2026-07-08
2026-07-08 23:16Z
HIGH

CVE-2026-15133 — Use: after free in InterestGroups in Google Chrome prior to 150.0.7871.115 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-15133

Use after free in InterestGroups in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.8 (HIGH)

CWECWE 416TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-08
2026-07-08 23:16Z
HIGH

CVE-2026-15132 — Uninitialized: Use in V8 in Google Chrome prior to 150.0.7871.115 allowed a remote attacker

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-15132

Uninitialized Use in V8 in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.8 (HIGH)

CWECWE 457VNDUninitializedTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-08
2026-07-08 23:16Z
HIGH

CVE-2026-15129 — Use: after free in Views in Google Chrome prior to 150.0.7871.115 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-15129

Use after free in Views in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical) CVSSv3.1 8.8 (HIGH)

CWECWE 416TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-08
2026-07-08 23:16Z
HIGH

CVE-2026-15126 — Use: after free in Forms in Google Chrome prior to 150.0.7871.115 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-15126

Use after free in Forms in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.8 (HIGH)

CWECWE 416TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-08
2026-07-08 23:16Z
HIGH

CVE-2026-15125 — Inappropriate: implementation in Forms in Google Chrome prior to 150.0.7871.115 allowed a remote attacker

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-15125

Inappropriate implementation in Forms in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.8 (HIGH)

CWECWE 863VNDInappropriateTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-08
2026-07-08 23:16Z
HIGH

CVE-2026-15123 — Inappropriate: implementation in DOM in Google Chrome prior to 150.0.7871.115 allowed a remote attacker

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-15123

Inappropriate implementation in DOM in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.8 (HIGH)

CWECWE 863VNDInappropriateTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-08
2026-07-08 23:16Z
HIGH

CVE-2026-15122 — Insufficient validation of untrusted input in Codecs in Google Chrome on Windows prior to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-15122

Insufficient validation of untrusted input in Codecs in Google Chrome on Windows prior to 150.0.7871.115 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.3 (HIGH)

CWECWE 20TYPVulnerability
8.3
CVSS v3.1
92
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-07-08
2026-07-08 23:16Z
HIGH

CVE-2026-15121 — Use: after free in WebRTC in Google Chrome prior to 150.0.7871.115 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-15121

Use after free in WebRTC in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.8 (HIGH)

CWECWE 416TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-08
2026-07-08 23:16Z
HIGH

CVE-2026-15120 — Use: after free in Core in Google Chrome on Windows prior to 150.0.7871.115 allowed

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-15120

Use after free in Core in Google Chrome on Windows prior to 150.0.7871.115 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.3 (HIGH)

CWECWE 416TYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-07-08
2026-07-08 23:16Z
HIGH

CVE-2026-15119 — Race: in GetUserMedia in Google Chrome prior to 150.0.7871.115 allowed a remote attacker who

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-15119

Race in GetUserMedia in Google Chrome prior to 150.0.7871.115 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.3 (HIGH)

CWECWE 362VNDRaceTYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-07-08
2026-07-08 23:16Z
HIGH

CVE-2026-15118 — Use: after free in Input in Google Chrome prior to 150.0.7871.115 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-15118

Use after free in Input in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.8 (HIGH)

CWECWE 416TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-08
2026-07-08 23:16Z
HIGH

CVE-2026-15116 — Use: after free in Actor in Google Chrome prior to 150.0.7871.115 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-15116

Use after free in Actor in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.8 (HIGH)

CWECWE 416TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-08
2026-07-08 23:16Z
HIGH

CVE-2026-15114 — Out: of bounds read and write in Codecs in Google Chrome prior to 150.0.7871.115

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-15114

Out of bounds read and write in Codecs in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to potentially exploit heap corruption via a crafted video file. (Chromium security severity: High) CVSSv3.1 8.8 (HIGH)

CWECWE 125CWECWE 787TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-08
2026-07-08 23:16Z
CRIT

CVE-2026-15113 — Use: after free in Autofill in Google Chrome on Android prior to 150.0.7871.115 allowed

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-15113

Use after free in Autofill in Google Chrome on Android prior to 150.0.7871.115 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 9.6 (CRITICAL)

CWECWE 416TYPVulnerability
9.6
CVSS v3.1
98
Edit Score
2026-07-08
2026-07-08 23:16Z
HIGH

CVE-2026-15112 — Use: after free in Ozone in Google Chrome prior to 150.0.7871.115 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-15112

Use after free in Ozone in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical) CVSSv3.1 8.8 (HIGH)

CWECWE 416TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-08
2026-07-08 23:16Z
HIGH

CVE-2026-15110 — Use: after free in Extensions in Google Chrome prior to 150.0.7871.115 allowed an attacker

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-15110

Use after free in Extensions in Google Chrome prior to 150.0.7871.115 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted Chrome Extension. (Chromium security severity: High) CVSSv3.1 8.8 (HIGH)

CWECWE 416TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-08
2026-07-08 23:16Z
HIGH

CVE-2026-15107 — Use: after free in IndexedDB in Google Chrome prior to 150.0.7871.115 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-15107

Use after free in IndexedDB in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium) CVSSv3.1 8.8 (HIGH)

CWECWE 416TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-08
2026-07-08 22:17Z
HIGH

CVE-2026-55830 — RestrictedPython: Prior to 8.3, check_function_argument_names() rejected protected guard hook names for regular, variadic, and keyword-only

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-55830

RestrictedPython is a tool that helps to define a subset of the Python language which allows to provide a program input into a trusted environment. Prior to 8.3, check_function_argument_names() rejected protected guard hook names for regular, variadic, and keyword-only arguments but omitted positional-only arguments, allowing __getattr__, _getitem_, _write_, or _print_ to be shadowed by a local parameter and bypass the embedding application's access policy. This issue is fixe CVSSv3.1 8.3 (HIGH)

CWECWE 184VNDRestrictedpythonTYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-07-08
2026-07-08 22:17Z
CRIT

CVE-2026-55471 — Hapifhir Hl7_fhir_core: Prior to 6.9.10, org.hl7.fhir.utilities.XsltUtilities saxonTransform(...) overloads instantiated a bare net.sf.saxon.TransformerFactoryImpl() without ACCESS_EX

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-55471

HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to 6.9.10, org.hl7.fhir.utilities.XsltUtilities saxonTransform(...) overloads instantiated a bare net.sf.saxon.TransformerFactoryImpl() without ACCESS_EXTERNAL_DTD or ACCESS_EXTERNAL_STYLESHEET restrictions, allowing an attacker who controls or can tamper with transformed XML to trigger XML External Entity injection for local file disclosure and blind XXE or SSRF to CVSSv3.1 9.1 (CRITICAL) · EPSS 23th percentile

CWECWE 611VNDHapifhirVNDHapiTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-07-08
2026-07-08 22:17Z
CRIT

CVE-2026-52200 — Generic: An issue in Generic OEM UZ801_v2.1 4G LTE Router V3.4.3 allows a remote attacker

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-52200

An issue in Generic OEM UZ801_v2.1 4G LTE Router V3.4.3 allows a remote attacker to execute arbitrary code via the /ajax web management API endpoint in MifiService.apk CVSSv3.1 9.8 (CRITICAL)

CWECWE 94VNDGenericTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-08
2026-07-08 22:17Z
CRIT

CVE-2026-44024 — Fluentd: Prior to 1.19.3, Fluentd allows dynamically constructing file paths using the ${tag} placeholder, and

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-44024

Fluentd collects events from various data sources and writes them to files, RDBMS, NoSQL, IaaS, SaaS, Hadoop and so on. Prior to 1.19.3, Fluentd allows dynamically constructing file paths using the ${tag} placeholder, and insufficient validation of ${tag} in file configurations such as the path parameter of the out_file plugin allows attackers sending untrusted tags containing path traversal characters to write or overwrite arbitrary files and potentially achieve remote code CVSSv3.1 9.8 (CRITICAL)

CWECWE 22VNDFluentdTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-08
2026-07-08 22:17Z
HIGH

CVE-2026-35552 — CAXperts: Due to missing authorization checks, this allows the attacker to deactivate the application's license.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-35552

In CAXperts UPVWebServices 2.4.2212.603 through 2.7.6 and UDiTH Portal 2026.0.0 through 2026.2.0, an authenticated remote user can invoke an administrative API endpoint intended for privileged users. Due to missing authorization checks, this allows the attacker to deactivate the application's license. CVSSv3.1 8.1 (HIGH)

CWECWE 862VNDCaxpertsTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-07-08
2026-07-08 22:17Z
CRIT

CVE-2026-31309 — Improper authorization in the /tequilapi/config/user endpoint of Mysterium Node from v1.21.1-rc0 before v1.36.0 allows

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-31309

Improper authorization in the /tequilapi/config/user endpoint of Mysterium Node from v1.21.1-rc0 before v1.36.0 allows an unauthenticated attacker to arbitrarily overwrite the node's configuration and achieve a full node takeover via a crafted POST request. CVSSv3.1 9.8 (CRITICAL) · EPSS 29th percentile

CWECWE 862TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-08
2026-07-08 22:17Z
HIGH

CVE-2026-10037 — A compromised or malicious sandboxed application with access to the OpenURI portal via xdg-desktop-portal-gtk

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-10037

A sandbox escape vulnerability exists in the OpenJDK packages provided in Ubuntu. The .jar MIME handlers installed by these packages execute files marked as executable when the mailcap package is installed. A compromised or malicious sandboxed application with access to the OpenURI portal via xdg-desktop-portal-gtk can write a malicious .jar file to the host file system, set its executable bit, and trigger the handler to execute arbitrary code outside of the sandbox environme CVSSv3.1 8.8 (HIGH)

CWECWE 20TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-08
2026-07-08 21:16Z
HIGH

CVE-2026-6896 — GitLab: has remediated an issue in GitLab EE affecting all versions from 13.11 before

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-6896

GitLab has remediated an issue in GitLab EE affecting all versions from 13.11 before 18.11.7, 19.0 before 19.0.4, and 19.1 before 19.1.2 that under certain conditions could have allowed an authenticated user with developer-role permissions to execute arbitrary scripts in another user's browser session due to improper sanitization of user-supplied input. CVSSv3.1 8.7 (HIGH)

CWECWE 79VNDGitlabTYPVulnerability
8.7
CVSS v3.1
94
Edit Score