5.4
CVE-2026-2322 - chromium-browser: Inappropriate implementation in File input
Inappropriate implementation in File input in Google Chrome prior to 145.0.7632.45 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)
4.3
CVE-2026-2323 - chromium-browser: Inappropriate implementation in Downloads
Inappropriate implementation in Downloads in Google Chrome prior to 145.0.7632.45 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)
8.8
CVE-2026-2313 - chromium-browser: Use after free in CSS
Use after free in CSS in Google Chrome prior to 145.0.7632.45 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
6.5
CVE-2026-2318 - chromium-browser: Inappropriate implementation in PictureInPicture
Inappropriate implementation in PictureInPicture in Google Chrome prior to 145.0.7632.45 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
6.5
CVE-2026-2316 - chromium-browser: Insufficient policy enforcement in Frames
Insufficient policy enforcement in Frames in Google Chrome prior to 145.0.7632.45 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
4.3
CVE-2025-15147 - WCFM Membership โ WooCommerce Memberships for Multivendor Marketplace <= 2.11.8 - Insecure Direct Oโฆ
The WCFM Membership โ WooCommerce Memberships for Multivendor Marketplace plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.11.8 via the 'WCFMvm_Memberships_Payment_Controller::processing' due to missing validation on a user controlled keโฆ
7.2
CVE-2026-0845 - WCFM - WooCommerce Frontend Manager <= 6.7.24 - Authenticated (Shop Manager+) Arbitrary Options Updโฆ
The WCFM โ Frontend Manager for WooCommerce along with Bookings Subscription Listings Compatible plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the 'WCFM_Settings_Controller::processing' function in โฆ
5.5
CVE-2025-15314 - Tanium addressed an arbitrary file deletion vulnerability in end-user-cx.
Tanium addressed an arbitrary file deletion vulnerability in end-user-cx.
5.5
CVE-2025-15313 - Tanium addressed an arbitrary file deletion vulnerability in Tanium EUSS.
Tanium addressed an arbitrary file deletion vulnerability in Tanium EUSS.
7.8
CVE-2025-15310 - Tanium addressed a local privilege escalation vulnerability in Patch Endpoint Tools.
Tanium addressed a local privilege escalation vulnerability in Patch Endpoint Tools.