3w ago
2026-05-29 07:16Z
HIGH

CVE-2025-11993 — WooCommerce: The WooCommerce Infinite Scroll and Ajax Pagination plugin for WordPress is vulnerable to PHP

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2025-11993

The WooCommerce Infinite Scroll and Ajax Pagination plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.8 via the 'settings' parameter in the 'import_settings' function. This is due to deserialization of untrusted data supplied via the import configuration feature without capability checks. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject a PHP Object. No POP chain is present w CVSSv3.1 8.8 (HIGH)

CWECWE 502VNDWoocommerceTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
3w ago
2026-05-29 07:00Z
HIGH

What’s in the container? Analyzing vulnerabilities, risks and protection with Kaspersky Container Security and the KIRA AI assistant

Kaspersky's analysis of 100 popular Docker Hub images reveals systemic container security failures: 64% contain critical unpatched vulnerabilities (Redis RCE, nginx DoS/RCE, sudo/glibc privesc), hardcoded credentials in layer history, passwordless sudo configurations, and world-writable directories enabling privilege escalation. Only 10% of analyzed images are fully up-to-date; the research demonstrates how supply-chain risks (Trivy/LiteLLM incidents) compound the challenge of balancing timely patching against update-driven compromise.

TACTA0004TACTA0001TACTA0003SRFCloudSWDockerVNDKasperskyTYPResearchSTGPrivesc
72
Edit Score
3w ago
2026-05-28 23:16Z
HIGH

CVE-2026-9999 — Inappropriate: implementation in ANGLE in Google Chrome on Mac prior to 148.0.7778.216 allowed a

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-9999

Inappropriate implementation in ANGLE in Google Chrome on Mac prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.8 (HIGH)

CWECWE 269VNDInappropriateTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
3w ago
2026-05-28 23:16Z
HIGH

CVE-2026-9998 — Integer: overflow in Skia in Google Chrome prior to 148.0.7778.216 allowed a remote attacker

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-9998

Integer overflow in Skia in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.3 (HIGH)

CWECWE 472TYPVulnerability
8.3
CVSS v3.1
92
Edit Score
3w ago
2026-05-28 23:16Z
HIGH

CVE-2026-9997 — Use: after free in Input in Google Chrome prior to 148.0.7778.216 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-9997

Use after free in Input in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.3 (HIGH)

CWECWE 416TYPVulnerability
8.3
CVSS v3.1
92
Edit Score
3w ago
2026-05-28 23:16Z
HIGH

CVE-2026-9995 — Use: after free in WebXR in Google Chrome prior to 148.0.7778.216 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-9995

Use after free in WebXR in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.8 (HIGH)

CWECWE 416TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
3w ago
2026-05-28 23:16Z
HIGH

CVE-2026-9994 — Use: after free in Core in Google Chrome on Windows prior to 148.0.7778.216 allowed

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-9994

Use after free in Core in Google Chrome on Windows prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.3 (HIGH)

CWECWE 416TYPVulnerability
8.3
CVSS v3.1
92
Edit Score
728 × 90 / responsive · programmatic ad slot
3w ago
2026-05-28 23:16Z
HIGH

CVE-2026-9993 — Use: after free in Views in Google Chrome prior to 148.0.7778.216 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-9993

Use after free in Views in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted PDF file. (Chromium security severity: High) CVSSv3.1 8.3 (HIGH)

CWECWE 416TYPVulnerability
8.3
CVSS v3.1
92
Edit Score
3w ago
2026-05-28 23:16Z
HIGH

CVE-2026-9992 — Use: after free in Network in Google Chrome prior to 148.0.7778.216 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-9992

Use after free in Network in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.8 (HIGH)

CWECWE 416TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
3w ago
2026-05-28 23:16Z
HIGH

CVE-2026-9988 — Use: after free in WebRTC in Google Chrome on Linux prior to 148.0.7778.216 allowed

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-9988

Use after free in WebRTC in Google Chrome on Linux prior to 148.0.7778.216 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.3 (HIGH)

CWECWE 416TYPVulnerability
8.3
CVSS v3.1
92
Edit Score
3w ago
2026-05-28 23:16Z
HIGH

CVE-2026-9984 — Use: after free in UI in Google Chrome on Windows prior to 148.0.7778.216 allowed

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-9984

Use after free in UI in Google Chrome on Windows prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.8 (HIGH)

CWECWE 416TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
3w ago
2026-05-28 23:16Z
HIGH

CVE-2026-9983 — Type: Confusion in Skia in Google Chrome prior to 148.0.7778.216 allowed a remote attacker

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-9983

Type Confusion in Skia in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.8 (HIGH)

CWECWE 843VNDTypeTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
3w ago
2026-05-28 23:16Z
HIGH

CVE-2026-9982 — Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 148.0.7778.216 allowed

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-9982

Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.3 (HIGH)

CWECWE 20TYPVulnerability
8.3
CVSS v3.1
92
Edit Score
3w ago
2026-05-28 23:16Z
HIGH

CVE-2026-9978 — Use: after free in Glic in Google Chrome prior to 148.0.7778.216 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-9978

Use after free in Glic in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.8 (HIGH)

CWECWE 416TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
3w ago
2026-05-28 23:16Z
HIGH

CVE-2026-9977 — Insufficient validation of untrusted input in WebShare in Google Chrome on Android prior to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-9977

Insufficient validation of untrusted input in WebShare in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.3 (HIGH)

CWECWE 20TYPVulnerability
8.3
CVSS v3.1
92
Edit Score
3w ago
2026-05-28 23:16Z
HIGH

CVE-2026-9976 — Inappropriate: implementation in USB in Google Chrome prior to 148.0.7778.216 allowed a remote attacker

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-9976

Inappropriate implementation in USB in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.8 (HIGH)

CWECWE 94VNDInappropriateTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
3w ago
2026-05-28 23:16Z
HIGH

CVE-2026-9975 — Out: of bounds read and write in ANGLE in Google Chrome prior to 148.0.7778.216

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-9975

Out of bounds read and write in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.3 (HIGH)

TYPVulnerability
8.3
CVSS v3.1
92
Edit Score
3w ago
2026-05-28 23:16Z
HIGH

CVE-2026-9974 — Out: of bounds write in GPU in Google Chrome prior to 148.0.7778.216 allowed a

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-9974

Out of bounds write in GPU in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.3 (HIGH)

CWECWE 787TYPVulnerability
8.3
CVSS v3.1
92
Edit Score
3w ago
2026-05-28 23:16Z
HIGH

CVE-2026-9973 — Out: of bounds write in V8 in Google Chrome prior to 148.0.7778.216 allowed a

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-9973

Out of bounds write in V8 in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.8 (HIGH)

CWECWE 787TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
3w ago
2026-05-28 23:16Z
HIGH

CVE-2026-9972 — Uninitialized: Use in Gamepad in Google Chrome on Mac prior to 148.0.7778.216 allowed a

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-9972

Uninitialized Use in Gamepad in Google Chrome on Mac prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.3 (HIGH)

CWECWE 457VNDUninitializedTYPVulnerability
8.3
CVSS v3.1
92
Edit Score
3w ago
2026-05-28 23:16Z
HIGH

CVE-2026-9970 — Use: after free in WebGL in Google Chrome prior to 148.0.7778.216 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-9970

Use after free in WebGL in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.3 (HIGH)

CWECWE 416TYPVulnerability
8.3
CVSS v3.1
92
Edit Score
3w ago
2026-05-28 23:16Z
HIGH

CVE-2026-9969 — Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 148.0.7778.216 allowed

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-9969

Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.8 (HIGH)

CWECWE 20TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
3w ago
2026-05-28 23:16Z
HIGH

CVE-2026-9968 — Integer: overflow in V8 in Google Chrome prior to 148.0.7778.216 allowed a remote attacker

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-9968

Integer overflow in V8 in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.8 (HIGH)

CWECWE 472TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
3w ago
2026-05-28 23:16Z
CRIT

CVE-2026-9967 — Out: of bounds write in GPU in Google Chrome prior to 148.0.7778.216 allowed a

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-9967

Out of bounds write in GPU in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 9.6 (CRITICAL)

CWECWE 787TYPVulnerability
9.6
CVSS v3.1
98
Edit Score
3w ago
2026-05-28 23:16Z
HIGH

CVE-2026-9966 — Integer: overflow in XML in Google Chrome on Windows prior to 148.0.7778.216 allowed a

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-9966

Integer overflow in XML in Google Chrome on Windows prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.3 (HIGH)

CWECWE 472TYPVulnerability
8.3
CVSS v3.1
92
Edit Score