CVE Notify
19.6K subscribers
4 photos
313K links
Alert on the latest CVEs

Partner channel: @malwr
Download Telegram
🚨 CVE-2026-19142
Use after free in Views in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

🎖@cveNotify
🚨 CVE-2026-19144
Use after free in HTML in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

🎖@cveNotify
🚨 CVE-2026-19147
Use after free in Aura in Google Chrome on Linux prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

🎖@cveNotify
🚨 CVE-2026-57105
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

🎖@cveNotify
🚨 CVE-2026-58639
Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

🎖@cveNotify
🚨 CVE-2026-62827
Improper authentication in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.

🎖@cveNotify
🚨 CVE-2026-62829
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

🎖@cveNotify
🚨 CVE-2026-62837
Relative path traversal in Microsoft Office SharePoint allows an authorized attacker to disclose information over a network.

🎖@cveNotify
🚨 CVE-2026-62839
Insufficiently protected credentials in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

🎖@cveNotify
🚨 CVE-2026-62917
Improper input validation in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

🎖@cveNotify
🚨 CVE-2026-63512
Incorrect authorization in Microsoft Office SharePoint allows an authorized attacker to perform tampering over a network.

🎖@cveNotify
🚨 CVE-2026-63514
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

🎖@cveNotify
🚨 CVE-2026-63516
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

🎖@cveNotify
🚨 CVE-2026-64897
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

🎖@cveNotify
🚨 CVE-2026-64900
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

🎖@cveNotify
🚨 CVE-2026-64901
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

🎖@cveNotify
🚨 CVE-2026-64902
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

🎖@cveNotify
🚨 CVE-2024-11831
A flaw was found in npm-serialize-javascript. The vulnerability occurs because the serialize-javascript module does not properly sanitize certain inputs, such as regex or other JavaScript object types, allowing an attacker to inject malicious code. This code could be executed when deserialized by a web browser, causing Cross-site scripting (XSS) attacks. This issue is critical in environments where serialized data is sent to web clients, potentially compromising the security of the website or web application using this package.

🎖@cveNotify
🚨 CVE-2026-12001
A hardcoded credential
vulnerability exists in the firmware of multiple TP-Link routers (TL-WR845N v4, TL-WR850N v3, TL-WR902AC v4, Archer C20 v6 & Archer MR200 v5).  Authentication-related credential material is
embedded within a password file in the firmware image and may be recovered
through firmware analysis.





Successful
exploitation could result in unauthorized access to privileged functions on
affected devices.

🎖@cveNotify
🚨 CVE-2026-18649
A flaw was found in the GStreamer gst-plugins-good package. The rtph264depay and rtph265depay RTP depayloader elements do not enforce a maximum size limit on the reassembly buffer used during fragmented RTP packet processing. A remote, unauthenticated attacker can send a continuous stream of RTP fragments without ever transmitting an end-of-fragment marker, causing the reassembly buffer to grow without bound until process memory is exhausted. This results in a denial of service through process termination.

🎖@cveNotify
🚨 CVE-2026-17435
File::Rotate::Simple versions before 0.4.0 for Perl create the target of dangling symlinks when rotating files.

When the file to be rotated is a symbolic link to a missing file, and the touch option is enabled, then the rotate method assumes that the file is absent (since the existence check is against the target), and does not rotate it. But it touches the file, which creates the target.

An attacker that has the ability to create the symlink can use this to create an arbitrary file with permissions of the process rotating the files (which may be different from the process that normally writes to the log file that is being rotated).

Note that the touch option is disabled by default.

🎖@cveNotify