in single-user mod…

anythingllm | Remote | Authentication
May 28, 2026 Jun 03, 2026
May 28, 2026
Jun 03, 2026
5.3 MEDIUM
CVE-2026-45410 — Time-based user enumeration in TREK authentication endpoint

TREK is a collaborative travel planner. Prior to 3.0.18, early return on missing user during login flow allowed an attacker to enumerate valid user accounts via response timing discrepancy. When an e…

trek | Remote | Authentication
May 28, 2026 May 29, 2026
May 28, 2026
May 29, 2026
2.5 LOW
CVE-2026-45403 — AnythingLLM: filesystem-copy-file follows nested symlinks and copies files from outside t…

AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. Prior to 1.13.0, the AnythingLLM agent filesystem copy tool validates only …

anythingllm | Path Traversal
May 28, 2026 Jun 02, 2026
May 28, 2026
Jun 02, 2026
4.7 MEDIUM
CVE-2026-45366 — typescript-utcp: SSRF via attacker-controlled OpenAPI servers[0].url in HTTP communicatio…

typescript-utcp is a typescript implementation of UTCP. Prior to 1.1.2, the @utcp/http package is vulnerable to a blind Server-Side Request Forgery (SSRF) caused by a trust-boundary inconsistency bet…

Remote | Server-Side Request Forgery
May 28, 2026 Jun 01, 2026
May 28, 2026
Jun 01, 2026
Showing 20 of 7097 Results