|
221
|
8.8 |
HIGH
Network
|
google
|
chrome
|
Type Confusion in Turbofan in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
New
|
CWE-843
Type Confusion
|
CVE-2026-6301
|
2026-04-18 00:41 |
2026-04-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222
|
8.8 |
HIGH
Network
|
google
|
chrome
|
Heap buffer overflow in PDFium in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted PDF file. (Chromium security severity: High)
New
|
CWE-122
Heap-based Buffer Overflow
|
CVE-2026-6306
|
2026-04-18 00:40 |
2026-04-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223
|
7.5 |
HIGH
Network
|
-
|
-
|
A heap buffer overflow in the av_bprint_finalize() function of FFmpeg v8.0.1 allows attackers to cause a Denial of Service (DoS) via a crafted input.
Update
|
CWE-122
Heap-based Buffer Overflow
|
CVE-2026-30999
|
2026-04-18 00:38 |
2026-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224
|
5.4 |
MEDIUM
Network
|
-
|
-
|
Cross-Site Scripting vulnerability in the Snipe-IT web-based asset management system v8.3.0 to up and including v8.3.1 allows authenticated attacker with lowest privileges sufficient only to log in, …
Update
|
CWE-79
Cross-site Scripting
|
CVE-2025-63743
|
2026-04-18 00:38 |
2026-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
225
|
7.5 |
HIGH
Network
|
-
|
-
|
A NULL pointer dereference in Nitro PDF Pro for Windows v14.41.1.4 allows attackers to cause a Denial of Service (DoS) via a crafted XFA packet.
Update
|
CWE-476
NULL Pointer Dereference
|
CVE-2025-66769
|
2026-04-18 00:38 |
2026-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
226
|
8.4 |
HIGH
Local
|
-
|
-
|
Nitro PDF Pro for Windows 14.41.1.4 contains a heap use-after-free vulnerability in the implementation of the JavaScript method this.mailDoc(). During execution, an internal XID object is allocated a…
Update
|
CWE-416
Use After Free
|
CVE-2025-69627
|
2026-04-18 00:38 |
2026-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
227
|
- |
|
-
|
-
|
Unrestricted Upload of File with Dangerous Type vulnerability allows Remote Code Execution via file upload. This issue affects Pandora FMS: from 777 through 800
Update
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2026-30804
|
2026-04-18 00:38 |
2026-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
228
|
- |
|
-
|
-
|
Improper Neutralization of Special Elements used in an OS Command vulnerability allows OS Command Injection via Network Report. This issue affects Pandora FMS: from 777 through 800
Update
|
CWE-78
OS Command
|
CVE-2026-30806
|
2026-04-18 00:38 |
2026-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
229
|
- |
|
-
|
-
|
Improper Neutralization of Special Elements used in an OS Command vulnerability allows OS Command Injection via WebServerModuleDebug. This issue affects Pandora FMS: from 777 through 800
Update
|
CWE-78
OS Command
|
CVE-2026-30809
|
2026-04-18 00:38 |
2026-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
230
|
- |
|
-
|
-
|
Missing Authorization vulnerability allows Exposure of Sensitive Information via configuration endpoint. This issue affects Pandora FMS: from 777 through 800
Update
|
CWE-276
Incorrect Default Permissions
|
CVE-2026-30811
|
2026-04-18 00:38 |
2026-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|