VulnSea

CWE-706

CVEs classified under CWE-706, newest first.

23 CVEsRSS

CVE-2026-93375High· 8.1
4d ago

Incorrect reference resolution in Tracing in Google Chrome on on Windows prior to 153.0.8010.52 allowed a local attacker to potentially execute arbitrary code outside the sandbox via a local program

Incorrect reference resolution in Tracing in Google Chrome on on Windows prior to 153.0.8010.52 allowed a local attacker to potentially execute arbitrary code outside the sandbox via a local program. (Chromium security severity: High)

Twilightgoogle · chromeEPSS 0.09%via NVD
CVE-2026-92951Critical· 9.9
4d ago

vm2 before 3.11.7 contains an incorrect authorization vulnerability in the external package allowlist check that uses non-exact substring matching instead of full package-name boundary validation

vm2 before 3.11.7 contains an incorrect authorization vulnerability in the external package allowlist check that uses non-exact substring matching instead of full package-name boundary validation. Attackers can bypass the allowlist by re…

Midnightpatriksimek · vm2EPSS 0.37%via NVD
CVE-2026-91727High· 8.1
6d ago

Incorrect reference resolution in Extensions in Google Chrome on on Mac prior to 153.0.8010.47 allowed a local attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a local program

Incorrect reference resolution in Extensions in Google Chrome on on Mac prior to 153.0.8010.47 allowed a local attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a local program. (Chromium…

Twilightgoogle · chromeEPSS 0.11%via NVD
CVE-2026-87547Critical· 9.6⚖ disputed
1w ago

Incorrect reference resolution in FileSystem in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page

Incorrect reference resolution in FileSystem in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium sec…

Midnightgoogle · chromeEPSS 0.43%via NVD
CVE-2026-87613Critical· 9.0
1w ago

Incorrect reference resolution in Extensions in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via crafted network traffic

Incorrect reference resolution in Extensions in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via crafted network traffic. (Chromium security severity: Medium)

Midnightgoogle · chromeEPSS 0.35%via NVD
CVE-2026-87562Medium· 4.3
1w ago

Incorrect reference resolution in Accessibility in Google Chrome on on Mac prior to 153.0.8010.36 allowed a remote attacker to potentially spoof UI elements via a crafted HTML page

Incorrect reference resolution in Accessibility in Google Chrome on on Mac prior to 153.0.8010.36 allowed a remote attacker to potentially spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)

Sunlitgoogle · chromeEPSS 0.18%via NVD
CVE-2026-87618High· 8.3⚖ disputed
1w ago

Incorrect reference resolution in Storage in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HT…

Incorrect reference resolution in Storage in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HT…

Twilightgoogle · chromeEPSS 0.32%via NVD
CVE-2026-81383High· 7.4
1w ago

Use of incorrectly-resolved name or reference in Visual Studio Code allows an unauthorized attacker to disclose information over a network.

Use of incorrectly-resolved name or reference in Visual Studio Code allows an unauthorized attacker to disclose information over a network.

Twilightmicrosoft · visual_studio_codeEPSS 0.69%via NVD
CVE-2026-78942Medium· 4.3
3w ago

Incorrect reference resolution in Loader in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass web origin policy via crafted network traffic

Incorrect reference resolution in Loader in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass web origin policy via crafted network traffic. (Chromium security severity: Medium)

SunlitGoogle · ChromeEPSS 0.32%via CVEORG
CVE-2026-79049Medium· 4.3
3w ago

Incorrect reference resolution in Passwords in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass system access restrictions via a crafted file

Incorrect reference resolution in Passwords in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass system access restrictions via a crafted file. (Chromium security severity: Medium)

SunlitGoogle · ChromeEPSS 0.36%via CVEORG
CVE-2026-79070Medium· 4.3
3w ago

Incorrect reference resolution in Cache in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass web origin policy via a crafted HTML page

Incorrect reference resolution in Cache in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)

SunlitGoogle · ChromeEPSS 0.26%via CVEORG
CVE-2026-79264Medium· 4.3
3w ago

Incorrect reference resolution in Preload in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass web origin policy via a crafted HTML page

Incorrect reference resolution in Preload in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)

SunlitGoogle · ChromeEPSS 0.39%via CVEORG
CVE-2026-79103Low· 3.1
3w ago

Incorrect reference resolution in Speech in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page

Incorrect reference resolution in Speech in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium)

SunlitGoogle · ChromeEPSS 0.23%via CVEORG
CVE-2026-62385Medium· 5.9
1mo ago

NLTK versions before 3.10.0 contain a path traversal vulnerability in FramenetCorpusReader and NKJPCorpusReader that allows attackers to parse XML files outside the corpus root by supplying unsafe selectors or poisoned index state

NLTK versions before 3.10.0 contain a path traversal vulnerability in FramenetCorpusReader and NKJPCorpusReader that allows attackers to parse XML files outside the corpus root by supplying unsafe selectors or poisoned index state. Attac…

Sunlitnltk · nltkEPSS 0.37%via NVD
CVE-2026-65816Critical· 10.0
1mo ago

Azure Arc Elevation of Privilege Vulnerability

Use of incorrectly-resolved name or reference in Azure Arc allows an unauthorized attacker to elevate privileges over a network.

MidnightMicrosoft · Azure Web AppsEPSS 0.52%via CVEORG
CVE-2026-13097High· 8.7
1mo ago

A privilege escalation flaw was found in FreeIPA

A privilege escalation flaw was found in FreeIPA. The uniqueness constraint enforced on Kerberos principal name attributes in the 389-ds directory server does not properly account for equivalent representations of the same principal name…

Twilightfreeipa · freeipaEPSS 0.27%via NVD
CVE-2026-62685High· 8.1
2mo ago

File Browser: Colliding username normalization gives two users the same home directory

File Browser: Colliding username normalization gives two users the same home directory

Twilightfilebrowser · github.com/filebrowser/filebrowser/v2EPSS 0.55%via GHSA
CVE-2026-16120Medium· 6.3
2mo ago

A vulnerability was determined in nextlevelbuilder GoClaw up to 3.13.3-beta.3

A vulnerability was determined in nextlevelbuilder GoClaw up to 3.13.3-beta.3. This impacts the function matchesAllowlist/extractBin of the file internal/tools/exec_approval.go. Executing a manipulation can lead to incorrectly-resolved n…

SunlitEPSS 0.40%via NVD
CVE-2026-35358Medium· 4.4
2mo ago

cp: -R reads device nodes as streams, destroying device semantics

cp: -R reads device nodes as streams, destroying device semantics

Sunlituu_cp · uu_cpEPSS 0.18%via GHSA
CVE-2026-13372High· 7.2
2mo ago

Incorrect link resolution by display name in the custom PowerShell VPN editor in Devolutions Remote Desktop Manager 2026.2.5 through 2026.2.11 allows an authenticated attacker with write access to a shared workspace to execute a PowerShe…

Incorrect link resolution by display name in the custom PowerShell VPN editor in Devolutions Remote Desktop Manager 2026.2.5 through 2026.2.11 allows an authenticated attacker with write access to a shared workspace to execute a PowerShe…

TwilightEPSS 0.50%via NVD
CVE-2026-54022Medium· 5.3
3mo ago

Open WebUI: Any authenticated user can read other users' private notes via Socket.IO

Open WebUI: Any authenticated user can read other users' private notes via Socket.IO

Sunlitopen-webui · open-webuiEPSS 0.35%via GHSA
CVE-2026-54282Low· 3.7
3mo ago

Starlette: Unvalidated request path concatenated into authority poisons request.url.hostname

Starlette: Unvalidated request path concatenated into authority poisons request.url.hostname

Sunlitstarlette · starletteEPSS 0.19%via OSV
CVE-2021-24122Medium· 5.9
5y ago

When serving resources from a network location using the NTFS file system, Apache Tomcat versions 10.0.0-M1 to 10.0.0-M9, 9.0.0.M1 to 9.0.39, 8.5.0 to 8.5.59 and 7.0.0 to 7.0.106 were susceptible to JSP source code disclosure in some con…

When serving resources from a network location using the NTFS file system, Apache Tomcat versions 10.0.0-M1 to 10.0.0-M9, 9.0.0.M1 to 9.0.39, 8.5.0 to 8.5.59 and 7.0.0 to 7.0.106 were susceptible to JSP source code disclosure in some con…

Sunlitapache · tomcatEPSS 23%via NVD
CWE-706 vulnerabilities (CVEs) · VulnSea