|
31
|
8.1 |
HIGH
Network
|
apollographql
|
apollo_mcp_server
|
Apollo MCP Server is a Model Context Protocol server that exposes GraphQL operations as MCP tools. Prior to version 1.7.0, the Apollo MCP Server did not validate the Host header on incoming HTTP requ…
New
|
CWE-346
Origin Validation Error
|
CVE-2026-35577
|
2026-04-18 02:31 |
2026-04-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
32
|
8.8 |
HIGH
Network
|
google
|
chrome
|
Use after free in Video in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
New
|
CWE-416
Use After Free
|
CVE-2026-6302
|
2026-04-18 02:27 |
2026-04-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
33
|
8.8 |
HIGH
Network
|
google
|
chrome
|
Use after free in Codecs in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
New
|
CWE-416
Use After Free
|
CVE-2026-6303
|
2026-04-18 02:27 |
2026-04-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
34
|
8.3 |
HIGH
Network
|
google
|
chrome
|
Use after free in Graphite in Google Chrome prior to 147.0.7727.101 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.…
New
|
CWE-416
Use After Free
|
CVE-2026-6304
|
2026-04-18 02:27 |
2026-04-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
35
|
8.8 |
HIGH
Network
|
google
|
chrome
|
Heap buffer overflow in PDFium in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted PDF file. (Chromium security severity: High)
New
|
CWE-122 CWE-787
Heap-based Buffer Overflow Out-of-bounds Write
|
CVE-2026-6305
|
2026-04-18 02:27 |
2026-04-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
36
|
8.8 |
HIGH
Network
|
google
|
chrome
|
Type Confusion in Turbofan in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
New
|
CWE-843
Type Confusion
|
CVE-2026-6307
|
2026-04-18 02:27 |
2026-04-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
37
|
7.5 |
HIGH
Network
|
google
|
chrome
|
Out of bounds read in Media in Google Chrome prior to 147.0.7727.101 allowed a remote attacker who convinced a user to engage in specific UI gestures to execute arbitrary code via a crafted HTML page…
New
|
CWE-125
Out-of-bounds Read
|
CVE-2026-6308
|
2026-04-18 02:26 |
2026-04-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
38
|
8.3 |
HIGH
Network
|
google
|
chrome
|
Use after free in Viz in Google Chrome prior to 147.0.7727.101 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chr…
New
|
CWE-416
Use After Free
|
CVE-2026-6309
|
2026-04-18 02:26 |
2026-04-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
39
|
8.3 |
HIGH
Network
|
google
|
chrome
|
Use after free in Dawn in Google Chrome prior to 147.0.7727.101 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Ch…
New
|
CWE-416
Use After Free
|
CVE-2026-6310
|
2026-04-18 02:26 |
2026-04-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
40
|
8.3 |
HIGH
Network
|
google
|
chrome
|
Uninitialized Use in Accessibility in Google Chrome on Windows prior to 147.0.7727.101 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a…
New
|
CWE-457
Use of Uninitialized Variable
|
CVE-2026-6311
|
2026-04-18 02:26 |
2026-04-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|