2026-06-09
2026-06-09 05:16Z
HIGH

CVE-2026-9662 — Recover: The Recover Exit For WooCommerce plugin for WordPress is vulnerable to Local File Inclusion

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-9662

The Recover Exit For WooCommerce plugin for WordPress is vulnerable to Local File Inclusion in all versions up to and including 1.0.3. This is due to insufficient validation and sanitization of the user-controlled `tpf` POST parameter before it is used in an `include()` path in the `recover_exit()` function. This makes it possible for unauthenticated attackers to perform path traversal and include unintended local PHP files, which can lead to sensitive information exposure an CVSSv3.1 8.1 (HIGH)

CWECWE 98VNDRecoverTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-06-09
2026-06-09 05:16Z
HIGH

CVE-2026-41855 — JMS: In an untrusted JMS environment, org.springframework.jms.support.converter.MappingJackson2MessageConverter and org.springframework.jms.support.converter.JacksonJsonMessageConvert

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-41855

In an untrusted JMS environment, org.springframework.jms.support.converter.MappingJackson2MessageConverter and org.springframework.jms.support.converter.JacksonJsonMessageConverter allow arbitrary class instantiation, which can lead to unauthorized actions via gadget class deserialization. Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48. CVSSv3.1 8.1 (HIGH)

CWECWE 502VNDJmsTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-06-09
2026-06-09 01:16Z
CRIT

CVE-2026-44748 — SAP: NetWeaver Application Server ABAP and ABAP Platform allows an authenticated attacker with normal

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-44748

SAP NetWeaver Application Server ABAP and ABAP Platform allows an authenticated attacker with normal privileges to obtain a valid signed message and send modified signed XML documents to the verifier. This may result in acceptance of tampered identity information leading to unauthorized access to sensitive user data and potential disruption of normal system usage. This causes a high impact on confidentiality, integrity and availability of the application. CVSSv3.1 9.9 (CRITICAL)

CWECWE 347VNDSapTYPVulnerability
9.9
CVSS v3.1
100
Edit Score
2026-06-09
2026-06-09 01:16Z
CRIT

CVE-2026-40128 — SAP: NetWeaver Application Server Java (Web Container) allows an unauthenticated attacker to craft a

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-40128

SAP NetWeaver Application Server Java (Web Container) allows an unauthenticated attacker to craft a malicious HTTP logon request that manipulates file inclusion parameters, enabling path traversal and processing of the included file. Processing the included file could allow the attacker to view or modify sensitive information or render any part of the local system unavailable. CVSSv3.1 9.0 (CRITICAL)

CWECWE 35VNDSapTYPVulnerability
9.0
CVSS v3.1
95
Edit Score
2026-06-09
2026-06-09 01:16Z
CRIT

CVE-2026-27671 — RFC: Due to improper RFC protocol validation in the SAP Kernel used by the Application

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-27671

Due to improper RFC protocol validation in the SAP Kernel used by the Application Server ABAP of SAP NetWeaver and ABAP Platform, an unauthenticated attacker can send a crafted RFC request that exploits logical errors in memory management, leading to memory corruption. This could lead to a high impact on the confidentiality, integrity, and availability of the application. CVSSv3.1 9.8 (CRITICAL)

CWECWE 121VNDRfcTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-06-09
2026-06-09 00:16Z
HIGH

CVE-2026-11700 — Use: after free in Tracing in Google Chrome prior to 149.0.7827.103 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-11700

Use after free in Tracing in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium) CVSSv3.1 8.3 (HIGH)

CWECWE 416TYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-06-09
2026-06-09 00:16Z
HIGH

CVE-2026-11699 — Use: after free in Bluetooth in Google Chrome on Mac prior to 149.0.7827.103 allowed

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-11699

Use after free in Bluetooth in Google Chrome on Mac prior to 149.0.7827.103 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.8 (HIGH)

CWECWE 416TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-06-09
2026-06-09 00:16Z
HIGH

CVE-2026-11698 — Use: after free in Bluetooth in Google Chrome on Mac prior to 149.0.7827.103 allowed

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-11698

Use after free in Bluetooth in Google Chrome on Mac prior to 149.0.7827.103 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.8 (HIGH)

CWECWE 416TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-09
2026-06-09 00:16Z
CRIT

CVE-2026-11697 — Insufficient validation of untrusted input in UI in Google Chrome prior to 149.0.7827.103 allowed

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-11697

Insufficient validation of untrusted input in UI in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 9.6 (CRITICAL)

CWECWE 20TYPVulnerability
9.6
CVSS v3.1
98
Edit Score
2026-06-09
2026-06-09 00:16Z
HIGH

CVE-2026-11693 — Inappropriate: implementation in Plugins in Google Chrome prior to 149.0.7827.103 allowed a remote attacker

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-11693

Inappropriate implementation in Plugins in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.1 (HIGH)

CWECWE 346VNDInappropriateTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-06-09
2026-06-09 00:16Z
HIGH

CVE-2026-11692 — Use: after free in Read Anything in Google Chrome prior to 149.0.7827.103 allowed a

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-11692

Use after free in Read Anything in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.3 (HIGH)

CWECWE 416TYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-06-09
2026-06-09 00:16Z
HIGH

CVE-2026-11689 — Passwords: Insufficient policy enforcement in Passwords in Google Chrome prior to 149.0.7827.103 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-11689

Insufficient policy enforcement in Passwords in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.1 (HIGH)

CWECWE 20TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-06-09
2026-06-09 00:16Z
HIGH

CVE-2026-11688 — Inappropriate: implementation in SVG in Google Chrome prior to 149.0.7827.103 allowed a remote attacker

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-11688

Inappropriate implementation in SVG in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.8 (HIGH)

CWECWE 94VNDInappropriateTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-09
2026-06-09 00:16Z
HIGH

CVE-2026-11687 — Use: after free in Dawn in Google Chrome on Mac prior to 149.0.7827.103 allowed

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-11687

Use after free in Dawn in Google Chrome on Mac prior to 149.0.7827.103 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.8 (HIGH)

CWECWE 416TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-09
2026-06-09 00:16Z
HIGH

CVE-2026-11683 — Use: after free in WebCodecs in Google Chrome prior to 149.0.7827.103 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-11683

Use after free in WebCodecs in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.8 (HIGH)

CWECWE 416TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-09
2026-06-09 00:16Z
HIGH

CVE-2026-11682 — Inappropriate: implementation in Views in Google Chrome on Linux prior to 149.0.7827.103 allowed a

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-11682

Inappropriate implementation in Views in Google Chrome on Linux prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.3 (HIGH)

CWECWE 20VNDInappropriateTYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-06-09
2026-06-09 00:16Z
HIGH

CVE-2026-11681 — Use: after free in Ozone in Google Chrome on Linux prior to 149.0.7827.103 allowed

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-11681

Use after free in Ozone in Google Chrome on Linux prior to 149.0.7827.103 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.8 (HIGH)

CWECWE 416TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-09
2026-06-09 00:16Z
HIGH

CVE-2026-11680 — Use: after free in Media in Google Chrome on Windows prior to 149.0.7827.103 allowed

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-11680

Use after free in Media in Google Chrome on Windows prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.8 (HIGH)

CWECWE 416TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-09
2026-06-09 00:16Z
HIGH

CVE-2026-11679 — Use: after free in Codecs in Google Chrome on Windows prior to 149.0.7827.103 allowed

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-11679

Use after free in Codecs in Google Chrome on Windows prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.3 (HIGH)

CWECWE 416TYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-06-09
2026-06-09 00:16Z
HIGH

CVE-2026-11677 — Race: in Network in Google Chrome on Mac prior to 149.0.7827.103 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-11677

Race in Network in Google Chrome on Mac prior to 149.0.7827.103 allowed a remote attacker who had compromised the network process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.3 (HIGH)

CWECWE 362VNDRaceTYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-06-09
2026-06-09 00:16Z
HIGH

CVE-2026-11676 — Insufficient validation of untrusted input in Dawn in Google Chrome on Linux and ChromeOS

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-11676

Insufficient validation of untrusted input in Dawn in Google Chrome on Linux and ChromeOS prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.3 (HIGH)

CWECWE 20TYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-06-09
2026-06-09 00:16Z
HIGH

CVE-2026-11674 — Use: after free in Guest View in Google Chrome prior to 149.0.7827.103 allowed a

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-11674

Use after free in Guest View in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.8 (HIGH)

CWECWE 416TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-09
2026-06-09 00:16Z
HIGH

CVE-2026-11673 — Use: after free in InterestGroups in Google Chrome prior to 149.0.7827.103 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-11673

Use after free in InterestGroups in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.8 (HIGH)

CWECWE 416TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-09
2026-06-09 00:16Z
HIGH

CVE-2026-11672 — Heap: buffer overflow in GPU in Google Chrome on Android prior to 149.0.7827.103 allowed

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-11672

Heap buffer overflow in GPU in Google Chrome on Android prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.3 (HIGH)

CWECWE 787VNDHeapTYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-06-09
2026-06-09 00:16Z
CRIT

CVE-2026-11671 — Use: after free in Navigation in Google Chrome prior to 149.0.7827.103 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-11671

Use after free in Navigation in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 9.6 (CRITICAL)

CWECWE 416TYPVulnerability
9.6
CVSS v3.1
98
Edit Score