CVE-2026-14096
Inappropriate implementation in Input in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker who had compromised the r
CVSS
6.5
Medio
EPSS
0.3%
p22
KEV
—
Exploit Today
7
0-100
Publicado: 30 jun 2026 · Última mod.: 1 jul 2026 · CWE-200
0.2%EPSS · 30 días0.3%
2026-08-102026-09-07
Inappropriate implementation in Input in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-866725.3 MED—
———A vulnerability has been found in ningzichun Student Management System up to 98760f5711cf6dc8b4adca53a9e207ca49b02ebf. Affected is an unknown function of the file example.7z of the component Backup Handler. The manipulation leads to information disclosure. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. Continious delivery with rolling releases is used by this product. Therefore, no version details of affected nor updated releases are available. The project was informed of the problem early through an issue report but has not responded yet.43mCVE-2026-698625.5 MED—
———Out-of-bounds read in Windows Wireless Wide Area Network Service allows an authorized attacker to disclose information locally.37mCVE-2026-698067.0 ALT—
———Exposure of sensitive information to an unauthorized actor in .NET allows an authorized attacker to elevate privileges locally.37mCVE-2026-698057.5 ALT—
———External control of file name or path in .NET allows an unauthorized attacker to elevate privileges over a network.37mCVE-2026-695497.0 ALT—
———Out-of-bounds read in Virtual Hard Disk (VHD) Miniport Driver allows an authorized attacker to elevate privileges locally.37mCVE-2026-688525.5 MED—
———Use of uninitialized resource in Microsoft Account allows an authorized attacker to disclose information locally.37m