| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| Missing authorization in Browser in Google Chrome prior to 153.0.8010.47 allowed a remote attacker who had compromised the renderer process to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium) |
| Race condition in Extensions in Google Chrome on on Mac prior to 153.0.8010.47 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High) |
| Out of bounds write in ServiceWorker in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High) |
| Use after free in WebAppInstalls in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High) |
| Type confusion in ServiceWorker in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High) |
| Race condition in Network in Google Chrome prior to 153.0.8010.47 allowed a remote attacker who had compromised the renderer process to obtain cross-origin data via a crafted HTML page. (Chromium security severity: High) |
| Contributor Cross Site Scripting (XSS) in JetBlog <= 2.4.10 versions. |
| Contributor Cross Site Scripting (XSS) in JetSearch <= 3.6.3 versions. |
| Contributor Cross Site Scripting (XSS) in JetElements For Elementor <= 2.9.2.1 versions. |
| Unauthenticated Broken Access Control in BerqWP <= 4.1.15 versions. |
| Contributor Cross Site Scripting (XSS) in Geo Mashup <= 1.13.21 versions. |
| Unauthenticated Broken Access Control in Booking Calendar <= 11.7 versions. |
| Contributor Insecure Direct Object References (IDOR) in Cooked <= 1.16.0 versions. |
| Administrator SQL Injection in PublishPress Series <= 3.1.3 versions. |
| Editor SQL Injection in SKT Addons for Elementor <= 4.0 versions. |
| Administrator SQL Injection in Newsletters <= 4.18 versions. |
| Contributor Cross Site Scripting (XSS) in PublishPress Series <= 3.1.3 versions. |
| Contributor Cross Site Scripting (XSS) in Element Pack Elementor Addons <= 8.8.3 versions. |
| Unauthenticated Remote Code Execution (RCE) in Migratico Lite <= 2.6.8 versions. |
| admin3 through 3.0.0 persists user session tokens in the audit log event body when publishing UserLoggedIn domain events. Attackers with log:view permission can read the JSON response from the GET /logs endpoint to harvest session tokens and replay them as bearer credentials for full user access. |