CWE-672

CWE-672 · 6 records · 2 with a public proof-of-concept

Records the NVD classes under CWE-672, highest CVSS first.

  1. MEDIUM 6.5CVE-2026-95366public PoC

    Use of released resource in Core in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)

    chrome

    AI risk analysis on Exploit-DB.ai →

  2. UNSCOREDCVE-2026-96589public PoC

    When a private repository is transferred to a user who lacks access, Gitea grants that recipient temporary read access as a collaborator so they can review the repository. Rejecting or cancelling the transfer did not revoke this collaboration, so the named rec…

    AI risk analysis on Exploit-DB.ai →

  3. UNSCOREDCVE-2026-106345

    Use of released resource in Session in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to spoof UI elements via a crafted HTML page. (Chromium security severity: Low)

    AI risk analysis on Exploit-DB.ai →

  4. UNSCOREDCVE-2026-106339

    Use of released resource in Core in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to potentially obtain cross-origin data via a crafted HTML page. (Chromium security severity: Low)

    AI risk analysis on Exploit-DB.ai →

  5. UNSCOREDCVE-2026-106320

    Use of released resource in UI in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to spoof UI elements via a crafted HTML page. (Chromium security severity: Low)

    AI risk analysis on Exploit-DB.ai →

  6. UNSCOREDCVE-2026-106310

    Use of released resource in FontAccess in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Low)

    AI risk analysis on Exploit-DB.ai →