2026-07-01
2026-07-01 23:16Z
CRIT

CVE-2026-14398 — Use: after free in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-14398

Use after free in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical) CVSSv3.1 9.6 (CRITICAL)

CWECWE 416TYPVulnerability
9.6
CVSS v3.1
98
Edit Score
2026-07-01
2026-07-01 23:16Z
CRIT

CVE-2026-14397 — Out: of bounds write in ANGLE in Google Chrome on Mac prior to 150.0.7871.46

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-14397

Out of bounds write in ANGLE in Google Chrome on Mac prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium) CVSSv3.1 9.6 (CRITICAL)

CWECWE 787TYPVulnerability
9.6
CVSS v3.1
98
Edit Score
2026-07-01
2026-07-01 23:16Z
HIGH

CVE-2026-14395 — Out: of bounds write in V8 in Google Chrome prior to 150.0.7871.46 allowed a

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-14395

Out of bounds write in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Low) CVSSv3.1 8.8 (HIGH)

CWECWE 787TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-01
2026-07-01 23:16Z
HIGH

CVE-2026-14394 — Use: after free in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-14394

Use after free in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Low) CVSSv3.1 8.8 (HIGH)

CWECWE 416TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-01
2026-07-01 23:16Z
HIGH

CVE-2026-14393 — Use: after free in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-14393

Use after free in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium) CVSSv3.1 8.8 (HIGH)

CWECWE 416TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-01
2026-07-01 23:16Z
CRIT

CVE-2026-14392 — Out: of bounds write in Tint in Google Chrome prior to 150.0.7871.46 allowed a

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-14392

Out of bounds write in Tint in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 9.6 (CRITICAL)

CWECWE 787TYPVulnerability
9.6
CVSS v3.1
98
Edit Score
2026-07-01
2026-07-01 23:16Z
CRIT

CVE-2026-14390 — Use: after free in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-14390

Use after free in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 9.6 (CRITICAL)

CWECWE 416TYPVulnerability
9.6
CVSS v3.1
98
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-07-01
2026-07-01 23:16Z
HIGH

CVE-2026-14389 — Integer: overflow in Skia in Google Chrome prior to 150.0.7871.46 allowed a remote attacker

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-14389

Integer overflow in Skia in Google Chrome prior to 150.0.7871.46 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium) CVSSv3.1 8.3 (HIGH)

CWECWE 472TYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-07-01
2026-07-01 23:16Z
CRIT

CVE-2026-14387 — Integer: overflow in Skia in Google Chrome prior to 150.0.7871.46 allowed a remote attacker

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-14387

Integer overflow in Skia in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium) CVSSv3.1 9.6 (CRITICAL)

CWECWE 472TYPVulnerability
9.6
CVSS v3.1
98
Edit Score
2026-07-01
2026-07-01 23:16Z
HIGH

CVE-2026-14385 — Heap: buffer overflow in ANGLE in Google Chrome on Mac prior to 150.0.7871.46 allowed

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-14385

Heap buffer overflow in ANGLE in Google Chrome on Mac prior to 150.0.7871.46 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.8 (HIGH)

CWECWE 122VNDHeapTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-01
2026-07-01 23:16Z
HIGH

CVE-2026-14383 — Inappropriate: implementation in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-14383

Inappropriate implementation in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium) CVSSv3.1 8.8 (HIGH)

CWECWE 94CWECWE 119VNDInappropriateTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-01
2026-07-01 23:16Z
CRIT

CVE-2026-14382 — Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 150.0.7871.46 allowed

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-14382

Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 9.6 (CRITICAL)

CWECWE 20TYPVulnerability
9.6
CVSS v3.1
98
Edit Score
2026-07-01
2026-07-01 22:16Z
CRIT

CVE-2026-52186 — SQL: Injection vulnerability in UTT nv518G nv518GV3v3.2.7-210919-161313 allows a remote attacker to execute arbitrary

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-52186

SQL Injection vulnerability in UTT nv518G nv518GV3v3.2.7-210919-161313 allows a remote attacker to execute arbitrary code via the gohead/sub_463bbc component CVSSv3.1 9.8 (CRITICAL)

CWECWE 89TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-01
2026-07-01 21:17Z
HIGH

CVE-2026-50521 — Use: after free in Microsoft Edge (Chromium-based) allows an authorized attacker to execute code

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-50521

Use after free in Microsoft Edge (Chromium-based) allows an authorized attacker to execute code over a network. CVSSv3.1 8.3 (HIGH)

CWECWE 416TYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-07-01
2026-07-01 20:17Z
HIGH

CVE-2026-58592 — Ladybird: contains a dangling-reference memory-safety flaw in its WebAssembly ESM-integration module loader.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-58592

Ladybird contains a dangling-reference memory-safety flaw in its WebAssembly ESM-integration module loader. When a JavaScript function is imported into a WebAssembly module via the ESM path, WebAssemblyModule.cpp passes a stack-local Wasm::FunctionType by reference to create_host_function, whose host callback captures and later reads that reference; once the ESM link-loop iteration ends the FunctionType is destroyed, leaving the callback with a dangling reference (the normal CVSSv3.1 8.3 (HIGH)

CWECWE 787CWECWE 843CWECWE 825VNDLadybirdTYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-07-01
2026-07-01 20:17Z
CRIT

CVE-2026-58457 — Shenzhen: Aitemi M300 Wi-Fi Repeater (hardware model MT02) contains an unauthenticated OS command injection

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-58457

Shenzhen Aitemi M300 Wi-Fi Repeater (hardware model MT02) contains an unauthenticated OS command injection vulnerability that allows network-adjacent attackers to execute arbitrary shell commands by injecting unsanitized input through the smacfilter_conf handler in the commuos web backend. Attackers can append semicolon-delimited payloads to the name, enable, or mac GET parameters, which are passed without sanitization into sprintf() to build uci shell commands executed via d CVSSv3.1 9.8 (CRITICAL)

CWECWE 78VNDShenzhenTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-01
2026-07-01 20:17Z
CRIT

CVE-2026-14363 — Mediawiki Cargo: Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-14363

Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in The Wikimedia Foundation Mediawiki - Cargo Extension allows SQL Injection. This issue affects Mediawiki - Cargo Extension: from * before 1.43.9,1.44.6,1.45.4. CVSSv3.1 9.8 (CRITICAL) · EPSS 17th percentile

CWECWE 89VNDMediawikiTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-01
2026-07-01 19:16Z
CRIT

CVE-2026-53492 — Linuxfoundation Containerd: In Versions prior to 2.3.2, 2.2.5 and 2.1.9, the CRI implementation improperly trusts Container

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-53492

containerd is an open-source container runtime. In Versions prior to 2.3.2, 2.2.5 and 2.1.9, the CRI implementation improperly trusts Container Device Interface (CDI) annotations found within untrusted checkpoint image metadata during container restoration. When restoring a container from a checkpoint, containerd preserves CDI-related annotations from the checkpoint archive rather than relying solely on the pod's create-time specification. This allows a user with pod creation CVSSv3.1 9.6 (CRITICAL)

CWECWE 863CWECWE 20VNDLinuxfoundationTYPVulnerability
9.6
CVSS v3.1
98
Edit Score
2026-07-01
2026-07-01 19:16Z
CRIT

CVE-2026-51947 — Pivotal: An issue in Pivotal CRM 6.6.4.08 and systems using patch-ghi-15381-cwe-502-20251225.zip (fixed in Pivotal CRM

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-51947

An issue in Pivotal CRM 6.6.4.08 and systems using patch-ghi-15381-cwe-502-20251225.zip (fixed in Pivotal CRM 6.6.5.10 and Patch_CWE502_20260316.zip) allows a remote attacker to execute arbitrary code via the Pivotal.Engine.Client.Services.Conversion.dll component. NOTE: this issue exists because of an incomplete fix for CVE-2026-39253. CVSSv3.1 9.8 (CRITICAL)

CWECWE 502VNDPivotalTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-01
2026-07-01 19:16Z
CRIT

CVE-2026-50195 — Linuxfoundation Containerd: This can lead to a compromise of the affected pods, allowing the attacker to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-50195

containerd is an open-source container runtime. Versions prior to 2.3.2, 2.2.5 and 2.1.9 contain a vulnerability in the CRI checkpoint import process where it fails to validate the image references specified within a checkpoint image's configuration. An attacker with permissions to create pods can use a crafted checkpoint image to force containerd to pull a malicious image and assign it an arbitrary local tag, thereby poisoning the node's local image cache. Subsequently, if o CVSSv3.1 9.9 (CRITICAL)

CWECWE 345CWECWE 829VNDLinuxfoundationTYPVulnerability
9.9
CVSS v3.1
100
Edit Score
2026-07-01
2026-07-01 19:16Z
CRIT

CVE-2026-50160 — Hoppscotch: In self-hosted deployments of hoppscotch-backend from version 2026.4.1 and earlier, the unauthenticated POST /v1/onboarding/config

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-50160

Hoppscotch is an API development ecosystem. In self-hosted deployments of hoppscotch-backend from version 2026.4.1 and earlier, the unauthenticated POST /v1/onboarding/config endpoint is vulnerable to mass assignment. The global NestJS ValidationPipe is configured without whitelist: true, so extra properties on the request body that are not declared in SaveOnboardingConfigRequest are not stripped and are iterated in the service layer as if they were legitimate InfraConfig ent CVSSv3.1 10.0 (CRITICAL)

CWECWE 915VNDHoppscotchTYPVulnerability
10.0
CVSS v3.1
100
Edit Score
2026-07-01
2026-07-01 18:16Z
CRIT

CVE-2026-58521 — Mediawiki Cargo: Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-58521

Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in The Wikimedia Foundation Mediawiki - Cargo Extension allows SQL Injection. This issue affects Mediawiki - Cargo Extension: from * before 1.43.9,1.44.6,1.45.4. CVSSv3.1 9.8 (CRITICAL) · EPSS 16th percentile

CWECWE 89VNDMediawikiTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-01
2026-07-01 18:16Z
HIGH

CVE-2026-49091 — Output: Improper Output Neutralization for Logs (CWE-117) in Kibana can lead to log injection via

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-49091

Improper Output Neutralization for Logs (CWE-117) in Kibana can lead to log injection via Log Injection-Tampering-Forging (CAPEC-93). An attacker can supply specially crafted input that is written to log files without proper neutralization. When the log files are subsequently viewed in a terminal that interprets control sequences, the injected content may alter the displayed log data. CVSSv3.1 8.0 (HIGH)

CWECWE 116VNDOutputTYPVulnerability
8.0
CVSS v3.1
90
Edit Score
2026-07-01
2026-07-01 18:12Z
INFO

v9.4.0-rc2

BloodHound releases·github.com

BloodHound v9.4.0-rc2 release candidate published with internal code review preparation, readability improvements, audit logging middleware proposal, and data quality enhancements including environment_kind fields and database migration fixes.

SWBloodhoundVNDSpecteropsTYPTool
28
Edit Score
2026-07-01
2026-07-01 17:16Z
CRIT

CVE-2026-58453 — JAIOTlink: C492A-W6 Wi-Fi IP cameras running firmware 4.8.30.57701411 contain a hard-coded credentials vulnerability that

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-58453

JAIOTlink C492A-W6 Wi-Fi IP cameras running firmware 4.8.30.57701411 contain a hard-coded credentials vulnerability that allows network-adjacent attackers to gain unauthorized access by using the default admin username with an empty password accepted by the anyka_ipc HTTP service on port 80. Attackers can authenticate with these hardcoded credentials to access camera snapshots, video streams, network configuration, and factory-level API endpoints including the SetMAC command CVSSv3.1 9.8 (CRITICAL)

CWECWE 1392VNDJaiotlinkTYPVulnerability
9.8
CVSS v3.1
99
Edit Score