Use after free in PictureInPicture in Google Chrome prior to 154.0.8037.92 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
Shenlong is analyzing...
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-102242 | 8.6 HIGH | Path Traversal via Symlink Following in allowedLocalRoots in MCP Toolbox for Databases |
| CVE-2026-102252 | 6.9 MEDIUM | Path Traversal in VMDK Extractor in OSV-SCALIBR |
| CVE-2026-95345 | CVE-2026-95345 | |
| CVE-2026-95299 | CVE-2026-95299 | |
| CVE-2026-95366 | Chrome 154前核心释放后重用致跨域 | |
| CVE-2026-95351 | Chrome 154.0.8037.57 Views 释放后使用漏洞 | |
| CVE-2026-95331 | Chrome 154前ANGLE越界写漏洞 | |
| CVE-2026-95381 | Chrome 154.0.8037.57 前沙盒逃逸漏洞 | |
| CVE-2026-95382 | Chrome 154.0.8037.57前Auth输入验证漏洞 | |
| CVE-2026-95297 | Chrome 154.0.8037.57 上下文任务缺失授权漏洞 | |
| CVE-2026-95362 | CVE-2026-95362 | |
| CVE-2026-95302 | Chrome Android 154.0.8037.57 授权错误 | |
| CVE-2026-95369 | Chrome 154 XML漏洞致沙箱内代码执行 | |
| CVE-2026-95375 | Chrome 154.0.8037.57前BrowserTag授权错误 | |
| CVE-2026-95294 | CVE-2026-95294 | |
| CVE-2026-95376 | Chrome 154前 DevTools外部引用漏洞 | |
| CVE-2026-95359 | Chrome Android 154.0.8037.57 GPU未初始化资源漏洞 | |
| CVE-2026-95337 | Chrome Android 154.0.8037.57前UI伪造漏洞 | |
| CVE-2026-95330 | CVE-2026-95330 | |
| CVE-2026-95371 | Chrome Mac 154前视图UI欺骗漏洞 |
Showing top 20 of 142 CVEs. View all on vendor page → →
No comments yet