🕵️ RESEARCH & DEEP DIVES
- Multiple high-severity use-after-free and out-of-bounds write flaws in Google Chrome before 150.0.7871.186 — cve.threatint.com
Google Chrome versions prior to 150.0.7871.186 contain multiple high-severity memory corruption vulnerabilities exploitable via crafted HTML pages.- Affects Google Chrome versions prior to 150.0.7871.186
- Includes use-after-free vulnerabilities in Input, Blink, and WebMCP components
- Includes an out-of-bounds write vulnerability in Codecs component
- Remote attackers can exploit these flaws via crafted HTML pages to execute arbitrary code or escape sandbox
- All vulnerabilities have high Chromium security severity ratings
🔓 CVEs & KEV
-
CVE-2026-42933 — CVSS 10.0 — Unintended Proxy or Intermediary in Panduit IntraVUE
A critical vulnerability in Panduit IntraVUE allows unintended proxy or intermediary behavior, posing significant security risks. -
CVE-2026-28698 — CVSS 8.6 — Exposure of Sensitive System Information
Exposure of sensitive system information to unauthorized control spheres. -
CVE-2026-40430 — CVSS 7.5 — Plaintext Storage of a Password in Panduit IntraVUE
Panduit IntraVUE stores passwords in plaintext, risking credential compromise. -
CVE-2026-16765 — CVSS 7.3 — SQL Injection in CodeAstro Online Classroom
SQL injection vulnerability in loginlinkadmin.php of CodeAstro Online Classroom. -
CVE-2026-50044 — CVSS 6.8 — Inadequate Encryption Strength in Panduit IntraVUE
Weak encryption implementation in Panduit IntraVUE. -
CVE-2026-16767 — CVSS 6.5 — Path Traversal in Ne-Lexa php-zip ZipFile.php
Path traversal vulnerability in php-zip extractTo function. -
CVE-2026-44955 — CVSS 5.3 — Exposure of Sensitive System Information
Exposure of sensitive system information to unauthorized control spheres.