2026-06-11
2026-06-11 22:16Z
HIGH

CVE-2026-12019 — Heap: buffer overflow in Codecs in Google Chrome on Linux and ChromeOS prior to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-12019

Heap buffer overflow in Codecs in Google Chrome on Linux and ChromeOS prior to 149.0.7827.115 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.3 (HIGH)

CWECWE 787VNDHeapTYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-06-11
2026-06-11 22:16Z
HIGH

CVE-2026-12018 — Inappropriate: implementation in Mojo in Google Chrome on Windows prior to 149.0.7827.115 allowed a

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-12018

Inappropriate implementation in Mojo in Google Chrome on Windows prior to 149.0.7827.115 allowed a local attacker to perform OS-level privilege escalation via a malicious file. (Chromium security severity: High) CVSSv3.1 8.8 (HIGH)

CWECWE 269VNDInappropriateTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-11
2026-06-11 22:16Z
HIGH

CVE-2026-12016 — Inappropriate: implementation in DevTools in Google Chrome prior to 149.0.7827.115 allowed a remote attacker

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-12016

Inappropriate implementation in DevTools in Google Chrome prior to 149.0.7827.115 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.3 (HIGH)

CWECWE 20VNDInappropriateTYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-06-11
2026-06-11 22:16Z
HIGH

CVE-2026-12014 — Use: after free in Cast in Google Chrome prior to 149.0.7827.115 allowed an attacker

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-12014

Use after free in Cast in Google Chrome prior to 149.0.7827.115 allowed an attacker on the local network segment to potentially perform a sandbox escape via malicious network traffic. (Chromium security severity: High) CVSSv3.1 8.3 (HIGH)

CWECWE 416TYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-06-11
2026-06-11 22:16Z
HIGH

CVE-2026-12013 — Use: after free in Media in Google Chrome on Windows prior to 149.0.7827.115 allowed

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-12013

Use after free in Media in Google Chrome on Windows prior to 149.0.7827.115 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.8 (HIGH)

CWECWE 416TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-11
2026-06-11 22:16Z
HIGH

CVE-2026-12012 — Use: after free in Network in Google Chrome prior to 149.0.7827.115 allowed an attacker

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-12012

Use after free in Network in Google Chrome prior to 149.0.7827.115 allowed an attacker in a privileged network position to potentially exploit heap corruption via malicious network traffic. (Chromium security severity: High) CVSSv3.1 8.1 (HIGH)

CWECWE 416TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-06-11
2026-06-11 22:16Z
HIGH

CVE-2026-12011 — Use: after free in WebMIDI in Google Chrome on Windows prior to 149.0.7827.115 allowed

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-12011

Use after free in WebMIDI in Google Chrome on Windows prior to 149.0.7827.115 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical) CVSSv3.1 8.3 (HIGH)

CWECWE 416TYPVulnerability
8.3
CVSS v3.1
92
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-06-11
2026-06-11 22:16Z
HIGH

CVE-2026-12010 — Heap: buffer overflow in GPU in Google Chrome on Android prior to 149.0.7827.115 allowed

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-12010

Heap buffer overflow in GPU in Google Chrome on Android prior to 149.0.7827.115 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical) CVSSv3.1 8.3 (HIGH)

CWECWE 122VNDHeapTYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-06-11
2026-06-11 22:16Z
HIGH

CVE-2026-12009 — Insufficient validation of untrusted input in Accessibility in Google Chrome on Mac prior to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-12009

Insufficient validation of untrusted input in Accessibility in Google Chrome on Mac prior to 149.0.7827.115 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical) CVSSv3.1 8.3 (HIGH)

CWECWE 20TYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-06-11
2026-06-11 22:16Z
HIGH

CVE-2026-12008 — Use: after free in DigitalCredentials in Google Chrome prior to 149.0.7827.115 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-12008

Use after free in DigitalCredentials in Google Chrome prior to 149.0.7827.115 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical) CVSSv3.1 8.3 (HIGH)

CWECWE 416TYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-06-11
2026-06-11 22:16Z
HIGH

CVE-2026-12007 — Use: after free in Core in Google Chrome on Windows prior to 149.0.7827.115 allowed

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-12007

Use after free in Core in Google Chrome on Windows prior to 149.0.7827.115 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: Critical) CVSSv3.1 8.8 (HIGH)

CWECWE 416TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-11
2026-06-11 21:16Z
HIGH

CVE-2026-53819 — OpenClaw: before 2026.5.27 contains an arbitrary code execution vulnerability in skill install flows where

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-53819

OpenClaw before 2026.5.27 contains an arbitrary code execution vulnerability in skill install flows where workspace .env files can override the Homebrew executable selection. Attackers with access to trusted operator workspaces can execute unintended Homebrew-compatible executables during skill setup to compromise the system. CVSSv3.1 8.8 (HIGH)

CWECWE 426VNDOpenclawTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-11
2026-06-11 21:16Z
HIGH

CVE-2026-53817 — OpenClaw: before 2026.5.22 contains a locality validation vulnerability in Control UI pairing that allows

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-53817

OpenClaw before 2026.5.22 contains a locality validation vulnerability in Control UI pairing that allows attackers with network access to spoof locality information and obtain durable admin-capable device tokens. Attackers can exploit insufficient locality-derived trust validation to convert temporary shared access into persistent administrative credentials that survive token rotation. CVSSv3.1 8.8 (HIGH)

CWECWE 290VNDOpenclawTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-11
2026-06-11 21:16Z
HIGH

CVE-2026-53814 — OpenClaw: before 2026.5.20 contains a privilege escalation vulnerability where hook-triggered agent runs incorrectly receive

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-53814

OpenClaw before 2026.5.20 contains a privilege escalation vulnerability where hook-triggered agent runs incorrectly receive owner-scoped MCP loopback authority instead of hook-appropriate scope. Attackers with a valid hook token can exploit the /hooks/agent endpoint to cause spawned CLI runtimes to access or invoke owner-only MCP tools, potentially executing privileged actions like persistent cron state modifications. CVSSv3.1 8.3 (HIGH)

CWECWE 266VNDOpenclawTYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-06-11
2026-06-11 21:16Z
HIGH

CVE-2026-53811 — OpenClaw: before 2026.5.7 contains a privilege escalation vulnerability in the Matrix allowFrom feature that

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-53811

OpenClaw before 2026.5.7 contains a privilege escalation vulnerability in the Matrix allowFrom feature that allows authenticated accounts to match policy entries through mutable display name metadata. Attackers with the ability to change display names can receive agent access intended for another Matrix identity, potentially gaining unauthorized permissions depending on operator configuration. CVSSv3.1 8.8 (HIGH)

CWECWE 290VNDOpenclawTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-11
2026-06-11 21:16Z
HIGH

CVE-2026-53810 — OpenClaw: before 2026.5.18 contains a code execution vulnerability where marketplace runtime extension metadata can

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-53810

OpenClaw before 2026.5.18 contains a code execution vulnerability where marketplace runtime extension metadata can redirect loading toward unscanned package payloads. Attackers with trusted operator access can manipulate extension metadata to load plugin code outside reviewed package entry points, bypassing security scanning. CVSSv3.1 8.8 (HIGH)

CWECWE 829VNDOpenclawTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-11
2026-06-11 21:16Z
HIGH

CVE-2026-53807 — OpenClaw: before 2026.5.6 contains an authorization bypass vulnerability in Telegram interactive callbacks that allows

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-53807

OpenClaw before 2026.5.6 contains an authorization bypass vulnerability in Telegram interactive callbacks that allows authenticated users to skip commands.allowFrom validation. Attackers can invoke affected callbacks to mark themselves as authorized senders before allowlist checks are applied, triggering command behavior outside configured Telegram sender restrictions. CVSSv3.1 8.8 (HIGH)

CWECWE 863VNDOpenclawTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-11
2026-06-11 21:16Z
HIGH

CVE-2026-53806 — OpenClaw: before 2026.5.12 contains a shell option parsing vulnerability that allows combined POSIX shell

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-53806

OpenClaw before 2026.5.12 contains a shell option parsing vulnerability that allows combined POSIX shell flags to bypass exec revalidation checks. Attackers can exploit this by using combined shell options to execute inline shell content without intended allowlist validation, potentially enabling unauthorized command execution when the affected feature is enabled. CVSSv3.1 8.8 (HIGH)

CWECWE 367VNDOpenclawTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-11
2026-06-11 21:16Z
CRIT

CVE-2026-41005 — Cloud: Foundry UAA incorrectly treated XML encryption to the Service Provider (confidentiality) as a

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-41005

Cloud Foundry UAA incorrectly treated XML encryption to the Service Provider (confidentiality) as a substitute for XML signatures from the Identity Provider (authenticity) in two SAML flows: the OAuth 2.0 SAML2 bearer grant (token endpoint) and browser SSO (ACS) when wantAssertionSigned is set to false. Assertions or responses that were unsigned but contained encrypted content could still be accepted. Encryption uses the SP's public key from published metadata, therefore, any CVSSv3.1 9.0 (CRITICAL)

CWECWE 347VNDCloudTYPVulnerability
9.0
CVSS v3.1
95
Edit Score
2026-06-11
2026-06-11 20:16Z
CRIT

CVE-2026-49973 — Hermes: WebUI before version 0.51.358 contains an improper access control vulnerability that allows unauthenticated

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-49973

Hermes WebUI before version 0.51.358 contains an improper access control vulnerability that allows unauthenticated remote attackers to hijack initial setup by submitting the _set_password parameter to the settings API endpoint without any network origin restriction. Attackers on any reachable network can send a POST request to the settings endpoint during the first-run setup window to persist an arbitrary password hash, obtain a valid session cookie, and lock out the legitima CVSSv3.1 9.4 (CRITICAL)

CWECWE 306VNDHermesTYPVulnerability
9.4
CVSS v3.1
97
Edit Score
2026-06-11
2026-06-11 20:16Z
HIGH

CVE-2026-46622 — SolidInvoice: Any attacker who obtains read access to the database — through SQL injection, a

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-46622

SolidInvoice is an open-source invoicing platform. Prior to version 2.3.17, API tokens used to authenticate all REST API requests are stored as plaintext strings in the api_tokens database table. Any attacker who obtains read access to the database — through SQL injection, a leaked backup, a misconfigured replica, or insider access — immediately obtains all API credentials for every user with no further effort. This issue has been patched in version 2.3.17. CVSSv3.1 8.1 (HIGH)

CWECWE 312VNDSolidinvoiceTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-06-11
2026-06-11 20:16Z
HIGH

CVE-2026-46489 — SolidInvoice: This script is base64-encoded and injected unescaped into every page of the application, causing

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-46489

SolidInvoice is an open-source invoicing platform. Prior to version 2.3.17, the company logo upload feature accepts any file type without validation. An authenticated administrator can upload an SVG file containing embedded JavaScript. This script is base64-encoded and injected unescaped into every page of the application, causing stored cross-site scripting (XSS) that executes in every authenticated user's browser. This issue has been patched in version 2.3.17. CVSSv3.1 8.1 (HIGH)

CWECWE 434CWECWE 79VNDSolidinvoiceTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-06-11
2026-06-11 19:16Z
HIGH

CVE-2026-52859 — Vim Vim: When a cell legitimately fills all VTERM_MAX_CHARS_PER_CELL (6) slots — a base character plus

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-52859

Vim is an open source, command line text editor. Prior to version 9.2.0565, the update_snapshot() function in src/terminal.c copies the visible terminal screen into the scrollback buffer when a snapshot is taken. For each screen cell it walks the cell's chars[] array with no upper bound, stopping only when it encounters a NUL terminator. When a cell legitimately fills all VTERM_MAX_CHARS_PER_CELL (6) slots — a base character plus five combining marks — the bundled libvterm re CVSSv3.1 8.2 (HIGH) · EPSS 12th percentile

CWECWE 125VNDVimTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-06-11
2026-06-11 19:16Z
HIGH

CVE-2026-47162 — Vim Vim: Prior to version 9.2.0495, a Vimscript code injection vulnerability exists in s:NetrwBookHistSave() in the

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-47162

Vim is an open source, command line text editor. Prior to version 9.2.0495, a Vimscript code injection vulnerability exists in s:NetrwBookHistSave() in the netrw plugin (runtime/pack/dist/opt/netrw/autoload/netrw.vim) when serializing browsed directory paths to the history file ~/.vim/.netrwhist. A directory name derived from the filesystem is interpolated into a single-quoted Vimscript string literal without escaping embedded single quotes, allowing a crafted directory name CVSSv3.1 8.8 (HIGH)

CWECWE 94CWECWE 74VNDVimTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-11
2026-06-11 19:16Z
HIGH

CVE-2026-46519 — Model: mcp-server-kubernetes is a Model Context Protocol server for Kubernetes cluster management.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-46519

mcp-server-kubernetes is a Model Context Protocol server for Kubernetes cluster management. Prior to version 3.6.0, mcp-server-kubernetes exposes three environment variables (ALLOW_ONLY_READONLY_TOOLS, ALLOW_ONLY_NON_DESTRUCTIVE_TOOLS, ALLOWED_TOOLS) documented as access controls for restricting which Kubernetes operations are available. These controls are enforced at the tool discovery layer (tools/list) but not at the execution layer (tools/call). Any client that knows a to CVSSv3.1 8.8 (HIGH)

CWECWE 863VNDModelTYPVulnerability
8.8
CVSS v3.1
94
Edit Score