CVE-2021-31955 | MEDIUM | 5.5 | 0.81107 | 75.39 | Yes | No | 2021-11-03 | 2021-11-03 | cisa.gov, euvd | Microsoft Windows Kernel contains an unspecified vulnerability that allows for information disclosure. Successful exploitation allows attack…Microsoft Windows Kernel contains an unspecified vulnerability that allows for information disclosure. Successful exploitation allows attackers to read the contents of kernel memory from a user-mode process. |
CVE-2021-27852 | CRITICAL | 9.8 | 0.31946 | 75.38 | Yes | No | 2022-04-11 | 2022-04-11 | cisa.gov, euvd | Deserialization of Untrusted Data vulnerability in CheckboxWeb.dll of Checkbox Survey allows an unauthenticated remote attacker to execute a…Deserialization of Untrusted Data vulnerability in CheckboxWeb.dll of Checkbox Survey allows an unauthenticated remote attacker to execute arbitrary code. |
CVE-2025-20393 | CRITICAL | 10.0 | 0.2951 | 75.33 | Yes | No | 2025-12-17 | 2025-12-17 | cisa.gov, euvd | Cisco Secure Email Gateway, Secure Email, AsyncOS Software, and Web Manager appliances contains an improper input validation vulnerability t…Cisco Secure Email Gateway, Secure Email, AsyncOS Software, and Web Manager appliances contains an improper input validation vulnerability that allows threat actors to execute arbitrary commands with root privileges on the underlying operating system of an affected appliance. |
CVE-2015-1671 | HIGH | 7.8 | 0.54628 | 75.32 | Yes | No | 2022-05-25 | 2022-05-25 | cisa.gov, euvd | A remote code execution vulnerability exists when components of Windows, .NET Framework, Office, Lync, and Silverlight fail to properly hand…A remote code execution vulnerability exists when components of Windows, .NET Framework, Office, Lync, and Silverlight fail to properly handle TrueType fonts. |
CVE-2013-2094 | HIGH | 8.4 | 0.47709 | 75.3 | Yes | No | 2022-09-15 | 2022-09-15 | cisa.gov, euvd | Linux kernel fails to check all 64 bits of attr.config passed by user space, resulting to out-of-bounds access of the perf_swevent_enabled a…Linux kernel fails to check all 64 bits of attr.config passed by user space, resulting to out-of-bounds access of the perf_swevent_enabled array in sw_perf_event_destroy(). Explotation allows for privilege escalation. |
CVE-2009-0238 | HIGH | 8.8 | 0.43063 | 75.27 | Yes | No | 2009-02-25 | 2026-04-15 | cisa.gov, euvd | Microsoft Office Excel 2000 SP3, 2002 SP3, 2003 SP3, and 2007 SP1; Excel Viewer 2003 Gold and SP3; Excel Viewer; Compatibility Pack for Word…Microsoft Office Excel 2000 SP3, 2002 SP3, 2003 SP3, and 2007 SP1; Excel Viewer 2003 Gold and SP3; Excel Viewer; Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1; and Excel in Microsoft Office 2004 and 2008 for Mac allow remote attackers to execute arbitrary code via a crafted Excel document that triggers an access attempt on an invalid object, as exploited in the wild in February 2009 by Trojan.Mdropper.AC. |
CVE-2024-0769 | MEDIUM | 5.3 | 0.82714 | 75.15 | Yes | No | 2025-06-25 | 2025-06-25 | cisa.gov, euvd | D-Link DIR-859 routers contain a path traversal vulnerability in the file /hedwig.cgi of the component HTTP POST Request Handler. Manipulati…D-Link DIR-859 routers contain a path traversal vulnerability in the file /hedwig.cgi of the component HTTP POST Request Handler. Manipulation of the argument service with the input ../../../../htdocs/webinc/getcfg/DHCPS6.BRIDGE-1.xml allows for the leakage of session data potentially enabling privilege escalation and unauthorized control of the device. This vulnerability affects legacy D-Link products. All associated hardware revisions have reached their end-of-life (EOL) or end-of-service (EOS) life cycle and should be retired and replaced per vendor instructions. |
CVE-2017-6737 | HIGH | 8.8 | 0.42632 | 75.12 | Yes | No | 2022-03-03 | 2022-03-03 | cisa.gov, euvd | The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE contains a vulnerability that could allow an authenticated, …The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE contains a vulnerability that could allow an authenticated, remote attacker to remotely execute code. |
CVE-2026-20963 | CRITICAL | 9.8 | 0.31139 | 75.1 | Yes | No | 2026-01-13 | 2026-07-30 | cisa.gov, cnvd, euvd | Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network. |
CVE-2022-21971 | HIGH | 7.8 | 0.53934 | 75.08 | Yes | No | 2022-08-18 | 2022-08-18 | cisa.gov, euvd | Microsoft Windows Runtime contains an unspecified vulnerability that allows for remote code execution.Microsoft Windows Runtime contains an unspecified vulnerability that allows for remote code execution. |
CVE-2024-37383 | MEDIUM | 6.1 | 0.73296 | 75.05 | Yes | No | 2024-10-24 | 2024-10-24 | cisa.gov, euvd | RoundCube Webmail contains a cross-site scripting (XSS) vulnerability in the handling of SVG animate attributes that allows a remote attacke…RoundCube Webmail contains a cross-site scripting (XSS) vulnerability in the handling of SVG animate attributes that allows a remote attacker to run malicious JavaScript code. |
CVE-2007-0671 | HIGH | 8.8 | 0.42139 | 74.95 | Yes | No | 2025-08-12 | 2025-08-12 | cisa.gov, euvd | Microsoft Office Excel contains a remote code execution vulnerability that can be exploited when a specially crafted Excel file is opened. T…Microsoft Office Excel contains a remote code execution vulnerability that can be exploited when a specially crafted Excel file is opened. This malicious file could be delivered as an email attachment or hosted on a malicious website. An attacker could leverage this vulnerability by creating a specially crafted Excel file, which, when opened, allowing an attacker to execute remote code on the affected system. |
CVE-2019-9978 | MEDIUM | 6.1 | 0.72946 | 74.93 | Yes | No | 2021-11-03 | 2021-11-03 | cisa.gov, euvd | WordPress Social Warfare plugin contains a cross-site scripting (XSS) vulnerability that allows for remote code execution. This vulnerabilit…WordPress Social Warfare plugin contains a cross-site scripting (XSS) vulnerability that allows for remote code execution. This vulnerability affects Social Warfare and Social Warfare Pro. |
CVE-2023-33538 | HIGH | 8.8 | 0.41874 | 74.86 | Yes | No | 2025-06-16 | 2025-06-16 | cisa.gov, euvd | TP-Link TL-WR940N V2/V4, TL-WR841N V8/V10, and TL-WR740N V1/V2 contain a command injection vulnerability via the component /userRpm/WlanNetw…TP-Link TL-WR940N V2/V4, TL-WR841N V8/V10, and TL-WR740N V1/V2 contain a command injection vulnerability via the component /userRpm/WlanNetworkRpm. The impacted products could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization. |
CVE-2026-20131 | CRITICAL | 10.0 | 0.28158 | 74.86 | Yes | Yes | 2026-03-04 | 2026-03-25 | cisa.gov, euvd, packetstorm | A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticat…A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to execute arbitrary Java code as root on an affected device.
This vulnerability is due to insecure deserialization of a user-supplied Java byte stream. An attacker could exploit this vulnerability by sending a crafted serialized Java object to the web-based management interface of an affected device. A successful exploit could allow the attacker to execute arbitrary code on the device and elevate privileges to root.
Note: If the FMC management interface does not have public internet access, the attack surface that is associated with this vulnerability is reduced. |
CVE-2019-0808 | HIGH | 7.8 | 0.53298 | 74.85 | Yes | No | 2021-11-03 | 2021-11-03 | cisa.gov, euvd | Microsoft Win32k contains a privilege escalation vulnerability due to the component failing to properly handle objects in memory. Successful…Microsoft Win32k contains a privilege escalation vulnerability due to the component failing to properly handle objects in memory. Successful exploitation allows an attacker to run code in kernel mode. |
CVE-2021-30633 | CRITICAL | 9.6 | 0.32657 | 74.83 | Yes | Yes | 2021-11-03 | 2021-11-03 | cisa.gov, euvd, packetstorm | Google Chromium Indexed DB API contains a use-after-free vulnerability that allows a remote attacker, who has compromised the renderer proce…Google Chromium Indexed DB API contains a use-after-free vulnerability that allows a remote attacker, who has compromised the renderer process, to potentially perform a sandbox escape via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. |
CVE-2023-21674 | HIGH | 8.8 | 0.41806 | 74.83 | Yes | No | 2023-01-10 | 2023-01-10 | cisa.gov, euvd | Microsoft Windows Advanced Local Procedure Call (ALPC) contains an unspecified vulnerability that allows for privilege escalation.Microsoft Windows Advanced Local Procedure Call (ALPC) contains an unspecified vulnerability that allows for privilege escalation. |
CVE-2015-1642 | HIGH | 7.8 | 0.53213 | 74.82 | Yes | No | 2022-03-03 | 2022-03-03 | cisa.gov, euvd | Microsoft Office contains a memory corruption vulnerability that allows remote attackers to execute arbitrary code via a crafted document.Microsoft Office contains a memory corruption vulnerability that allows remote attackers to execute arbitrary code via a crafted document. |
CVE-2012-2539 | HIGH | 7.8 | 0.53159 | 74.81 | Yes | No | 2022-03-28 | 2022-03-28 | cisa.gov, euvd | Microsoft Word allows attackers to execute remote code or cause a denial-of-service (DoS) via crafted RTF data.Microsoft Word allows attackers to execute remote code or cause a denial-of-service (DoS) via crafted RTF data. |
CVE-2025-32756 | CRITICAL | 9.6 | 0.3255 | 74.79 | Yes | No | 2025-05-14 | 2025-05-14 | cisa.gov, euvd | Fortinet FortiFone, FortiVoice, FortiNDR and FortiMail contain a stack-based overflow vulnerability that may allow a remote unauthenticated …Fortinet FortiFone, FortiVoice, FortiNDR and FortiMail contain a stack-based overflow vulnerability that may allow a remote unauthenticated attacker to execute arbitrary code or commands via crafted HTTP requests. |
CVE-2017-5030 | HIGH | 8.8 | 0.41603 | 74.76 | Yes | No | 2022-06-08 | 2022-06-08 | cisa.gov, euvd | Google Chromium V8 Engine contains a memory corruption vulnerability that allows a remote attacker to execute code via a crafted HTML page. …Google Chromium V8 Engine contains a memory corruption vulnerability that allows a remote attacker to execute code via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. |
CVE-2020-1054 | HIGH | 7.8 | 0.52778 | 74.67 | Yes | No | 2021-11-03 | 2021-11-03 | cisa.gov, euvd | Microsoft Win32k contains a privilege escalation vulnerability when the Windows kernel-mode driver fails to properly handle objects in memor…Microsoft Win32k contains a privilege escalation vulnerability when the Windows kernel-mode driver fails to properly handle objects in memory. Successful exploitation allows an attacker to execute code in kernel mode. |
CVE-2021-22894 | HIGH | 8.8 | 0.41284 | 74.65 | Yes | No | 2021-11-03 | 2021-11-03 | cisa.gov, euvd | Ivanti Pulse Connect Secure Collaboration Suite contains a buffer overflow vulnerabilities that allows a remote authenticated users to execu…Ivanti Pulse Connect Secure Collaboration Suite contains a buffer overflow vulnerabilities that allows a remote authenticated users to execute code as the root user via maliciously crafted meeting room. |
CVE-2021-20028 | CRITICAL | 9.8 | 0.29866 | 74.65 | Yes | No | 2022-03-28 | 2022-03-28 | cisa.gov, euvd | SonicWall Secure Remote Access (SRA) products contain an improper neutralization of a SQL Command leading to SQL injection.SonicWall Secure Remote Access (SRA) products contain an improper neutralization of a SQL Command leading to SQL injection. |
CVE-2022-4135 | CRITICAL | 9.6 | 0.31864 | 74.55 | Yes | No | 2022-11-28 | 2022-11-28 | cisa.gov, euvd | Google Chromium GPU contains a heap buffer overflow vulnerability that allows a remote attacker, who has compromised the renderer process, t…Google Chromium GPU contains a heap buffer overflow vulnerability that allows a remote attacker, who has compromised the renderer process, to potentially perform a sandbox escape via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. |
CVE-2023-2033 | HIGH | 8.8 | 0.40798 | 74.48 | Yes | No | 2023-04-17 | 2023-04-17 | cisa.gov, euvd | Google Chromium V8 Engine contains a type confusion vulnerability that allows a remote attacker to potentially exploit heap corruption via a…Google Chromium V8 Engine contains a type confusion vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. |
CVE-2018-20753 | CRITICAL | 9.8 | 0.29336 | 74.47 | Yes | No | 2022-04-13 | 2022-04-13 | cisa.gov, euvd | Kaseya VSA RMM allows unprivileged remote attackers to execute PowerShell payloads on all managed devices.Kaseya VSA RMM allows unprivileged remote attackers to execute PowerShell payloads on all managed devices. |
CVE-2019-13272 | HIGH | 7.8 | 0.52199 | 74.47 | Yes | No | 2021-12-10 | 2021-12-10 | cisa.gov, euvd | Kernel/ptrace.c in Linux kernel mishandles contains an improper privilege management vulnerability that allows local users to obtain root ac…Kernel/ptrace.c in Linux kernel mishandles contains an improper privilege management vulnerability that allows local users to obtain root access. |
CVE-2014-0496 | HIGH | 8.8 | 0.40243 | 74.29 | Yes | No | 2022-03-03 | 2022-03-03 | cisa.gov, euvd | Adobe Reader and Acrobat contain a use-after-free vulnerability which can allow for code execution.Adobe Reader and Acrobat contain a use-after-free vulnerability which can allow for code execution. |
CVE-2023-33010 | CRITICAL | 9.8 | 0.28813 | 74.28 | Yes | No | 2023-06-05 | 2023-06-05 | cisa.gov, euvd | Zyxel ATP, USG FLEX, USG FLEX 50(W), USG20(W)-VPN, VPN, and ZyWALL/USG firewalls contain a buffer overflow vulnerability in the ID processin…Zyxel ATP, USG FLEX, USG FLEX 50(W), USG20(W)-VPN, VPN, and ZyWALL/USG firewalls contain a buffer overflow vulnerability in the ID processing function that could allow an unauthenticated attacker to cause denial-of-service (DoS) conditions and remote code execution on an affected device. |
CVE-2023-32434 | HIGH | 7.8 | 0.51517 | 74.23 | Yes | Yes | 2023-06-23 | 2023-06-23 | cisa.gov, euvd, github | Apple iOS. iPadOS, macOS, and watchOS contain an integer overflow vulnerability that could allow an application to execute code with kernel …Apple iOS. iPadOS, macOS, and watchOS contain an integer overflow vulnerability that could allow an application to execute code with kernel privileges. |
CVE-2024-11120 | CRITICAL | 9.8 | 0.28554 | 74.19 | Yes | No | 2025-05-07 | 2025-05-07 | cisa.gov, euvd | Multiple GeoVision devices contain an OS command injection vulnerability that allows a remote, unauthenticated attacker to inject and execut…Multiple GeoVision devices contain an OS command injection vulnerability that allows a remote, unauthenticated attacker to inject and execute arbitrary system commands. The impacted products could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization. |
CVE-2022-39952 | CRITICAL | 9.8 | 0.99809 | 74.13 | No | No | 2023-02-16 | 2024-10-23 | euvd | A external control of file name or path in Fortinet FortiNAC versions 9.4.0, 9.2.0 through 9.2.5, 9.1.0 through 9.1.7, 8.8.0 through 8.8.11,…A external control of file name or path in Fortinet FortiNAC versions 9.4.0, 9.2.0 through 9.2.5, 9.1.0 through 9.1.7, 8.8.0 through 8.8.11, 8.7.0 through 8.7.6, 8.6.0 through 8.6.5, 8.5.0 through 8.5.4, 8.3.7 may allow an unauthenticated attacker to execute unauthorized code or commands via specifically crafted HTTP request. |
CVE-2006-1547 | HIGH | 7.5 | 0.54635 | 74.12 | Yes | No | 2022-01-21 | 2022-01-21 | cisa.gov, euvd | ActionForm in Apache Struts versions before 1.2.9 with BeanUtils 1.7 contains a vulnerability that allows for denial-of-service (DoS).ActionForm in Apache Struts versions before 1.2.9 with BeanUtils 1.7 contains a vulnerability that allows for denial-of-service (DoS). |
CVE-2013-6282 | HIGH | 8.8 | 0.39711 | 74.1 | Yes | No | 2022-09-15 | 2022-09-15 | cisa.gov, euvd | The get_user and put_user API functions of the Linux kernel fail to validate the target address when being used on ARM v6k/v7 platforms. Thi…The get_user and put_user API functions of the Linux kernel fail to validate the target address when being used on ARM v6k/v7 platforms. This allows an application to read and write kernel memory which could lead to privilege escalation. |
CVE-2023-27372 | CRITICAL | 9.8 | 0.99637 | 74.07 | No | No | 2023-02-28 | 2025-03-11 | euvd | SPIP before 4.2.1 allows Remote Code Execution via form values in the public area because serialization is mishandled. The fixed versions ar…SPIP before 4.2.1 allows Remote Code Execution via form values in the public area because serialization is mishandled. The fixed versions are 3.2.18, 4.0.10, 4.1.8, and 4.2.1. |
CVE-2018-8373 | HIGH | 7.5 | 0.54457 | 74.06 | Yes | No | 2022-03-25 | 2022-03-25 | cisa.gov, euvd | A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer.A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer. |
CVE-2023-33009 | CRITICAL | 9.8 | 0.28144 | 74.05 | Yes | No | 2023-06-05 | 2023-06-05 | cisa.gov, euvd | Zyxel ATP, USG FLEX, USG FLEX 50(W), USG20(W)-VPN, VPN, and ZyWALL/USG firewalls contain a buffer overflow vulnerability in the notification…Zyxel ATP, USG FLEX, USG FLEX 50(W), USG20(W)-VPN, VPN, and ZyWALL/USG firewalls contain a buffer overflow vulnerability in the notification function that could allow an unauthenticated attacker to cause denial-of-service (DoS) conditions and remote code execution on an affected device. |
CVE-2025-1974 | CRITICAL | 9.8 | 0.99517 | 74.03 | No | No | 2025-03-24 | 2026-02-26 | euvd | A security issue was discovered in Kubernetes where under certain conditions, an unauthenticated attacker with access to the pod network can…A security issue was discovered in Kubernetes where under certain conditions, an unauthenticated attacker with access to the pod network can achieve arbitrary code execution in the context of the ingress-nginx controller. This can lead to disclosure of Secrets accessible to the controller. (Note that in the default installation, the controller can access all Secrets cluster-wide.) |
CVE-2010-0738 | MEDIUM | 5.3 | 0.79415 | 74.0 | Yes | No | 2022-05-25 | 2022-05-25 | cisa.gov, euvd | The JMX-Console web application in JBossAs in Red Hat JBoss Enterprise Application Platform performs access control only for the GET and POS…The JMX-Console web application in JBossAs in Red Hat JBoss Enterprise Application Platform performs access control only for the GET and POST methods, which allows remote attackers to send requests to this application's GET handler by using a different method. |
CVE-2021-26828 | HIGH | 8.8 | 0.39356 | 73.97 | Yes | No | 2025-12-03 | 2025-12-03 | cisa.gov, euvd | OpenPLC ScadaBR contains an unrestricted upload of file with dangerous type vulnerability that allows remote authenticated users to upload a…OpenPLC ScadaBR contains an unrestricted upload of file with dangerous type vulnerability that allows remote authenticated users to upload and execute arbitrary JSP files via view_edit.shtm. |
CVE-2023-23333 | CRITICAL | 9.8 | 0.99291 | 73.95 | No | No | 2023-02-06 | 2025-03-26 | euvd | There is a command injection vulnerability in SolarView Compact through 6.00, attackers can execute commands by bypassing internal restricti…There is a command injection vulnerability in SolarView Compact through 6.00, attackers can execute commands by bypassing internal restrictions through downloader.php. |
CVE-2016-3718 | MEDIUM | 5.5 | 0.76897 | 73.91 | Yes | No | 2021-11-03 | 2021-11-03 | cisa.gov, euvd | ImageMagick contains an unspecified vulnerability that allows attackers to perform server-side request forgery (SSRF) via a crafted image.ImageMagick contains an unspecified vulnerability that allows attackers to perform server-side request forgery (SSRF) via a crafted image. |
CVE-2014-0130 | HIGH | 7.5 | 0.53703 | 73.8 | Yes | No | 2022-03-25 | 2022-03-25 | cisa.gov, euvd | Directory traversal vulnerability in actionpack/lib/abstract_controller/base.rb in the implicit-render implementation in Ruby on Rails allow…Directory traversal vulnerability in actionpack/lib/abstract_controller/base.rb in the implicit-render implementation in Ruby on Rails allows remote attackers to read arbitrary files via a crafted request. |
CVE-2015-2502 | HIGH | 8.8 | 0.38705 | 73.75 | Yes | No | 2022-04-13 | 2022-04-13 | cisa.gov, euvd | Microsoft Internet Explorer contains a memory corruption vulnerability that allows an attacker to execute code or cause a denial-of-service …Microsoft Internet Explorer contains a memory corruption vulnerability that allows an attacker to execute code or cause a denial-of-service (DoS). |
CVE-2021-38003 | HIGH | 8.8 | 0.38573 | 73.7 | Yes | Yes | 2021-11-03 | 2021-11-03 | cisa.gov, euvd, packetstorm | Google Chromium V8 Engine has a bug in JSON.stringify, where the internal TheHole value can leak to script code, causing memory corruption. …Google Chromium V8 Engine has a bug in JSON.stringify, where the internal TheHole value can leak to script code, causing memory corruption. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. |
CVE-2015-2424 | HIGH | 8.8 | 0.38497 | 73.67 | Yes | No | 2022-03-03 | 2022-03-03 | cisa.gov, euvd | Microsoft PowerPoint allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted Office…Microsoft PowerPoint allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted Office document. |
CVE-2022-43781 | CRITICAL | 9.8 | 0.98076 | 73.53 | No | No | 2022-11-17 | 2024-10-02 | euvd | There is a command injection vulnerability using environment variables in Bitbucket Server and Data Center. An attacker with permission to c…There is a command injection vulnerability using environment variables in Bitbucket Server and Data Center. An attacker with permission to control their username can exploit this issue to execute arbitrary code on the system. This vulnerability can be unauthenticated if the Bitbucket Server and Data Center instance has enabled “Allow public signup”. |
CVE-2023-4762 | HIGH | 8.8 | 0.37987 | 73.5 | Yes | No | 2024-02-06 | 2024-02-06 | cisa.gov, euvd | Google Chromium V8 contains a type confusion vulnerability that allows a remote attacker to execute code via a crafted HTML page. This vulne…Google Chromium V8 contains a type confusion vulnerability that allows a remote attacker to execute code via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. |