CWE-472
CWE-472
MITRENo catalog description on file. The MITRE CWE site has the canonical reference.
Recent CVEs
showing 17 of 17- CVE-2026-42655Medium· 5.916 h ago
Unauthenticated Bypass Vulnerability in Best Payments Plugin for WP <= 4.6.19 versions.
- CVE-2026-11290Medium· 5.0EPSS 0%18 h ago
Integer overflow in WebView in Google Chrome on Android prior to 149.0.7827.53 allowed a local attacker to cause a denial of service via a malicious file. (Chromium security severity: Low)
- CVE-2025-35939Medium· 5.3KEVEPSS 1%18 h ago
Craft CMS External Control of Assumed-Immutable Web Parameter Vulnerability
- CVE-2025-59382—EPSS 0%4 d ago
QTS, QuTS hero, QuTScloud are not affected. We have already fixed the vulnerability in the following version:
- CVE-2026-11669Medium· 5.3EPSS 0%5 d ago
Out of bounds read in Media in Google Chrome on ChromeOS prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Ch
- CVE-2026-11640High· 8.3EPSS 0%6 d ago
Integer overflow in libyuv in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
- CVE-2026-11655High· 8.3EPSS 0%6 d ago
Integer overflow in Media in Google Chrome on Mac prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
- CVE-2026-11678Medium· 5.3EPSS 0%6 d ago
Integer overflow in libyuv in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium securi
- CVE-2026-11281Medium· 5.0EPSS 0%7 d ago
Integer overflow in Chromoting in Google Chrome on Windows prior to 149.0.7827.53 allowed a local attacker to obtain potentially sensitive information from process memory via a crafted ETW event. (Chromium security severity: Low)
- CVE-2026-11044Medium· 6.5EPSS 0%7 d ago
Integer overflow in ANGLE in Google Chrome on Mac prior to 149.0.7827.53 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)
- CVE-2026-11085High· 8.8EPSS 0%7 d ago
Integer overflow in GPU in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page. (Chromium security severity: Medium)
- CVE-2026-11211High· 8.8EPSS 0%7 d ago
Integer overflow in V8 in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)
- CVE-2026-10987High· 8.8EPSS 0%10 d ago
Integer overflow in V8 in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
- CVE-2026-10986High· 8.8EPSS 0%10 d ago
Integer overflow in Media in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a malicious file. (Chromium security severity: High)
- CVE-2026-11058High· 7.5EPSS 0%10 d ago
Integer overflow in CredentialProvider in Google Chrome on Windows prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to perform OS-level privilege escalation via a crafted HTML page. (Chromium securit
- CVE-2026-11171High· 8.8EPSS 0%10 d ago
Integer overflow in Blink in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)
- CVE-2026-11088Critical· 9.6EPSS 0%10 d ago
Integer overflow in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)
CWE catalog data sourced from MITRE. CVE associations come from NVD weakness mappings; some CVEs carry multiple CWEs.