|
191
|
6.5 |
MEDIUM
Adjacent
|
juniper
|
junos
|
A Missing Release of Memory after Effective Lifetime vulnerability in the DHCP daemon (jdhcpd) of Juniper Networks Junos OS on MX Series, allows an adjacent, unauthenticated attacker to cause a memor…
Update
|
CWE-401
Missing Release of Memory after Effective Lifetime
|
CVE-2026-33782
|
2026-04-18 02:39 |
2026-04-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
192
|
6.5 |
MEDIUM
Network
|
praison
|
praisonai
|
PraisonAI is a multi-agent teams system. Prior to 4.5.128, the _safe_extractall() function in PraisonAI's recipe registry validates archive members against path traversal attacks but performs no chec…
Update
|
CWE-409
Improper Handling of Highly Compressed Data (Data Amplification)
|
CVE-2026-40148
|
2026-04-18 02:38 |
2026-04-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
193
|
8.8 |
HIGH
Local
|
juniper
|
junos
|
A Missing Authorization vulnerability in the CLI of Juniper Networks Junos OS on MX Series allows a local, authenticated user with low privileges to execute specific commands which will lead to a com…
Update
|
CWE-862
Missing Authorization
|
CVE-2026-33785
|
2026-04-18 02:38 |
2026-04-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194
|
3.1 |
LOW
Network
|
beszel
|
beszel
|
Beszel is a server monitoring platform. Prior to 0.18.7, some API endpoints in the Beszel hub accept a user-supplied system ID and proceed without further checks that the user should have access to t…
Update
|
CWE-184
Incomplete Blacklist
|
CVE-2026-40077
|
2026-04-18 02:37 |
2026-04-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195
|
8.1 |
HIGH
Network
|
apollographql
|
apollo_mcp_server
|
Apollo MCP Server is a Model Context Protocol server that exposes GraphQL operations as MCP tools. Prior to version 1.7.0, the Apollo MCP Server did not validate the Host header on incoming HTTP requ…
Update
|
CWE-346
Origin Validation Error
|
CVE-2026-35577
|
2026-04-18 02:31 |
2026-04-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196
|
8.8 |
HIGH
Network
|
google
|
chrome
|
Use after free in Video in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
New
|
CWE-416
Use After Free
|
CVE-2026-6302
|
2026-04-18 02:27 |
2026-04-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197
|
8.8 |
HIGH
Network
|
google
|
chrome
|
Use after free in Codecs in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
New
|
CWE-416
Use After Free
|
CVE-2026-6303
|
2026-04-18 02:27 |
2026-04-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198
|
8.3 |
HIGH
Network
|
google
|
chrome
|
Use after free in Graphite in Google Chrome prior to 147.0.7727.101 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.…
New
|
CWE-416
Use After Free
|
CVE-2026-6304
|
2026-04-18 02:27 |
2026-04-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199
|
8.8 |
HIGH
Network
|
google
|
chrome
|
Heap buffer overflow in PDFium in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted PDF file. (Chromium security severity: High)
New
|
CWE-122 CWE-787
Heap-based Buffer Overflow Out-of-bounds Write
|
CVE-2026-6305
|
2026-04-18 02:27 |
2026-04-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
200
|
8.8 |
HIGH
Network
|
google
|
chrome
|
Type Confusion in Turbofan in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
New
|
CWE-843
Type Confusion
|
CVE-2026-6307
|
2026-04-18 02:27 |
2026-04-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|