|
201
|
6.8 |
MEDIUM
Network
|
-
|
-
|
ProcessWire CMS version 3.0.255 and prior contain a server-side request forgery vulnerability in the admin panel's 'Add Module From URL' feature that allows authenticated administrators to supply arb…
New
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2026-40500
|
2026-04-16 07:17 |
2026-04-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
202
|
7.5 |
HIGH
Network
|
-
|
-
|
Improper input validation in .NET Framework allows an unauthorized attacker to deny service over a network.
New
|
CWE-755
Improper Handling of Exceptional Conditions
|
CVE-2026-23666
|
2026-04-16 07:16 |
2026-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
203
|
- |
|
-
|
-
|
Pega Platform versions 8.1.0 through 25.1.1 are affected by a Stored Cross-Site Scripting vulnerability in a user interface component. Requires a high privileged user with a developer role.
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-1711
|
2026-04-16 07:16 |
2026-04-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
204
|
- |
|
-
|
-
|
Pega Platform versions 8.1.0 through 25.1.1 are affected by an HTML Injection vulnerability in a user interface component. Requires a high privileged user with a developer role.
New
|
CWE-80
Basic XSS
|
CVE-2026-1564
|
2026-04-16 07:16 |
2026-04-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
205
|
- |
|
-
|
-
|
Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All references and descriptions in this candidate have been removed to prevent accid…
New
|
-
|
CVE-2026-6398
|
2026-04-16 06:17 |
2026-04-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
206
|
8.8 |
HIGH
Network
|
-
|
-
|
Heap buffer overflow in PDFium in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted PDF file. (Chromium security severity: High)
New
|
CWE-122
Heap-based Buffer Overflow
|
CVE-2026-6305
|
2026-04-16 06:17 |
2026-04-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
207
|
4.3 |
MEDIUM
Network
|
-
|
-
|
Heap buffer overflow in Skia in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium secu…
New
|
CWE-122
Heap-based Buffer Overflow
|
CVE-2026-6298
|
2026-04-16 06:17 |
2026-04-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208
|
9.6 |
CRITICAL
Network
|
-
|
-
|
Heap buffer overflow in ANGLE in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
New
|
CWE-122
Heap-based Buffer Overflow
|
CVE-2026-6296
|
2026-04-16 06:17 |
2026-04-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209
|
8.8 |
HIGH
Network
|
-
|
-
|
Composer is a dependency manager for PHP. Versions 1.0 through 2.2.26 and 2.3 through 2.9.5 contain a command injection vulnerability in the Perforce::syncCodeBase() method, which appends the $source…
New
|
CWE-20 CWE-78
Improper Input Validation OS Command
|
CVE-2026-40261
|
2026-04-16 06:17 |
2026-04-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210
|
6.1 |
MEDIUM
Network
|
-
|
-
|
ApostropheCMS is an open-source Node.js content management system. A regression introduced in commit 49d0bb7, included in versions 2.17.1 of the ApostropheCMS-maintained sanitize-html package bypasse…
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-40186
|
2026-04-16 06:17 |
2026-04-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|