|
2101
|
8.8 |
HIGH
Network
|
google
|
chrome
|
Type Confusion in V8 in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
|
CWE-843
Type Confusion
|
CVE-2026-5871
|
2026-04-14 01:18 |
2026-04-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2102
|
9.8 |
CRITICAL
Network
|
samsung
|
exynos_1280_firmware exynos_1330_firmware exynos_1380_firmware exynos_1480_firmware exynos_1580_firmware exynos_850_firmware exynos_980_firmware exynos_w930_firmware exynos_w9…
|
An issue was discovered in the Wi-Fi driver in Samsung Mobile Processor and Wearable Processor Exynos 980, 850, 1280, 1330, 1380, 1480, 1580, W920, W930, and W1000. Incorrect Handling of the NL80211 …
|
CWE-120
Classic Buffer Overflow
|
CVE-2025-52909
|
2026-04-14 01:17 |
2026-04-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2103
|
7.3 |
HIGH
Network
|
-
|
-
|
A flaw has been found in SourceCodester Pharmacy Sales and Inventory System 1.0. Impacted is an unknown function of the file /ajax.php?action=delete_sales. This manipulation of the argument ID causes…
|
CWE-74 CWE-89
Injection SQL Injection
|
CVE-2026-6188
|
2026-04-14 01:16 |
2026-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2104
|
7.3 |
HIGH
Network
|
-
|
-
|
A vulnerability was detected in SourceCodester Pharmacy Sales and Inventory System 1.0. This issue affects some unknown processing of the file /ajax.php?action=chk_prod_availability. The manipulation…
|
CWE-74 CWE-89
Injection SQL Injection
|
CVE-2026-6187
|
2026-04-14 01:16 |
2026-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2105
|
8.8 |
HIGH
Network
|
-
|
-
|
A security vulnerability has been detected in UTT HiPER 1200GW up to 2.5.3-170306. This vulnerability affects the function strcpy of the file /goform/formNatStaticMap. The manipulation of the argumen…
|
CWE-119 CWE-120
Incorrect Access of Indexable Resource ('Range Error') Classic Buffer Overflow
|
CVE-2026-6186
|
2026-04-14 01:16 |
2026-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2106
|
2.4 |
LOW
Network
|
-
|
-
|
A weakness has been identified in code-projects Simple Content Management System 1.0. This affects an unknown part of the file /web/admin/welcome.php. Executing a manipulation of the argument News Ti…
|
CWE-79 CWE-94
Cross-site Scripting Code Injection
|
CVE-2026-6184
|
2026-04-14 01:16 |
2026-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2107
|
9.1 |
CRITICAL
Network
|
-
|
-
|
Solstice::Session versions through 1440 for Perl generates session ids insecurely.
The _generateSessionID method returns an MD5 digest seeded by the epoch time, a random hash reference, a call to th…
|
CWE-338 CWE-340
Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG) Generation of Predictable Numbers or Identifiers
|
CVE-2026-5085
|
2026-04-14 01:16 |
2026-04-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2108
|
3.7 |
LOW
Network
|
-
|
-
|
phpseclib is a PHP secure communications library. Prior to 3.0.51, 2.0.53, and 1.0.28, phpseclib\Net\SSH2::get_binary_packet() uses PHP's != operator to compare a received SSH packet HMAC against the…
|
CWE-208
Information Exposure Through Timing Discrepancy
|
CVE-2026-40194
|
2026-04-14 01:16 |
2026-04-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2109
|
- |
|
-
|
-
|
PraisonAIAgents is a multi-agent teams system. Prior to 1.5.128, web_crawl's httpx fallback path passes user-supplied URLs directly to httpx.AsyncClient.get() with follow_redirects=True and no host v…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2026-40160
|
2026-04-14 01:16 |
2026-04-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2110
|
7.8 |
HIGH
Local
|
-
|
-
|
PraisonAI is a multi-agent teams system. Prior to 4.5.128, PraisonAI automatically loads a file named tools.py from the current working directory to discover and register custom agent tools. This loa…
|
CWE-94 CWE-426 CWE-829
Code Injection Untrusted Search Path Inclusion of Functionality from Untrusted Control Sphere
|
CVE-2026-40156
|
2026-04-14 01:16 |
2026-04-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|