CVE Severity Distribution (Last 30 Days)
Found 11 CVEs in the last 30 days.
CVE-2026-10013
HIGH
CVSS: 8.8
EPSS: 0.3%
CWE-416
T1203
Use after free in WebCodecs in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
Published: 2026-05-28
CVE-2026-10015
HIGH
CVSS: 8.8
EPSS: 0.3%
CWE-472
Integer overflow in WTF in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
Published: 2026-05-28
CVE-2026-10016
HIGH
CVSS: 8.8
EPSS: 0.3%
CWE-416
T1203
Use after free in DOM in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
Published: 2026-05-28
CVE-2026-10019
HIGH
CVSS: 8.8
EPSS: 0.2%
CWE-472
Integer overflow in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-05-28
CVE-2026-10012
HIGH
CVSS: 8.3
EPSS: 0.2%
CWE-416
T1203
Use after free in Skia in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
Published: 2026-05-28
CVE-2026-10014
HIGH
CVSS: 8.3
EPSS: 0.2%
CWE-416
T1203
Use after free in WebMIDI in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
Published: 2026-05-28
CVE-2026-10017
HIGH
CVSS: 8.3
EPSS: 0.2%
CWE-125
T1005
Out of bounds read in Headless in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-05-28
CVE-2026-10018
MEDIUM
CVSS: 6.5
EPSS: 0.2%
CWE-472
Integer overflow in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-05-28
CVE-2026-10010
MEDIUM
CVSS: 5.0
EPSS: 0.1%
CWE-346
Inappropriate implementation in Input in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: High)
Published: 2026-05-28
CVE-2026-1001
MEDIUM
CVSS: 4.8
EPSS: 0.2%
CWE-79
T1189
Domoticz versions prior to 2026.1 contain a stored cross-site scripting vulnerability in the Add Hardware and rename device functionality of the web interface that allows authenticated administrators to execute arbitrary scripts by supplying crafted names containing script or HTML markup. Attackers can inject malicious code that is stored and rendered without proper output encoding, causing script execution in the browsers of users viewing the affected page and enabling unauthorized actions within their session context.
Published: 2026-03-25
CVE-2026-10011
LOW
CVSS: 3.1
EPSS: 0.2%
CWE-200
T1005
T1083
Inappropriate implementation in Skia in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)
Published: 2026-05-28