|
2001
|
4.4 |
MEDIUM
Local
|
libjxl_project
|
libjxl
|
Un archivo especialmente diseñado puede provocar que el decodificador de libjxl lea datos de píxeles de memoria no inicializada (pero asignada).
Esto se puede lograr al provocar que el decodificador…
|
CWE-908
Use of Uninitialized Resource
|
CVE-2025-12474
|
2026-04-25 01:42 |
2026-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2002
|
9.6 |
CRITICAL
Network
|
google
|
chrome
|
Use after free in DevTools in Google Chrome prior to 147.0.7727.117 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.…
|
CWE-416
Use After Free
|
CVE-2026-6919
|
2026-04-25 01:39 |
2026-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2003
|
9.6 |
CRITICAL
Network
|
google
|
chrome
|
Out of bounds read in GPU in Google Chrome on Android prior to 147.0.7727.117 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted …
|
CWE-125
Out-of-bounds Read
|
CVE-2026-6920
|
2026-04-25 01:39 |
2026-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2004
|
8.3 |
HIGH
Network
|
google
|
chrome
|
Race in GPU in Google Chrome on Windows prior to 147.0.7727.117 allowed a remote attacker to potentially perform a sandbox escape via a crafted video file. (Chromium security severity: Medium)
|
CWE-362
Race Condition
|
CVE-2026-6921
|
2026-04-25 01:39 |
2026-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2005
|
8.8 |
HIGH
Network
|
flowiseai
|
flowise
|
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, the Chatflow configuration file upload settings can be modified to allow the application/javas…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2026-41269
|
2026-04-25 01:39 |
2026-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2006
|
7.8 |
HIGH
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
apparmor: fix missing bounds check on DEFAULT table in verify_dfa()
The verify_dfa() function only checks DEFAULT_TABLE bounds wh…
|
CWE-125
Out-of-bounds Read
|
CVE-2026-23407
|
2026-04-25 01:38 |
2026-04-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2007
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
i2c: i801: Revert "i2c: i801: replace acpi_lock with I2C bus lock"
This reverts commit f707d6b9e7c18f669adfdb443906d46cfbaaa0c1.
…
|
CWE-476
NULL Pointer Dereference
|
CVE-2026-23369
|
2026-04-25 01:38 |
2026-03-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2008
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
platform/x86: dell-wmi-sysman: Don't hex dump plaintext password data
set_new_password() hex dumps the entire buffer, which conta…
|
NVD-CWE-noinfo
|
CVE-2026-23370
|
2026-04-25 01:37 |
2026-03-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2009
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
En el kernel de Linux, la siguiente vulnerabilidad ha sido resuelta:
platform/x86: dell-wmi-sysman: No volcar en hexadecimal datos de contraseña en texto plano
set_new_password() vuelca en hexadeci…
|
NVD-CWE-noinfo
|
CVE-2026-23370
|
2026-04-25 01:37 |
2026-03-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2010
|
8.3 |
HIGH
Network
|
flowiseai
|
flowise
|
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, a Server-Side Request Forgery (SSRF) vulnerability exists in FlowiseAI's POST/GET API Chain co…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2026-41271
|
2026-04-25 01:37 |
2026-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|