|
41
|
3.1 |
LOW
Network
|
google
|
chrome
|
Insufficient policy enforcement in Passwords in Google Chrome prior to 147.0.7727.101 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML p…
New
|
NVD-CWE-noinfo
|
CVE-2026-6312
|
2026-04-18 02:26 |
2026-04-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
42
|
3.1 |
LOW
Network
|
google
|
chrome
|
Insufficient policy enforcement in CORS in Google Chrome prior to 147.0.7727.101 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. …
New
|
CWE-284
Improper Access Control
|
CVE-2026-6313
|
2026-04-18 02:26 |
2026-04-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
43
|
8.3 |
HIGH
Network
|
google
|
chrome
|
Out of bounds write in GPU in Google Chrome prior to 147.0.7727.101 allowed a remote attacker who had compromised the GPU process to potentially perform a sandbox escape via a crafted HTML page. (Chr…
New
|
CWE-787
Out-of-bounds Write
|
CVE-2026-6314
|
2026-04-18 02:25 |
2026-04-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
44
|
7.5 |
HIGH
Network
|
juniper
|
junos
|
An Improper Validation of Syntactic Correctness of Input vulnerability in the IPsec library used by kmd and iked of Juniper Networks Junos OS on SRX Series and MX Series allows an unauthenticated, n…
New
|
CWE-1286
Improper Validation of Syntactic Correctness of Input
|
CVE-2026-33778
|
2026-04-18 02:23 |
2026-04-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
45
|
6.5 |
MEDIUM
Network
|
juniper
|
junos
|
An Improper Following of a Certificate's Chain of Trust vulnerability in J-Web of Juniper Networks Junos OS on SRX Series allows a PITM to intercept the communication of the device and get access to …
New
|
CWE-296
Improper Following of a Certificate's Chain of Trust
|
CVE-2026-33779
|
2026-04-18 02:21 |
2026-04-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
46
|
7.1 |
HIGH
Network
|
-
|
-
|
ByteDance DeerFlow before commit 2176b2b contains a path traversal and arbitrary file write vulnerability in bootstrap-mode custom-agent creation where the agent name validation is bypassed. Attacker…
New
|
CWE-22
Path Traversal
|
CVE-2026-40518
|
2026-04-18 02:17 |
2026-04-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
47
|
8.3 |
HIGH
Network
|
-
|
-
|
OpenHarness before commit bd4df81 contains a server-side request forgery vulnerability in the web_fetch and web_search tools that allows attackers to access private and localhost HTTP services by man…
New
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2026-40516
|
2026-04-18 02:17 |
2026-04-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
48
|
7.5 |
HIGH
Network
|
-
|
-
|
OpenHarness before commit bd4df81 contains a permission bypass vulnerability that allows attackers to read sensitive files by exploiting incomplete path normalization in the permission checker. Attac…
New
|
CWE-863
Incorrect Authorization
|
CVE-2026-40515
|
2026-04-18 02:17 |
2026-04-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
49
|
3.3 |
LOW
Local
|
-
|
-
|
MuPDF before 1.27 contains an ANSI injection vulnerability in mutool that allows attackers to inject arbitrary ANSI escape sequences through crafted PDF metadata fields. Attackers can embed malicious…
New
|
CWE-150
Improper Neutralization of Escape, Meta, or Control Sequences
|
CVE-2026-40505
|
2026-04-18 02:17 |
2026-04-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
50
|
8.8 |
HIGH
Network
|
-
|
-
|
The WP Customer Area plugin for WordPress is vulnerable to arbitrary file read and deletion due to insufficient file path validation in the 'ajax_attach_file' function in all versions up to, and incl…
New
|
CWE-22
Path Traversal
|
CVE-2026-3464
|
2026-04-18 02:17 |
2026-04-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|