|
2321
|
6.5 |
MEDIUM
Network
|
-
|
-
|
Out of bounds read in Skia in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted file. (Chromium security se…
|
CWE-125
Out-of-bounds Read
|
CVE-2026-6364
|
2026-04-18 00:08 |
2026-04-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2322
|
5.3 |
MEDIUM
Network
|
-
|
-
|
A flaw was found in the AAP MCP server. An unauthenticated remote attacker can exploit a log injection vulnerability by sending specially crafted input to the `toolsetroute` parameter. This parameter…
|
CWE-117
Improper Output Neutralization for Logs
|
CVE-2026-6494
|
2026-04-18 00:07 |
2026-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2323
|
6.7 |
MEDIUM
Local
|
-
|
-
|
Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7.0.0, LTS2025 release versions 8.3.1.0 through 8.3.1.20, LTS2024 release versions 7.13.1.0 through 7.13.1.60 contain an improper neutralizat…
|
CWE-78
OS Command
|
CVE-2026-35072
|
2026-04-18 00:07 |
2026-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2324
|
6.7 |
MEDIUM
Local
|
-
|
-
|
Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7.0.0, LTS2025 release versions 8.3.1.0 through 8.3.1.20, LTS2024 release versions 7.13.1.0 through 7.13.1.60 contain an improper neutralizat…
|
CWE-78
OS Command
|
CVE-2026-35073
|
2026-04-18 00:07 |
2026-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2325
|
6.7 |
MEDIUM
Local
|
-
|
-
|
Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7.0.0, LTS2025 release versions 8.3.1.0 through 8.3.1.20, LTS2024 release versions 7.13.1.0 through 7.13.1.60 contain an improper neutralizat…
|
CWE-78
OS Command
|
CVE-2026-35074
|
2026-04-18 00:07 |
2026-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2326
|
6.7 |
MEDIUM
Local
|
-
|
-
|
Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7.0.0, LTS2025 release versions 8.3.1.0 through 8.3.1.20, LTS2024 release versions 7.13.1.0 through 7.13.1.60 contain an improper neutralizat…
|
CWE-88
Argument Injection
|
CVE-2026-35153
|
2026-04-18 00:07 |
2026-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2327
|
- |
|
-
|
-
|
GREENmod uses named pipes for communication between plugins, the web portal, and the system service, but the access control lists for these pipes are configured incorrectly. This allows an attacker t…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2026-5131
|
2026-04-18 00:07 |
2026-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2328
|
6.2 |
MEDIUM
Network
|
-
|
-
|
Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 8.4 through 8.5 contain a session fixation vulnerability. A high privileged attacker with remote ac…
|
CWE-384
Session Fixation
|
CVE-2025-46605
|
2026-04-18 00:07 |
2026-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2329
|
6.2 |
MEDIUM
Network
|
-
|
-
|
Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 8.4 through 8.5 contain an improper restriction of excessive authentication attempts vulnerability.…
|
CWE-307
mproper Restriction of Excessive Authentication Attempts
|
CVE-2025-46606
|
2026-04-18 00:07 |
2026-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2330
|
6.6 |
MEDIUM
Network
|
-
|
-
|
Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 8.4 through 8.5 contain an improper authentication vulnerability. A high privileged attacker with r…
|
CWE-287
Improper Authentication
|
CVE-2025-46607
|
2026-04-18 00:07 |
2026-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|