2026-06-17
2026-06-17 13:20Z
CRIT

CVE-2026-22332 — SQL: Unauthenticated SQL Injection in Tutor LMS Pro <= 3.9.6 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-22332

Unauthenticated SQL Injection in Tutor LMS Pro <= 3.9.6 versions. CVSSv3.1 9.3 (CRITICAL)

CWECWE 89TYPVulnerability
9.3
CVSS v3.1
97
Edit Score
2026-06-17
2026-06-17 13:20Z
HIGH

CVE-2026-22331 — File: Unauthenticated Local File Inclusion in AutoParts <= 1.5.8 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-22331

Unauthenticated Local File Inclusion in AutoParts <= 1.5.8 versions. CVSSv3.1 8.1 (HIGH)

CWECWE 98TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-06-17
2026-06-17 13:20Z
HIGH

CVE-2026-22330 — File: Unauthenticated Local File Inclusion in Right Way <= 4.0 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-22330

Unauthenticated Local File Inclusion in Right Way <= 4.0 versions. CVSSv3.1 8.1 (HIGH)

CWECWE 98TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-06-17
2026-06-17 13:20Z
CRIT

CVE-2026-22327 — Subscriber: Arbitrary File Upload in Restaurt <= 1.0.4 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-22327

Subscriber Arbitrary File Upload in Restaurt <= 1.0.4 versions. CVSSv3.1 9.9 (CRITICAL)

CWECWE 434VNDSubscriberTYPVulnerability
9.9
CVSS v3.1
100
Edit Score
2026-06-17
2026-06-17 13:20Z
HIGH

CVE-2026-22326 — File: Unauthenticated Local File Inclusion in Reprizo <= 1.0.8 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-22326

Unauthenticated Local File Inclusion in Reprizo <= 1.0.8 versions. CVSSv3.1 8.1 (HIGH)

CWECWE 98TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-06-17
2026-06-17 13:20Z
HIGH

CVE-2026-22325 — File: Unauthenticated Local File Inclusion in Promo <= 1.3.0 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-22325

Unauthenticated Local File Inclusion in Promo <= 1.3.0 versions. CVSSv3.1 8.1 (HIGH)

CWECWE 98TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-06-17
2026-06-17 13:20Z
HIGH

CVE-2026-12468 — Race: in Updater in Google Chrome on Mac prior to 149.0.7827.155 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-12468

Race in Updater in Google Chrome on Mac prior to 149.0.7827.155 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.3 (HIGH)

CWECWE 362VNDRaceTYPVulnerability
8.3
CVSS v3.1
92
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-06-17
2026-06-17 13:20Z
HIGH

CVE-2026-12467 — Use: after free in Extensions in Google Chrome prior to 149.0.7827.155 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-12467

Use after free in Extensions in Google Chrome prior to 149.0.7827.155 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.3 (HIGH)

CWECWE 416TYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-06-17
2026-06-17 13:20Z
HIGH

CVE-2026-12466 — Heap: buffer overflow in WebRTC in Google Chrome on Windows prior to 149.0.7827.155 allowed

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-12466

Heap buffer overflow in WebRTC in Google Chrome on Windows prior to 149.0.7827.155 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.8 (HIGH)

CWECWE 122VNDHeapTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-17
2026-06-17 13:20Z
HIGH

CVE-2026-12465 — Object: lifecycle issue in Metrics in Google Chrome prior to 149.0.7827.155 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-12465

Object lifecycle issue in Metrics in Google Chrome prior to 149.0.7827.155 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.3 (HIGH)

CWECWE 20VNDObjectTYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-06-17
2026-06-17 13:20Z
HIGH

CVE-2026-12464 — Use: after free in Browser in Google Chrome prior to 149.0.7827.155 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-12464

Use after free in Browser in Google Chrome prior to 149.0.7827.155 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.3 (HIGH)

CWECWE 416TYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-06-17
2026-06-17 13:20Z
HIGH

CVE-2026-12454 — Race: in Safe Browsing in Google Chrome on Mac prior to 149.0.7827.155 allowed a

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-12454

Race in Safe Browsing in Google Chrome on Mac prior to 149.0.7827.155 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.3 (HIGH)

CWECWE 362VNDRaceTYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-06-17
2026-06-17 13:20Z
HIGH

CVE-2026-12452 — Use: after free in Downloads in Google Chrome on Android prior to 149.0.7827.155 allowed

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-12452

Use after free in Downloads in Google Chrome on Android prior to 149.0.7827.155 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.8 (HIGH)

CWECWE 416TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-17
2026-06-17 13:20Z
HIGH

CVE-2026-12451 — Use: after free in DigitalCredentials in Google Chrome prior to 149.0.7827.155 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-12451

Use after free in DigitalCredentials in Google Chrome prior to 149.0.7827.155 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.3 (HIGH)

CWECWE 416TYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-06-17
2026-06-17 13:20Z
HIGH

CVE-2026-12448 — Inappropriate: implementation in WebView in Google Chrome on Android prior to 149.0.7827.155 allowed a

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-12448

Inappropriate implementation in WebView in Google Chrome on Android prior to 149.0.7827.155 allowed a remote attacker to perform privilege escalation via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.8 (HIGH)

CWECWE 269VNDInappropriateTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-17
2026-06-17 13:20Z
HIGH

CVE-2026-12447 — Heap: buffer overflow in WebRTC in Google Chrome prior to 149.0.7827.155 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-12447

Heap buffer overflow in WebRTC in Google Chrome prior to 149.0.7827.155 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.8 (HIGH)

CWECWE 122VNDHeapTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-17
2026-06-17 13:19Z
HIGH

CVE-2026-12443 — Use: after free in Web Authentication in Google Chrome prior to 149.0.7827.155 allowed a

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-12443

Use after free in Web Authentication in Google Chrome prior to 149.0.7827.155 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: Critical) CVSSv3.1 8.8 (HIGH)

CWECWE 416TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-17
2026-06-17 13:19Z
HIGH

CVE-2026-12442 — Use: after free in Passwords in Google Chrome on Android prior to 149.0.7827.155 allowed

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-12442

Use after free in Passwords in Google Chrome on Android prior to 149.0.7827.155 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: Critical) CVSSv3.1 8.8 (HIGH)

CWECWE 416TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-17
2026-06-17 13:19Z
HIGH

CVE-2026-12441 — Use: after free in File Input in Google Chrome on Linux prior to 149.0.7827.155

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-12441

Use after free in File Input in Google Chrome on Linux prior to 149.0.7827.155 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical) CVSSv3.1 8.8 (HIGH)

CWECWE 416TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-17
2026-06-17 13:19Z
CRIT

CVE-2026-12440 — Use: after free in DigitalCredentials in Google Chrome on Windows prior to 149.0.7827.155 allowed

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-12440

Use after free in DigitalCredentials in Google Chrome on Windows prior to 149.0.7827.155 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical) CVSSv3.1 9.6 (CRITICAL)

CWECWE 416TYPVulnerability
9.6
CVSS v3.1
98
Edit Score
2026-06-17
2026-06-17 13:19Z
HIGH

CVE-2026-12439 — Use: after free in Digital Credentials in Google Chrome prior to 149.0.7827.155 allowed a

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-12439

Use after free in Digital Credentials in Google Chrome prior to 149.0.7827.155 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical) CVSSv3.1 8.8 (HIGH)

CWECWE 416TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-17
2026-06-17 13:19Z
HIGH

CVE-2026-12438 — Inappropriate: implementation in WebView in Google Chrome on Android prior to 149.0.7827.155 allowed a

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-12438

Inappropriate implementation in WebView in Google Chrome on Android prior to 149.0.7827.155 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical) CVSSv3.1 8.3 (HIGH)

CWECWE 693VNDInappropriateTYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-06-17
2026-06-17 13:19Z
HIGH

CVE-2026-12437 — Use: after free in WebShare in Google Chrome on Windows prior to 149.0.7827.155 allowed

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-12437

Use after free in WebShare in Google Chrome on Windows prior to 149.0.7827.155 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical) CVSSv3.1 8.3 (HIGH)

CWECWE 416TYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-06-17
2026-06-17 13:19Z
HIGH

CVE-2026-12256 — Contributor: PHP Object Injection in Avada <= 3.15.3 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-12256

Contributor PHP Object Injection in Avada <= 3.15.3 versions. CVSSv3.1 8.8 (HIGH)

CWECWE 502VNDContributorTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-17
2026-06-17 13:19Z
HIGH

CVE-2026-12165 — Contest: The Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-12165

The Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 30.0.2 via the `RegistryUserRole` parameter. This is due to the plugin's admin menu being registered at the `edit_posts` capability level — granting Contributor-level users access to the plugin's admin pages and a valid `cg_admin` nonce — while the option-saving handler in `change-options-and-sizes.php` p CVSSv3.1 8.8 (HIGH)

CWECWE 269VNDContestTYPVulnerability
8.8
CVSS v3.1
94
Edit Score