CVE tracker
367 subscribers
5.03K links
News monitoring: @irnewsagency

Main channel: @orgsecuritygate

Site: SecurityGate.org
Download Telegram
CVE-2026-17746 - Use after free in GPU in Google Chrome on Mac prio

CVE ID :CVE-2026-17746
Published : July 30, 2026, 12:19 a.m. | 42 minutes ago
Description :Use after free in GPU in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-17747 - Insufficient validation of untrusted input in Paym

CVE ID :CVE-2026-17747
Published : July 30, 2026, 12:19 a.m. | 42 minutes ago
Description :Insufficient validation of untrusted input in Payments in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-17748 - Inappropriate implementation in Extensions in Goog

CVE ID :CVE-2026-17748
Published : July 30, 2026, 12:19 a.m. | 42 minutes ago
Description :Inappropriate implementation in Extensions in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium)
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-17749 - Insufficient validation of untrusted input in Exte

CVE ID :CVE-2026-17749
Published : July 30, 2026, 12:19 a.m. | 42 minutes ago
Description :Insufficient validation of untrusted input in Extensions in Google Chrome prior to 151.0.7922.72 allowed an attacker who convinced a user to install a malicious extension to potentially perform a sandbox escape via a crafted Chrome Extension. (Chromium security severity: Medium)
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-17750 - Use after free in ANGLE in Google Chrome prior to

CVE ID :CVE-2026-17750
Published : July 30, 2026, 12:19 a.m. | 42 minutes ago
Description :Use after free in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-17751 - Inappropriate implementation in AdFilter in Google

CVE ID :CVE-2026-17751
Published : July 30, 2026, 12:19 a.m. | 42 minutes ago
Description :Inappropriate implementation in AdFilter in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-17752 - Use after free in Views in Google Chrome on Mac pr

CVE ID :CVE-2026-17752
Published : July 30, 2026, 12:19 a.m. | 42 minutes ago
Description :Use after free in Views in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-17753 - Inappropriate implementation in Autofill in Google

CVE ID :CVE-2026-17753
Published : July 30, 2026, 12:19 a.m. | 42 minutes ago
Description :Inappropriate implementation in Autofill in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-18013 - Google Chrome for iOS UI Spoofing Vulnerability

CVE ID :CVE-2026-18013
Published : July 30, 2026, 1:17 a.m. | 3 hours, 45 minutes ago
Description :Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-18014 - Google Chrome DevTools Navigation Restriction Bypass

CVE ID :CVE-2026-18014
Published : July 30, 2026, 1:17 a.m. | 3 hours, 45 minutes ago
Description :Insufficient validation of untrusted input in DevTools in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to bypass navigation restrictions via a malicious file. (Chromium security severity: Low)
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-18015 - Google Chrome Tint Sandbox Escape Vulnerability

CVE ID :CVE-2026-18015
Published : July 30, 2026, 1:17 a.m. | 3 hours, 45 minutes ago
Description :Inappropriate implementation in Tint in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low)
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-18016 - Google Chrome for iOS UI Spoofing Vulnerability

CVE ID :CVE-2026-18016
Published : July 30, 2026, 1:17 a.m. | 3 hours, 45 minutes ago
Description :Insufficient policy enforcement in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-18017 - Google Chrome Dawn Use-After-Free Vulnerability

CVE ID :CVE-2026-18017
Published : July 30, 2026, 1:17 a.m. | 3 hours, 45 minutes ago
Description :Use after free in Dawn in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Low)
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-18018 - Google Chrome Updater UI Spoofing Vulnerability

CVE ID :CVE-2026-18018
Published : July 30, 2026, 1:17 a.m. | 3 hours, 45 minutes ago
Description :Inappropriate implementation in Updater in Google Chrome on Windows prior to 151.0.7922.72 allowed a local attacker to perform UI spoofing via a malicious file. (Chromium security severity: Low)
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-18019 - Google Chrome Media Side-Channel Information Leakage

CVE ID :CVE-2026-18019
Published : July 30, 2026, 1:17 a.m. | 3 hours, 45 minutes ago
Description :Side-channel information leakage in Media in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-59952 - Valibot: record() issue paths can make flatten() throw for inherited Object property names

CVE ID :CVE-2026-59952
Published : July 30, 2026, 1:17 a.m. | 3 hours, 45 minutes ago
Description :Valibot helps validate data using a schema. Versions prior to 1.4.2 can throw a TypeError inside its flatten() helper when validation issues contain attacker-controlled object keys such as toString, valueOf, or hasOwnProperty. The issue is reachable through normal record() validation. record() intentionally filters __proto__, prototype, and constructor, but it still accepts other own keys that collide with inherited Object.prototype properties. If the record key schema or value schema rejects such an entry, Valibot creates an issue path containing that key. Passing the resulting issues to Valibot's documented flatten() helper causes flatErrors.nested[dotPath] to resolve to the inherited method instead of an own error array, and the helper calls .push(...) on that function. This is not a global prototype pollution issue. The impact is availability/error handling: applications that validate user-controlled objects with record() and flatten validation errors for API responses can crash the request path with a TypeError instead of returning structured validation errors. This issue has been fixed in version 1.4.2.
Severity: 6.9 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-15929 - LG Electronics SmartShare SQL Injection Vulnerability

CVE ID :CVE-2026-15929
Published : July 30, 2026, 2:16 a.m. | 2 hours, 45 minutes ago
Description :Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in LG Electronics SmartShare allows SQL Injection. This issue affects SmartShare: through 2.3.1712.1202, which is supported on Microsoft Windows 10 and earlier versions.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-16727 - ASUS Armoury Crate Race Condition Privilege Escalation

CVE ID :CVE-2026-16727
Published : July 30, 2026, 2:16 a.m. | 2 hours, 45 minutes ago
Description :Concurrent Execution using Shared Resource with Improper Synchronization (“Race Condition”) in ASUS Armoury Crate allows a local user to execute arbitrary code with elevated privileges via a crafted file replacement. Refer to the ' Security Update for ASUS Armoury Crate ' section on the ASUS Security Advisory for more information.
Severity: 7.3 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-16092 - Improved Save Button <= 1.2.1 - Authenticated (Author+) Second-Order SQL Injection via 'meta_key' Parameter

CVE ID :CVE-2026-16092
Published : July 30, 2026, 3:16 a.m. | 1 hour, 46 minutes ago
Description :The Improved Save Button plugin for WordPress is vulnerable to second-order SQL Injection via 'meta_key' Custom Field via 'Save and Duplicate' Action in all versions up to, and including, 1.2.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with author-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-18186 - A stored format string vulnerability was found in the FTP Backup on the ADM

CVE ID :CVE-2026-18186
Published : July 30, 2026, 3:16 a.m. | 1 hour, 46 minutes ago
Description :A stored format string vulnerability was found in the FTP Backup on the ADM. The vulnerability occurs because user-controlled backup configuration data may be written into a task log and later processed through an unsafe format string operation. An authenticated attacker can exploit this issue to disclose memory information or cause denial of service of the affected CGI process. Affected products and versions include: from ADM 4.1.0 through ADM 4.3.3.RUN1 as well as from ADM 5.0.0 through ADM 5.1.3.RI81.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-18187 - A format string vulnerability was found in the Internal Backup on the ADM

CVE ID :CVE-2026-18187
Published : July 30, 2026, 3:16 a.m. | 1 hour, 46 minutes ago
Description :A format string vulnerability was found in the Internal Backup on the ADM. The vulnerability occurs because user-controlled task input may be included in an error response and processed through an unsafe format string operation. An authenticated attacker can exploit this issue to disclose memory information or cause denial of service of the affected CGI process. Affected products and versions include: from ADM 4.1.0 through ADM 4.3.3.RUN1 as well as from ADM 5.0.0 through ADM 5.1.3.RI81.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...