|
2251
|
6.3 |
MEDIUM
Network
|
-
|
-
|
Use after free in Codecs in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to potentially perform out of bounds memory access via a crafted video file. (Chromium security severity: H…
|
CWE-416
Use After Free
|
CVE-2026-6362
|
2026-04-18 00:08 |
2026-04-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2252
|
8.8 |
HIGH
Network
|
-
|
-
|
Type Confusion in V8 in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page. (Chromium security severity: Medium)
|
CWE-843
Type Confusion
|
CVE-2026-6363
|
2026-04-18 00:08 |
2026-04-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2253
|
6.5 |
MEDIUM
Network
|
-
|
-
|
Out of bounds read in Skia in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted file. (Chromium security se…
|
CWE-125
Out-of-bounds Read
|
CVE-2026-6364
|
2026-04-18 00:08 |
2026-04-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2254
|
5.3 |
MEDIUM
Network
|
-
|
-
|
A flaw was found in the AAP MCP server. An unauthenticated remote attacker can exploit a log injection vulnerability by sending specially crafted input to the `toolsetroute` parameter. This parameter…
|
CWE-117
Improper Output Neutralization for Logs
|
CVE-2026-6494
|
2026-04-18 00:07 |
2026-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2255
|
6.7 |
MEDIUM
Local
|
-
|
-
|
Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7.0.0, LTS2025 release versions 8.3.1.0 through 8.3.1.20, LTS2024 release versions 7.13.1.0 through 7.13.1.60 contain an improper neutralizat…
|
CWE-78
OS Command
|
CVE-2026-35072
|
2026-04-18 00:07 |
2026-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2256
|
6.7 |
MEDIUM
Local
|
-
|
-
|
Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7.0.0, LTS2025 release versions 8.3.1.0 through 8.3.1.20, LTS2024 release versions 7.13.1.0 through 7.13.1.60 contain an improper neutralizat…
|
CWE-78
OS Command
|
CVE-2026-35073
|
2026-04-18 00:07 |
2026-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2257
|
6.7 |
MEDIUM
Local
|
-
|
-
|
Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7.0.0, LTS2025 release versions 8.3.1.0 through 8.3.1.20, LTS2024 release versions 7.13.1.0 through 7.13.1.60 contain an improper neutralizat…
|
CWE-78
OS Command
|
CVE-2026-35074
|
2026-04-18 00:07 |
2026-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2258
|
6.7 |
MEDIUM
Local
|
-
|
-
|
Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7.0.0, LTS2025 release versions 8.3.1.0 through 8.3.1.20, LTS2024 release versions 7.13.1.0 through 7.13.1.60 contain an improper neutralizat…
|
CWE-88
Argument Injection
|
CVE-2026-35153
|
2026-04-18 00:07 |
2026-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2259
|
- |
|
-
|
-
|
GREENmod uses named pipes for communication between plugins, the web portal, and the system service, but the access control lists for these pipes are configured incorrectly. This allows an attacker t…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2026-5131
|
2026-04-18 00:07 |
2026-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2260
|
6.2 |
MEDIUM
Network
|
-
|
-
|
Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 8.4 through 8.5 contain a session fixation vulnerability. A high privileged attacker with remote ac…
|
CWE-384
Session Fixation
|
CVE-2025-46605
|
2026-04-18 00:07 |
2026-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|