2026-07-30
2026-07-30 01:16Z
HIGH

CVE-2026-17665 — Use: after free in V8 in Google Chrome prior to 151.0.7922.72 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-17665

Use after free in V8 in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.8 (HIGH)

CWECWE 416TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-30
2026-07-30 01:16Z
HIGH

CVE-2026-17663 — Insufficient validation of untrusted input in GPU in Google Chrome on Android prior to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-17663

Insufficient validation of untrusted input in GPU in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.3 (HIGH)

CWECWE 20TYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-07-30
2026-07-30 01:16Z
HIGH

CVE-2026-17661 — Use: after free in Loader in Google Chrome prior to 151.0.7922.72 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-17661

Use after free in Loader in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.8 (HIGH)

CWECWE 416TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-30
2026-07-30 01:16Z
HIGH

CVE-2026-17660 — Insufficient validation of untrusted input in Network in Google Chrome prior to 151.0.7922.72 allowed

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-17660

Insufficient validation of untrusted input in Network in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.3 (HIGH)

CWECWE 20TYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-07-30
2026-07-30 01:16Z
HIGH

CVE-2026-17658 — Use: after free in V8 in Google Chrome prior to 151.0.7922.72 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-17658

Use after free in V8 in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.8 (HIGH)

CWECWE 416TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-30
2026-07-30 01:16Z
HIGH

CVE-2026-17657 — Use: after free in Navigation in Google Chrome prior to 151.0.7922.72 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-17657

Use after free in Navigation in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.3 (HIGH)

CWECWE 416TYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-07-30
2026-07-30 01:16Z
CRIT

CVE-2026-17656 — Use: after free in Ozone in Google Chrome prior to 151.0.7922.72 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-17656

Use after free in Ozone in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical) CVSSv3.1 9.6 (CRITICAL)

CWECWE 416TYPVulnerability
9.6
CVSS v3.1
98
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-07-30
2026-07-30 01:16Z
CRIT

CVE-2026-17655 — Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 151.0.7922.72 allowed

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-17655

Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical) CVSSv3.1 9.6 (CRITICAL)

CWECWE 20TYPVulnerability
9.6
CVSS v3.1
98
Edit Score
2026-07-30
2026-07-30 01:16Z
HIGH

CVE-2026-17653 — Use: after free in Skia in Google Chrome prior to 151.0.7922.72 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-17653

Use after free in Skia in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical) CVSSv3.1 8.3 (HIGH)

CWECWE 416TYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-07-30
2026-07-30 01:16Z
CRIT

CVE-2026-17652 — Use: after free in Views in Google Chrome prior to 151.0.7922.72 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-17652

Use after free in Views in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical) CVSSv3.1 9.6 (CRITICAL) · EPSS 23th percentile

CWECWE 416TYPVulnerability
9.6
CVSS v3.1
98
Edit Score
2026-07-30
2026-07-30 01:16Z
CRIT

CVE-2026-17651 — Insufficient validation of untrusted input in Dawn in Google Chrome on Android prior to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-17651

Insufficient validation of untrusted input in Dawn in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical) CVSSv3.1 9.6 (CRITICAL)

CWECWE 20TYPVulnerability
9.6
CVSS v3.1
98
Edit Score
2026-07-30
2026-07-30 01:16Z
HIGH

CVE-2026-17650 — Use: after free in Compositing in Google Chrome prior to 151.0.7922.72 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-17650

Use after free in Compositing in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical) CVSSv3.1 8.3 (HIGH)

CWECWE 416TYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-07-29
2026-07-29 22:16Z
HIGH

CVE-2026-67595 — VaahCMS: versions 2.0.0 through 2.3.4 contain a malicious obfuscated JavaScript payload embedded in the

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-67595

VaahCMS versions 2.0.0 through 2.3.4 contain a malicious obfuscated JavaScript payload embedded in the Blade template responsible for rendering security OTP emails, allowing remote attackers to execute unauthorized code in any browser that renders the affected email template with JavaScript enabled. The payload establishes a WebSocket connection to a hardcoded command-and-control endpoint, installs a password-field keylogger using MutationObserver to capture dynamically added CVSSv3.1 8.1 (HIGH)

CWECWE 506VNDVaahcmsTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-07-29
2026-07-29 22:16Z
CRIT

CVE-2025-69943 — Hospital: kishan0725 Hospital Management System 4.0 is vulnerale to SQL Injection in get_doctor.php via the

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2025-69943

kishan0725 Hospital Management System 4.0 is vulnerale to SQL Injection in get_doctor.php via the parameters doctor and specilizationid. CVSSv3.1 9.8 (CRITICAL)

CWECWE 89VNDHospitalTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-29
2026-07-29 22:16Z
CRIT

CVE-2025-69942 — Hospital: kishan0725 Hospital Management System 4.0 is vulnerable to SQL Injection in /hms/doctor/view-patient.php?viewid=1.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2025-69942

kishan0725 Hospital Management System 4.0 is vulnerable to SQL Injection in /hms/doctor/view-patient.php?viewid=1. CVSSv3.1 9.8 (CRITICAL)

CWECWE 89VNDHospitalTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-29
2026-07-29 22:16Z
CRIT

CVE-2025-67404 — Sourcecodester: CASAP Automated Enrollment System 1.0 is vulnerable to SQL Injection in save_stud.php via

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2025-67404

Sourcecodester CASAP Automated Enrollment System 1.0 is vulnerable to SQL Injection in save_stud.php via the parameters fname, lname, and student_class. CVSSv3.1 9.8 (CRITICAL)

CWECWE 89VNDSourcecodesterTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-29
2026-07-29 22:16Z
CRIT

CVE-2025-67403 — Sourcecodester: CASAP Automated Enrollment System 1.0 is vulnerable to SQL Injection in update_class.php via

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2025-67403

Sourcecodester CASAP Automated Enrollment System 1.0 is vulnerable to SQL Injection in update_class.php via the parameter class_name. CVSSv3.1 9.8 (CRITICAL)

CWECWE 89VNDSourcecodesterTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-29
2026-07-29 21:17Z
HIGH

CVE-2026-13308 — Autel: MaxiCharger AC Elite Home WebSockets Integer Underflow Remote Code Execution Vulnerability.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-13308

Autel MaxiCharger AC Elite Home WebSockets Integer Underflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Autel MaxiCharger AC Elite Home EV chargers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of WebSocket messages related to the OCPP service. The issue results from the lack of proper validation of user-supplied data, whic CVSSv3.1 8.1 (HIGH)

CWECWE 191VNDAutelTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-07-29
2026-07-29 21:17Z
CRIT

CVE-2025-65340 — Hospital: kishan0725 Hospital Management System 4.0 is vulnerable to SQL Injection in /betweendates-detailsreports.php.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2025-65340

kishan0725 Hospital Management System 4.0 is vulnerable to SQL Injection in /betweendates-detailsreports.php. CVSSv3.1 9.8 (CRITICAL)

CWECWE 89VNDHospitalTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-29
2026-07-29 20:17Z
HIGH

CVE-2026-6267 — GitLab: has remediated an issue in GitLab CE/EE affecting all versions from 10.1.0 before

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-6267

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 10.1.0 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 that under certain conditions could have allowed an authenticated user with Developer role to access unauthorized information due to insufficient access controls on internal request handling. CVSSv3.1 8.5 (HIGH)

CWECWE 201VNDGitlabTYPVulnerability
8.5
CVSS v3.1
93
Edit Score
2026-07-29
2026-07-29 20:17Z
HIGH

CVE-2026-5490 — DriveLock: SQL Injection Privilege Escalation Vulnerability.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-5490

DriveLock SQL Injection Privilege Escalation Vulnerability. This vulnerability allows remote attackers to escalate privileges on affected installations of DriveLock. Authentication is required to exploit this vulnerability. The specific flaw exists within the web service, which listens on TCP port 4568 by default. The issue results from the lack of proper validation of a user-supplied string before using it to construct SQL queries. An attacker can leverage this vulnerabilit CVSSv3.1 8.8 (HIGH)

CWECWE 89VNDDrivelockTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-29
2026-07-29 20:17Z
HIGH

CVE-2026-18022 — Integer: wraparound in IVFFlat index build in pgvector before 0.8.6 allows a database user

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-18022

Integer wraparound in IVFFlat index build in pgvector before 0.8.6 allows a database user to write data out-of-bounds, which could lead to arbitrary code execution. Only 32-bit systems are affected. CVSSv3.1 8.8 (HIGH)

CWECWE 787CWECWE 190TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-29
2026-07-29 20:17Z
HIGH

CVE-2026-12436 — GitLab: has remediated an issue in GitLab CE/EE affecting all versions from 18.0 before

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-12436

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.0 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 that under certain conditions could have allowed an authenticated user to modify CI/CD configuration belonging to another user due to improper validation of user-supplied attributes when processing pipeline schedule inputs. CVSSv3.1 8.4 (HIGH)

CWECWE 915VNDGitlabTYPVulnerability
8.4
CVSS v3.1
92
Edit Score
2026-07-29
2026-07-29 19:16Z
CRIT

CVE-2026-67429 — Flyto2: Prior to 2.26.6, image.download and related file-writing modules use caller-controlled output_dir instead of validate_path_with_env_config

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-67429

Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.6, image.download and related file-writing modules use caller-controlled output_dir instead of validate_path_with_env_config and its FLYTO_SANDBOX_DIR confinement, allowing attacker-controlled response bytes to be written to arbitrary filesystem paths the process can access. This issue is fixed in version 2.26.6. CVSSv3.1 10.0 (CRITICAL)

CWECWE 22CWECWE 73VNDFlyto2TYPVulnerability
10.0
CVSS v3.1
100
Edit Score
2026-07-29
2026-07-29 19:16Z
HIGH

CVE-2026-67428 — Flyto2: Prior to 2.26.7, HTTP-emitting modules including src/core/modules/third_party/developer/http/requests.py, core.api.http_get, core.api.http_post, graphql.query, graphql.mutatio

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-67428

Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.7, HTTP-emitting modules including src/core/modules/third_party/developer/http/requests.py, core.api.http_get, core.api.http_post, graphql.query, graphql.mutation, monitor.http_check, communication.slack_send, notification.discord.send_message, notification.slack.send_message, notification.teams.send_message, ai.vision_analyze, verify.visual_diff, browser.proxy_rotate, and the agent and ll CVSSv3.1 8.5 (HIGH)

CWECWE 918VNDFlyto2TYPVulnerability
8.5
CVSS v3.1
93
Edit Score