|
211
|
9.1 |
CRITICAL
Network
|
-
|
-
|
An attacker with network access to the PLC is able to brute force discover passwords to gain unauthorized access to systems and services. The limited password complexity and no password input limiter…
New
|
CWE-521
Weak Password Requirements
|
CVE-2026-6284
|
2026-04-18 01:17 |
2026-04-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212
|
9.8 |
CRITICAL
Network
|
-
|
-
|
A SQL injection vulnerability in CodeAstro Simple Attendance Management System v1.0 allows remote unauthenticated attackers to bypass authentication via the username parameter in index.php.
New
|
CWE-89
SQL Injection
|
CVE-2026-37749
|
2026-04-18 01:17 |
2026-04-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213
|
- |
|
-
|
-
|
A vulnerability allowing a local attacker with administrator privileges to bypass Windows Driver Signature Enforcement.
New
|
CWE-77
Command Injection
|
CVE-2026-21709
|
2026-04-18 01:16 |
2026-04-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
214
|
6.5 |
MEDIUM
Network
|
phoca
|
maps
|
Various stored XSS vulnerabilities in the maps- and icon rendering logic in Phoca Maps component 5.0.0-6.0.2 have been discovered.
Update
|
CWE-79
Cross-site Scripting
|
CVE-2026-23900
|
2026-04-18 01:15 |
2026-04-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
215
|
7.5 |
HIGH
Network
|
fastify
|
fastify
|
Impact:
Fastify applications using schema.body.content for per-content-type body validation can have validation bypassed entirely by prepending a space to the Content-Type header. The body is still …
New
|
CWE-1287
Improper Validation of Specified Type of Input
|
CVE-2026-33806
|
2026-04-18 00:49 |
2026-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
216
|
9.6 |
CRITICAL
Network
|
google
|
chrome
|
Heap buffer overflow in ANGLE in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
New
|
CWE-122
Heap-based Buffer Overflow
|
CVE-2026-6296
|
2026-04-18 00:42 |
2026-04-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
217
|
8.3 |
HIGH
Network
|
google
|
chrome
|
Use after free in Proxy in Google Chrome prior to 147.0.7727.101 allowed an attacker in a privileged network position to potentially perform a sandbox escape via a crafted HTML page. (Chromium securi…
New
|
CWE-416
Use After Free
|
CVE-2026-6297
|
2026-04-18 00:42 |
2026-04-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218
|
4.3 |
MEDIUM
Network
|
google
|
chrome
|
Heap buffer overflow in Skia in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium secu…
New
|
CWE-122
Heap-based Buffer Overflow
|
CVE-2026-6298
|
2026-04-18 00:41 |
2026-04-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219
|
8.8 |
HIGH
Network
|
google
|
chrome
|
Use after free in Prerender in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: Critical)
New
|
CWE-416
Use After Free
|
CVE-2026-6299
|
2026-04-18 00:41 |
2026-04-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
220
|
8.8 |
HIGH
Network
|
google
|
chrome
|
Use after free in CSS in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
New
|
CWE-416
Use After Free
|
CVE-2026-6300
|
2026-04-18 00:41 |
2026-04-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|