Aggregator
CVE-2026-8539 | Google Chrome up to 148.0.7778.96 on Android SanitizerAPI code injection (ID 496524 / Nessus ID 315114)
1 month ago
A vulnerability identified as critical has been detected in Google Chrome on Android. This vulnerability affects unknown code of the component SanitizerAPI. The manipulation leads to code injection.
This vulnerability is uniquely identified as CVE-2026-8539. The attack is possible to be carried out remotely. No exploit exists.
You should upgrade the affected component.
vuldb.com
CVE-2026-8535 | Google Chrome up to 148.0.7778.96 on Linux Media out-of-bounds (ID 495530 / Nessus ID 315114)
1 month ago
A vulnerability labeled as problematic has been found in Google Chrome on Linux. This issue affects some unknown processing of the component Media. The manipulation results in out-of-bounds read.
This vulnerability was named CVE-2026-8535. The attack may be performed from remote. There is no available exploit.
The affected component should be upgraded.
vuldb.com
CVE-2026-8537 | Google Chrome up to 148.0.7778.96 ViewTransitions cross-domain policy (ID 495890 / Nessus ID 315114)
1 month ago
A vulnerability marked as critical has been reported in Google Chrome. Impacted is an unknown function of the component ViewTransitions. This manipulation causes permissive cross-domain policy with untrusted domains.
The identification of this vulnerability is CVE-2026-8537. It is possible to initiate the attack remotely. There is no exploit available.
It is suggested to upgrade the affected component.
vuldb.com
CVE-2026-8536 | Google Chrome up to 148.0.7778.96 on macOS ReadingMode information disclosure (ID 495857 / Nessus ID 315114)
1 month ago
A vulnerability labeled as problematic has been found in Google Chrome on macOS. The impacted element is an unknown function of the component ReadingMode. Such manipulation leads to information disclosure.
This vulnerability is uniquely identified as CVE-2026-8536. The attack can be launched remotely. No exploit exists.
The affected component should be upgraded.
vuldb.com
CVE-2026-8538 | Google Chrome up to 148.0.7778.96 GPU denial of service (ID 496415 / Nessus ID 315114)
1 month ago
A vulnerability marked as problematic has been reported in Google Chrome. This affects an unknown function of the component GPU. Performing a manipulation results in denial of service.
This vulnerability was named CVE-2026-8538. The attack may be initiated remotely. There is no available exploit.
It is suggested to upgrade the affected component.
vuldb.com
CVE-2026-8532 | Google Chrome up to 148.0.7778.96 XML external control of assumed-immutable web parameter (ID 492812 / Nessus ID 315114)
1 month ago
A vulnerability categorized as critical has been discovered in Google Chrome. Impacted is an unknown function of the component XML. The manipulation results in external control of assumed-immutable web parameter.
This vulnerability is known as CVE-2026-8532. It is possible to launch the attack remotely. No exploit is available.
It is advisable to upgrade the affected component.
vuldb.com
CVE-2026-8533 | Google Chrome up to 148.0.7778.96 Accessibility use after free (ID 495247 / Nessus ID 315114)
1 month ago
A vulnerability identified as critical has been detected in Google Chrome. The affected element is an unknown function of the component Accessibility. This manipulation causes use after free.
This vulnerability is handled as CVE-2026-8533. The attack can be initiated remotely. There is not any exploit available.
You should upgrade the affected component.
vuldb.com
Exploit available for new DirtyDecrypt Linux root escalation flaw
1 month ago
A recently patched local privilege escalation vulnerability in the Linux kernel's rxgk modul
NCSC Calls for Tight Security and Human Oversight as Agentic AI Use Expands
1 month ago
The UK’s National Cyber Security Centre (NCSC) has warned organizations to take a measured
Нашли критическую уязвимость в Linux? Почитайте гневное послание Линуса Торвальдса любителям легких отчетов
1 month ago
Торвальдс признал пользу новых инструментов, но назвал поток повторяющихся сообщений бессмысленной нагрузкой.
谷歌更新垃圾内容政策打击“AI投毒”行为
1 month ago
谷歌更新了其垃圾信息政策,将试图在搜索结果中 “操纵” 其人工智能模型的行为标记为垃圾信息,包括在AI概览或搜索中的 AI模式中的结果。一些用户一直试图影响人工智能搜索的响应,使用诸如带有偏见的 “最
Exploit available for new DirtyDecrypt Linux root escalation flaw
1 month ago
A recently patched local privilege escalation vulnerability in the Linux kernel's rxgk module now has a proof-of-concept exploit that allows attackers to gain root access on some Linux systems. [...]
Sergiu Gatlan
Critical Pre-Auth Flaw CVE-2026-44338 Exploited to Hijack Autonomous AI Agents
1 month ago
Adversaries initiated a targeted reconnaissance campaign against vulnerable PraisonAI nodes less than four hours following the public disclosure
The post Critical Pre-Auth Flaw CVE-2026-44338 Exploited to Hijack Autonomous AI Agents appeared first on Penetration Testing Tools.
ddos
CVE-2026-8515 | Google Chrome up to 148.0.7778.96 HID use after free (ID 495999 / Nessus ID 314874)
1 month ago
A vulnerability categorized as critical has been discovered in Google Chrome. This issue affects some unknown processing of the component HID. Executing a manipulation can lead to use after free.
The identification of this vulnerability is CVE-2026-8515. The attack may be launched remotely. There is no exploit available.
It is advisable to upgrade the affected component.
vuldb.com
CVE-2026-8516 | Google Chrome up to 148.0.7778.96 DataTransfer information disclosure (ID 496393 / Nessus ID 314881)
1 month ago
A vulnerability described as problematic has been identified in Google Chrome. This affects an unknown function of the component DataTransfer. Such manipulation leads to information disclosure.
This vulnerability is listed as CVE-2026-8516. The attack may be performed from remote. There is no available exploit.
Upgrading the affected component is recommended.
vuldb.com
CVE-2026-8513 | Google Chrome up to 148.0.7778.96 on Android Input use after free (ID 495939 / Nessus ID 314885)
1 month ago
A vulnerability, which was classified as critical, was found in Google Chrome on Android. This impacts an unknown function of the component Input. Executing a manipulation can lead to use after free.
This vulnerability appears as CVE-2026-8513. The attack may be performed from remote. There is no available exploit.
You should upgrade the affected component.
vuldb.com
CVE-2026-8512 | Google Chrome up to 148.0.7778.96 Fileystem use after free (ID 495782 / Nessus ID 314979)
1 month ago
A vulnerability was found in Google Chrome. It has been declared as critical. This affects an unknown part of the component Fileystem. Such manipulation leads to use after free.
This vulnerability is uniquely identified as CVE-2026-8512. The attack can be launched remotely. No exploit exists.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2026-8514 | Google Chrome up to 148.0.7778.96 Aura use after free (ID 495948 / Nessus ID 314979)
1 month ago
A vulnerability was found in Google Chrome. It has been rated as critical. This vulnerability affects unknown code of the component Aura. Performing a manipulation results in use after free.
This vulnerability was named CVE-2026-8514. The attack may be initiated remotely. There is no available exploit.
Upgrading the affected component is advised.
vuldb.com
CVE-2026-45351 | open-webui Open WebUI up to 0.8.8 Web Request information disclosure (GHSA-jh9g-8jqw-m2qx / WID-SEC-2026-1542)
1 month ago
A vulnerability has been found in open-webui Open WebUI up to 0.8.8 and classified as problematic. Affected is an unknown function of the component Web Request Handler. This manipulation causes information disclosure.
This vulnerability is tracked as CVE-2026-45351. The attack is possible to be carried out remotely. No exploit exists.
The affected component should be upgraded.
vuldb.com