Common Vulnerabilities and Exposures (CVE)

CVE-2026-19148

Aug 8, 2026 03:55:20 UTC

Out of bounds write in GPU in Google Chrome on Linux prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Hi...

CVE-2026-19143

Aug 8, 2026 03:55:19 UTC

Insufficient validation of untrusted input in WebAPKs in Google Chrome on Android prior to 151.0.7922.109 allowed a local attacker to potentially perform a sandbox escape via a malicious file. (Chromium security severity: High)

CVE-2026-19141

Aug 8, 2026 03:55:18 UTC

Use after free in Resources in Google Chrome on Android prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity:...

CVE-2026-56162

Aug 8, 2026 03:55:17 UTC

Improper authentication in Azure SQL Database allows an unauthorized attacker to elevate privileges over a network.

CVE-2026-62873

Aug 8, 2026 03:55:16 UTC

Improper verification of cryptographic signature in Microsoft 365 Admin Center allows an unauthorized attacker to elevate privileges over a network.

CVE-2026-8037

Aug 8, 2026 03:55:14 UTC

OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an un-authenticated attacker to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in multiple command endpo...

CVE-2025-6946

Aug 8, 2026 03:25:30 UTC

A stored cross-site scripting (XSS) vulnerability exists in the management interface of WatchGuard Firebox appliances via the IPS configuration. An authenticated remote attacker with administrator privileges could exploit this vulnerability...

CVE-2026-71851

Aug 8, 2026 03:05:53 UTC

crypto-js is a JavaScript library of crypto standards. Versions of crypto-js prior to 4.0.0 generate randomness in CryptoJS.lib.WordArray.random() using a custom variation of the Multiply-With-Carry pseudorandom number generator, seeded fro...

CVE-2026-71848

Aug 8, 2026 03:04:43 UTC

Hono is a Web application framework that provides support for any JavaScript runtime. From 4.12.0 to 4.12.33, the languageDetector middleware is vulnerable to algorithmic complexity denial of service when processing a crafted language tag c...

CVE-2026-56818

Aug 8, 2026 03:01:06 UTC

Netty is an asynchronous, event-driven network application framework. Prior to 4.1.136.Final and 4.2.16.Final, the RedisArrayAggregator Redis codec clears retained partial aggregate state when the maxNestedArrayDepth limit is exceeded, but ...

CVE-2026-19212

Aug 8, 2026 02:58:54 UTC

A vulnerability was determined in WonderTrader up to 0.9.9. This impacts an unknown function of the file src/Includes/WTSTradeDef.hpp of the component TraderATP Cash Trade Conversion. Executing a manipulation of the argument m_offsetType ca...

CVE-2026-68772

Aug 8, 2026 02:56:13 UTC

ZenML 0.94.6 contains a remote code execution vulnerability in the CloudpickleMaterializer component that allows attackers with write access to a shared artifact store to execute arbitrary code by planting a malicious pickle file. Attackers...

CVE-2026-66059

Aug 8, 2026 02:54:58 UTC

Frappe is a full-stack web application framework. Prior to 16.20.0 and 15.112.0, a field-level permissions bypass exposes restricted DocType fields. This issue is fixed in versions 16.23.0 and 15.112.0.

CVE-2026-19207

Aug 8, 2026 02:52:52 UTC

A security vulnerability has been detected in PHPGurukul Company Visitor Management System 1.0. This issue affects some unknown processing of the file /manage-newvisitors.php. The manipulation of the argument fullname leads to cross site sc...

CVE-2026-11907

Aug 8, 2026 02:51:50 UTC

The Stream plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.2.0. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for a...