|
201
|
7.5 |
HIGH
Network
|
google
|
chrome
|
Out of bounds read in Media in Google Chrome prior to 147.0.7727.101 allowed a remote attacker who convinced a user to engage in specific UI gestures to execute arbitrary code via a crafted HTML page…
New
|
CWE-125
Out-of-bounds Read
|
CVE-2026-6308
|
2026-04-18 02:26 |
2026-04-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
202
|
8.3 |
HIGH
Network
|
google
|
chrome
|
Use after free in Viz in Google Chrome prior to 147.0.7727.101 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chr…
New
|
CWE-416
Use After Free
|
CVE-2026-6309
|
2026-04-18 02:26 |
2026-04-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
203
|
8.3 |
HIGH
Network
|
google
|
chrome
|
Use after free in Dawn in Google Chrome prior to 147.0.7727.101 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Ch…
New
|
CWE-416
Use After Free
|
CVE-2026-6310
|
2026-04-18 02:26 |
2026-04-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
204
|
8.3 |
HIGH
Network
|
google
|
chrome
|
Uninitialized Use in Accessibility in Google Chrome on Windows prior to 147.0.7727.101 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a…
New
|
CWE-457
Use of Uninitialized Variable
|
CVE-2026-6311
|
2026-04-18 02:26 |
2026-04-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
205
|
3.1 |
LOW
Network
|
google
|
chrome
|
Insufficient policy enforcement in Passwords in Google Chrome prior to 147.0.7727.101 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML p…
New
|
NVD-CWE-noinfo
|
CVE-2026-6312
|
2026-04-18 02:26 |
2026-04-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
206
|
3.1 |
LOW
Network
|
google
|
chrome
|
Insufficient policy enforcement in CORS in Google Chrome prior to 147.0.7727.101 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. …
New
|
CWE-284
Improper Access Control
|
CVE-2026-6313
|
2026-04-18 02:26 |
2026-04-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
207
|
8.3 |
HIGH
Network
|
google
|
chrome
|
Out of bounds write in GPU in Google Chrome prior to 147.0.7727.101 allowed a remote attacker who had compromised the GPU process to potentially perform a sandbox escape via a crafted HTML page. (Chr…
New
|
CWE-787
Out-of-bounds Write
|
CVE-2026-6314
|
2026-04-18 02:25 |
2026-04-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208
|
7.5 |
HIGH
Network
|
juniper
|
junos
|
An Improper Validation of Syntactic Correctness of Input vulnerability in the IPsec library used by kmd and iked of Juniper Networks Junos OS on SRX Series and MX Series allows an unauthenticated, n…
Update
|
CWE-1286
Improper Validation of Syntactic Correctness of Input
|
CVE-2026-33778
|
2026-04-18 02:23 |
2026-04-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209
|
6.5 |
MEDIUM
Network
|
juniper
|
junos
|
An Improper Following of a Certificate's Chain of Trust vulnerability in J-Web of Juniper Networks Junos OS on SRX Series allows a PITM to intercept the communication of the device and get access to …
Update
|
CWE-296
Improper Following of a Certificate's Chain of Trust
|
CVE-2026-33779
|
2026-04-18 02:21 |
2026-04-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210
|
7.1 |
HIGH
Network
|
-
|
-
|
ByteDance DeerFlow before commit 2176b2b contains a path traversal and arbitrary file write vulnerability in bootstrap-mode custom-agent creation where the agent name validation is bypassed. Attacker…
New
|
CWE-22
Path Traversal
|
CVE-2026-40518
|
2026-04-18 02:17 |
2026-04-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|