|
2681
|
4.3 |
MEDIUM
Network
|
google
|
chrome
|
Incorrect security UI in Blink in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
|
CWE-451
User Interface (UI) Misrepresentation of Critical Information
|
CVE-2026-5878
|
2026-04-15 05:02 |
2026-04-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2682
|
4.3 |
MEDIUM
Network
|
google
|
chrome
|
Insufficient policy enforcement in browser UI in Google Chrome prior to 147.0.7727.55 allowed a remote attacker who had compromised the renderer process to spoof the contents of the Omnibox (URL bar)…
|
CWE-451
User Interface (UI) Misrepresentation of Critical Information
|
CVE-2026-5880
|
2026-04-15 05:01 |
2026-04-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2683
|
6.5 |
MEDIUM
Network
|
google
|
chrome
|
Policy bypass in LocalNetworkAccess in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Medium)
|
CWE-284
Improper Access Control
|
CVE-2026-5881
|
2026-04-15 05:01 |
2026-04-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2684
|
4.3 |
MEDIUM
Network
|
google
|
chrome
|
Incorrect security UI in Fullscreen in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
|
CWE-451
User Interface (UI) Misrepresentation of Critical Information
|
CVE-2026-5882
|
2026-04-15 05:01 |
2026-04-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2685
|
9.8 |
CRITICAL
Network
|
pgx_project
|
pgx
|
Memory-safety vulnerability in github.com/jackc/pgx/v5.
|
NVD-CWE-noinfo
|
CVE-2026-33816
|
2026-04-15 05:01 |
2026-04-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2686
|
9.8 |
CRITICAL
Network
|
pgx_project
|
pgx
|
Memory-safety vulnerability in github.com/jackc/pgx/v5.
|
NVD-CWE-noinfo
|
CVE-2026-33815
|
2026-04-15 04:58 |
2026-04-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2687
|
7.5 |
HIGH
Network
|
ech0
|
ech0
|
Ech0 is an open-source, self-hosted publishing platform for personal idea sharing. Prior to 4.2.8, Ech0 implements link preview (editor fetches a page title) through GET /api/website/title. That is l…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2026-35036
|
2026-04-15 04:58 |
2026-04-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2688
|
8.8 |
HIGH
Network
|
devcode
|
openstamanager
|
OpenSTAManager is an open source management software for technical assistance and invoicing. Prior to 2.10.2, confronta_righe.php files across different modules in OpenSTAManager contain an SQL Injec…
|
CWE-89
SQL Injection
|
CVE-2026-35470
|
2026-04-15 04:58 |
2026-04-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2689
|
4.3 |
MEDIUM
Network
|
wwbn
|
avideo
|
WWBN AVideo is an open source video platform. In versions 26.0 and prior, the player skin configuration endpoint at admin/playerUpdate.json.php does not validate CSRF tokens. The plugins table is exp…
|
CWE-352
Origin Validation Error
|
CVE-2026-35181
|
2026-04-15 04:57 |
2026-04-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2690
|
3.7 |
LOW
Network
|
wwbn
|
avideo
|
WWBN AVideo is an open source video platform. In versions 26.0 and prior, the BlockonomicsYPT plugin's check.php endpoint returns payment order data for any Bitcoin address without requiring authenti…
|
CWE-862
Missing Authorization
|
CVE-2026-35448
|
2026-04-15 04:57 |
2026-04-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|