Use after free in V8 in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
CVSSv3.1 8.8 (HIGH)
CWECWE 416TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-30
2026-07-30 01:16Z
HIGH
CVE-2026-17663 — Insufficient validation of untrusted input in GPU in Google Chrome on Android prior to
Insufficient validation of untrusted input in GPU in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
CVSSv3.1 8.3 (HIGH)
CWECWE 20TYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-07-30
2026-07-30 01:16Z
HIGH
CVE-2026-17661 — Use: after free in Loader in Google Chrome prior to 151.0.7922.72 allowed a remote
Use after free in Loader in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
CVSSv3.1 8.8 (HIGH)
CWECWE 416TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-30
2026-07-30 01:16Z
HIGH
CVE-2026-17660 — Insufficient validation of untrusted input in Network in Google Chrome prior to 151.0.7922.72 allowed
Insufficient validation of untrusted input in Network in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
CVSSv3.1 8.3 (HIGH)
CWECWE 20TYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-07-30
2026-07-30 01:16Z
HIGH
CVE-2026-17658 — Use: after free in V8 in Google Chrome prior to 151.0.7922.72 allowed a remote
Use after free in V8 in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
CVSSv3.1 8.8 (HIGH)
CWECWE 416TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-30
2026-07-30 01:16Z
HIGH
CVE-2026-17657 — Use: after free in Navigation in Google Chrome prior to 151.0.7922.72 allowed a remote
Use after free in Navigation in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
CVSSv3.1 8.3 (HIGH)
CWECWE 416TYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-07-30
2026-07-30 01:16Z
CRIT
CVE-2026-17656 — Use: after free in Ozone in Google Chrome prior to 151.0.7922.72 allowed a remote
Use after free in Ozone in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
CVSSv3.1 9.6 (CRITICAL)
CWECWE 416TYPVulnerability
9.6
CVSS v3.1
98
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-07-30
2026-07-30 01:16Z
CRIT
CVE-2026-17655 — Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 151.0.7922.72 allowed
Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
CVSSv3.1 9.6 (CRITICAL)
CWECWE 20TYPVulnerability
9.6
CVSS v3.1
98
Edit Score
2026-07-30
2026-07-30 01:16Z
HIGH
CVE-2026-17653 — Use: after free in Skia in Google Chrome prior to 151.0.7922.72 allowed a remote
Use after free in Skia in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
CVSSv3.1 8.3 (HIGH)
CWECWE 416TYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-07-30
2026-07-30 01:16Z
CRIT
CVE-2026-17652 — Use: after free in Views in Google Chrome prior to 151.0.7922.72 allowed a remote
Use after free in Views in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
CVSSv3.1 9.6 (CRITICAL) · EPSS 23th percentile
CWECWE 416TYPVulnerability
9.6
CVSS v3.1
98
Edit Score
2026-07-30
2026-07-30 01:16Z
CRIT
CVE-2026-17651 — Insufficient validation of untrusted input in Dawn in Google Chrome on Android prior to
Insufficient validation of untrusted input in Dawn in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
CVSSv3.1 9.6 (CRITICAL)
CWECWE 20TYPVulnerability
9.6
CVSS v3.1
98
Edit Score
2026-07-30
2026-07-30 01:16Z
HIGH
CVE-2026-17650 — Use: after free in Compositing in Google Chrome prior to 151.0.7922.72 allowed a remote
Use after free in Compositing in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
CVSSv3.1 8.3 (HIGH)
CWECWE 416TYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-07-29
2026-07-29 22:16Z
HIGH
CVE-2026-67595 — VaahCMS: versions 2.0.0 through 2.3.4 contain a malicious obfuscated JavaScript payload embedded in the
VaahCMS versions 2.0.0 through 2.3.4 contain a malicious obfuscated JavaScript payload embedded in the Blade template responsible for rendering security OTP emails, allowing remote attackers to execute unauthorized code in any browser that renders the affected email template with JavaScript enabled. The payload establishes a WebSocket connection to a hardcoded command-and-control endpoint, installs a password-field keylogger using MutationObserver to capture dynamically added
CVSSv3.1 8.1 (HIGH)
CWECWE 506VNDVaahcmsTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-07-29
2026-07-29 22:16Z
CRIT
CVE-2025-69943 — Hospital: kishan0725 Hospital Management System 4.0 is vulnerale to SQL Injection in get_doctor.php via the
kishan0725 Hospital Management System 4.0 is vulnerale to SQL Injection in get_doctor.php via the parameters doctor and specilizationid.
CVSSv3.1 9.8 (CRITICAL)
CWECWE 89VNDHospitalTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-29
2026-07-29 22:16Z
CRIT
CVE-2025-69942 — Hospital: kishan0725 Hospital Management System 4.0 is vulnerable to SQL Injection in /hms/doctor/view-patient.php?viewid=1.
Sourcecodester CASAP Automated Enrollment System 1.0 is vulnerable to SQL Injection in save_stud.php via the parameters fname, lname, and student_class.
CVSSv3.1 9.8 (CRITICAL)
CWECWE 89VNDSourcecodesterTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-29
2026-07-29 22:16Z
CRIT
CVE-2025-67403 — Sourcecodester: CASAP Automated Enrollment System 1.0 is vulnerable to SQL Injection in update_class.php via
Sourcecodester CASAP Automated Enrollment System 1.0 is vulnerable to SQL Injection in update_class.php via the parameter class_name.
CVSSv3.1 9.8 (CRITICAL)
CWECWE 89VNDSourcecodesterTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-29
2026-07-29 21:17Z
HIGH
CVE-2026-13308 — Autel: MaxiCharger AC Elite Home WebSockets Integer Underflow Remote Code Execution Vulnerability.
Autel MaxiCharger AC Elite Home WebSockets Integer Underflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Autel MaxiCharger AC Elite Home EV chargers. Authentication is not required to exploit this vulnerability.
The specific flaw exists within the handling of WebSocket messages related to the OCPP service. The issue results from the lack of proper validation of user-supplied data, whic
CVSSv3.1 8.1 (HIGH)
CWECWE 191VNDAutelTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-07-29
2026-07-29 21:17Z
CRIT
CVE-2025-65340 — Hospital: kishan0725 Hospital Management System 4.0 is vulnerable to SQL Injection in /betweendates-detailsreports.php.
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 10.1.0 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 that under certain conditions could have allowed an authenticated user with Developer role to access unauthorized information due to insufficient access controls on internal request handling.
CVSSv3.1 8.5 (HIGH)
DriveLock SQL Injection Privilege Escalation Vulnerability. This vulnerability allows remote attackers to escalate privileges on affected installations of DriveLock. Authentication is required to exploit this vulnerability.
The specific flaw exists within the web service, which listens on TCP port 4568 by default. The issue results from the lack of proper validation of a user-supplied string before using it to construct SQL queries. An attacker can leverage this vulnerabilit
CVSSv3.1 8.8 (HIGH)
CWECWE 89VNDDrivelockTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-29
2026-07-29 20:17Z
HIGH
CVE-2026-18022 — Integer: wraparound in IVFFlat index build in pgvector before 0.8.6 allows a database user
Integer wraparound in IVFFlat index build in pgvector before 0.8.6 allows a database user to write data out-of-bounds, which could lead to arbitrary code execution. Only 32-bit systems are affected.
CVSSv3.1 8.8 (HIGH)
CWECWE 787CWECWE 190TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-29
2026-07-29 20:17Z
HIGH
CVE-2026-12436 — GitLab: has remediated an issue in GitLab CE/EE affecting all versions from 18.0 before
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.0 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 that under certain conditions could have allowed an authenticated user to modify CI/CD configuration belonging to another user due to improper validation of user-supplied attributes when processing pipeline schedule inputs.
CVSSv3.1 8.4 (HIGH)
CWECWE 915VNDGitlabTYPVulnerability
8.4
CVSS v3.1
92
Edit Score
2026-07-29
2026-07-29 19:16Z
CRIT
CVE-2026-67429 — Flyto2: Prior to 2.26.6, image.download and related file-writing modules use caller-controlled output_dir instead of validate_path_with_env_config
Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.6, image.download and related file-writing modules use caller-controlled output_dir instead of validate_path_with_env_config and its FLYTO_SANDBOX_DIR confinement, allowing attacker-controlled response bytes to be written to arbitrary filesystem paths the process can access. This issue is fixed in version 2.26.6.
CVSSv3.1 10.0 (CRITICAL)
CWECWE 22CWECWE 73VNDFlyto2TYPVulnerability
10.0
CVSS v3.1
100
Edit Score
2026-07-29
2026-07-29 19:16Z
HIGH
CVE-2026-67428 — Flyto2: Prior to 2.26.7, HTTP-emitting modules including src/core/modules/third_party/developer/http/requests.py, core.api.http_get, core.api.http_post, graphql.query, graphql.mutatio
Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.7, HTTP-emitting modules including src/core/modules/third_party/developer/http/requests.py, core.api.http_get, core.api.http_post, graphql.query, graphql.mutation, monitor.http_check, communication.slack_send, notification.discord.send_message, notification.slack.send_message, notification.teams.send_message, ai.vision_analyze, verify.visual_diff, browser.proxy_rotate, and the agent and ll
CVSSv3.1 8.5 (HIGH)