|
1711
|
6.7 |
MEDIUM
Local
|
qnap
|
qurouter
|
An SQL injection vulnerability has been reported to affect QHora. If a local attacker gains an administrator account, they can then exploit the vulnerability to execute unauthorized code or commands.…
|
CWE-89
SQL Injection
|
CVE-2025-62846
|
2026-04-14 23:18 |
2026-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1712
|
6.7 |
MEDIUM
Local
|
qnap
|
qurouter
|
Se ha reportado una vulnerabilidad de inyección SQL que afecta a QHora. Si un atacante local obtiene una cuenta de administrador, puede entonces explotar la vulnerabilidad para ejecutar código o coma…
|
CWE-89
SQL Injection
|
CVE-2025-62846
|
2026-04-14 23:18 |
2026-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1713
|
8.8 |
HIGH
Network
|
google
|
chrome
|
Integer overflow in Media in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to potentially exploit heap corruption via a crafted video file. (Chromium security severity: Low)
|
CWE-472
External Control of Assumed-Immutable Web Parameter
|
CVE-2026-5908
|
2026-04-14 23:11 |
2026-04-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1714
|
8.1 |
HIGH
Network
|
google
|
chrome
|
Out of bounds read in Blink in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: Low)
|
CWE-125
Out-of-bounds Read
|
CVE-2026-5913
|
2026-04-14 23:11 |
2026-04-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1715
|
8.8 |
HIGH
Network
|
google
|
chrome
|
Type Confusion in CSS in Google Chrome prior to 147.0.7727.55 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted Chrome Ext…
|
CWE-843
Type Confusion
|
CVE-2026-5914
|
2026-04-14 23:09 |
2026-04-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1716
|
8.1 |
HIGH
Network
|
google
|
chrome
|
Insufficient validation of untrusted input in WebML in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium secur…
|
CWE-20
Improper Input Validation
|
CVE-2026-5915
|
2026-04-14 23:09 |
2026-04-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1717
|
4.3 |
MEDIUM
Network
|
google
|
chrome
|
Inappropriate implementation in Navigation in Google Chrome prior to 147.0.7727.55 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page…
|
CWE-346 CWE-352
Origin Validation Error Origin Validation Error
|
CVE-2026-5918
|
2026-04-14 23:09 |
2026-04-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1718
|
8.8 |
HIGH
Network
|
mediawiki
|
checkuser
|
Vulnerability in Wikimedia Foundation CheckUser. This vulnerability is associated with program files includes/Mail/UserMailer.Php.
This issue affects CheckUser: from * before 1.39.14, 1.43.4, 1.44.1.
|
NVD-CWE-noinfo
|
CVE-2025-67478
|
2026-04-14 23:08 |
2026-02-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1719
|
8.8 |
HIGH
Network
|
mediawiki
|
checkuser
|
Vulnerabilidad en Wikimedia Foundation CheckUser. Esta vulnerabilidad está asociada con archivos de programa includes/Mail/UserMailer.PHP.
Este problema afecta a CheckUser: desde * antes de 1.39.14,…
|
NVD-CWE-noinfo
|
CVE-2025-67478
|
2026-04-14 23:08 |
2026-02-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1720
|
6.5 |
MEDIUM
Network
|
gitlab
|
gitlab
|
GitLab has remediated an issue in GitLab EE affecting all versions from 18.2 before 18.8.9, 18.9 before 18.9.5, and 18.10 before 18.10.3 that could have allowed an authenticated user to cause denial …
|
CWE-1284
Improper Validation of Specified Quantity in Input
|
CVE-2026-1101
|
2026-04-14 23:05 |
2026-04-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|