Use after free in InterestGroups in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
CVSSv3.1 8.8 (HIGH)
CWECWE 416TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-08
2026-07-08 23:16Z
HIGH
CVE-2026-15132 — Uninitialized: Use in V8 in Google Chrome prior to 150.0.7871.115 allowed a remote attacker
Uninitialized Use in V8 in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
CVSSv3.1 8.8 (HIGH)
CWECWE 457VNDUninitializedTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-08
2026-07-08 23:16Z
HIGH
CVE-2026-15129 — Use: after free in Views in Google Chrome prior to 150.0.7871.115 allowed a remote
Use after free in Views in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)
CVSSv3.1 8.8 (HIGH)
CWECWE 416TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-08
2026-07-08 23:16Z
HIGH
CVE-2026-15126 — Use: after free in Forms in Google Chrome prior to 150.0.7871.115 allowed a remote
Use after free in Forms in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
CVSSv3.1 8.8 (HIGH)
CWECWE 416TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-08
2026-07-08 23:16Z
HIGH
CVE-2026-15125 — Inappropriate: implementation in Forms in Google Chrome prior to 150.0.7871.115 allowed a remote attacker
Inappropriate implementation in Forms in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
CVSSv3.1 8.8 (HIGH)
CWECWE 863VNDInappropriateTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-08
2026-07-08 23:16Z
HIGH
CVE-2026-15123 — Inappropriate: implementation in DOM in Google Chrome prior to 150.0.7871.115 allowed a remote attacker
Inappropriate implementation in DOM in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVSSv3.1 8.8 (HIGH)
CWECWE 863VNDInappropriateTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-08
2026-07-08 23:16Z
HIGH
CVE-2026-15122 — Insufficient validation of untrusted input in Codecs in Google Chrome on Windows prior to
Insufficient validation of untrusted input in Codecs in Google Chrome on Windows prior to 150.0.7871.115 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
CVSSv3.1 8.3 (HIGH)
CWECWE 20TYPVulnerability
8.3
CVSS v3.1
92
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-07-08
2026-07-08 23:16Z
HIGH
CVE-2026-15121 — Use: after free in WebRTC in Google Chrome prior to 150.0.7871.115 allowed a remote
Use after free in WebRTC in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
CVSSv3.1 8.8 (HIGH)
CWECWE 416TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-08
2026-07-08 23:16Z
HIGH
CVE-2026-15120 — Use: after free in Core in Google Chrome on Windows prior to 150.0.7871.115 allowed
Use after free in Core in Google Chrome on Windows prior to 150.0.7871.115 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
CVSSv3.1 8.3 (HIGH)
CWECWE 416TYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-07-08
2026-07-08 23:16Z
HIGH
CVE-2026-15119 — Race: in GetUserMedia in Google Chrome prior to 150.0.7871.115 allowed a remote attacker who
Race in GetUserMedia in Google Chrome prior to 150.0.7871.115 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
CVSSv3.1 8.3 (HIGH)
CWECWE 362VNDRaceTYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-07-08
2026-07-08 23:16Z
HIGH
CVE-2026-15118 — Use: after free in Input in Google Chrome prior to 150.0.7871.115 allowed a remote
Use after free in Input in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
CVSSv3.1 8.8 (HIGH)
CWECWE 416TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-08
2026-07-08 23:16Z
HIGH
CVE-2026-15116 — Use: after free in Actor in Google Chrome prior to 150.0.7871.115 allowed a remote
Use after free in Actor in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
CVSSv3.1 8.8 (HIGH)
CWECWE 416TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-08
2026-07-08 23:16Z
HIGH
CVE-2026-15114 — Out: of bounds read and write in Codecs in Google Chrome prior to 150.0.7871.115
Out of bounds read and write in Codecs in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to potentially exploit heap corruption via a crafted video file. (Chromium security severity: High)
CVSSv3.1 8.8 (HIGH)
CWECWE 125CWECWE 787TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-08
2026-07-08 23:16Z
CRIT
CVE-2026-15113 — Use: after free in Autofill in Google Chrome on Android prior to 150.0.7871.115 allowed
Use after free in Autofill in Google Chrome on Android prior to 150.0.7871.115 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
CVSSv3.1 9.6 (CRITICAL)
CWECWE 416TYPVulnerability
9.6
CVSS v3.1
98
Edit Score
2026-07-08
2026-07-08 23:16Z
HIGH
CVE-2026-15112 — Use: after free in Ozone in Google Chrome prior to 150.0.7871.115 allowed a remote
Use after free in Ozone in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)
CVSSv3.1 8.8 (HIGH)
CWECWE 416TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-08
2026-07-08 23:16Z
HIGH
CVE-2026-15110 — Use: after free in Extensions in Google Chrome prior to 150.0.7871.115 allowed an attacker
Use after free in Extensions in Google Chrome prior to 150.0.7871.115 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted Chrome Extension. (Chromium security severity: High)
CVSSv3.1 8.8 (HIGH)
CWECWE 416TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-08
2026-07-08 23:16Z
HIGH
CVE-2026-15107 — Use: after free in IndexedDB in Google Chrome prior to 150.0.7871.115 allowed a remote
Use after free in IndexedDB in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)
CVSSv3.1 8.8 (HIGH)
CWECWE 416TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-08
2026-07-08 22:17Z
HIGH
CVE-2026-55830 — RestrictedPython: Prior to 8.3, check_function_argument_names() rejected protected guard hook names for regular, variadic, and keyword-only
RestrictedPython is a tool that helps to define a subset of the Python language which allows to provide a program input into a trusted environment. Prior to 8.3, check_function_argument_names() rejected protected guard hook names for regular, variadic, and keyword-only arguments but omitted positional-only arguments, allowing __getattr__, _getitem_, _write_, or _print_ to be shadowed by a local parameter and bypass the embedding application's access policy. This issue is fixe
CVSSv3.1 8.3 (HIGH)
CWECWE 184VNDRestrictedpythonTYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-07-08
2026-07-08 22:17Z
CRIT
CVE-2026-55471 — Hapifhir Hl7_fhir_core: Prior to 6.9.10, org.hl7.fhir.utilities.XsltUtilities saxonTransform(...) overloads instantiated a bare net.sf.saxon.TransformerFactoryImpl() without ACCESS_EX
HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to 6.9.10, org.hl7.fhir.utilities.XsltUtilities saxonTransform(...) overloads instantiated a bare net.sf.saxon.TransformerFactoryImpl() without ACCESS_EXTERNAL_DTD or ACCESS_EXTERNAL_STYLESHEET restrictions, allowing an attacker who controls or can tamper with transformed XML to trigger XML External Entity injection for local file disclosure and blind XXE or SSRF to
CVSSv3.1 9.1 (CRITICAL) · EPSS 23th percentile
CWECWE 611VNDHapifhirVNDHapiTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-07-08
2026-07-08 22:17Z
CRIT
CVE-2026-52200 — Generic: An issue in Generic OEM UZ801_v2.1 4G LTE Router V3.4.3 allows a remote attacker
An issue in Generic OEM UZ801_v2.1 4G LTE Router V3.4.3 allows a remote attacker to execute arbitrary code via the /ajax web management API endpoint in MifiService.apk
CVSSv3.1 9.8 (CRITICAL)
CWECWE 94VNDGenericTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-08
2026-07-08 22:17Z
CRIT
CVE-2026-44024 — Fluentd: Prior to 1.19.3, Fluentd allows dynamically constructing file paths using the ${tag} placeholder, and
Fluentd collects events from various data sources and writes them to files, RDBMS, NoSQL, IaaS, SaaS, Hadoop and so on. Prior to 1.19.3, Fluentd allows dynamically constructing file paths using the ${tag} placeholder, and insufficient validation of ${tag} in file configurations such as the path parameter of the out_file plugin allows attackers sending untrusted tags containing path traversal characters to write or overwrite arbitrary files and potentially achieve remote code
CVSSv3.1 9.8 (CRITICAL)
CWECWE 22VNDFluentdTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-08
2026-07-08 22:17Z
HIGH
CVE-2026-35552 — CAXperts: Due to missing authorization checks, this allows the attacker to deactivate the application's license.
In CAXperts UPVWebServices 2.4.2212.603 through 2.7.6 and UDiTH Portal 2026.0.0 through 2026.2.0, an authenticated remote user can invoke an administrative API endpoint intended for privileged users. Due to missing authorization checks, this allows the attacker to deactivate the application's license.
CVSSv3.1 8.1 (HIGH)
CWECWE 862VNDCaxpertsTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-07-08
2026-07-08 22:17Z
CRIT
CVE-2026-31309 — Improper authorization in the /tequilapi/config/user endpoint of Mysterium Node from v1.21.1-rc0 before v1.36.0 allows
Improper authorization in the /tequilapi/config/user endpoint of Mysterium Node from v1.21.1-rc0 before v1.36.0 allows an unauthenticated attacker to arbitrarily overwrite the node's configuration and achieve a full node takeover via a crafted POST request.
CVSSv3.1 9.8 (CRITICAL) · EPSS 29th percentile
CWECWE 862TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-08
2026-07-08 22:17Z
HIGH
CVE-2026-10037 — A compromised or malicious sandboxed application with access to the OpenURI portal via xdg-desktop-portal-gtk
A sandbox escape vulnerability exists in the OpenJDK packages provided in Ubuntu. The .jar MIME handlers installed by these packages execute files marked as executable when the mailcap package is installed. A compromised or malicious sandboxed application with access to the OpenURI portal via xdg-desktop-portal-gtk can write a malicious .jar file to the host file system, set its executable bit, and trigger the handler to execute arbitrary code outside of the sandbox environme
CVSSv3.1 8.8 (HIGH)
CWECWE 20TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-08
2026-07-08 21:16Z
HIGH
CVE-2026-6896 — GitLab: has remediated an issue in GitLab EE affecting all versions from 13.11 before
GitLab has remediated an issue in GitLab EE affecting all versions from 13.11 before 18.11.7, 19.0 before 19.0.4, and 19.1 before 19.1.2 that under certain conditions could have allowed an authenticated user with developer-role permissions to execute arbitrary scripts in another user's browser session due to improper sanitization of user-supplied input.
CVSSv3.1 8.7 (HIGH)