|
4281
|
5.7 |
MEDIUM
Network
|
oracle
|
peoplesoft_enterprise_cs_student_records
|
Vulnerability in the PeopleSoft Enterprise CS Student Records product of Oracle PeopleSoft (component: Research Tracking). The supported version that is affected is 9.2. Easily exploitable vulnerab…
|
CWE-284
Improper Access Control
|
CVE-2026-35241
|
2026-04-25 01:44 |
2026-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4282
|
7.8 |
HIGH
Local
|
oracle
|
application_development_framework
|
Vulnerability in the Oracle Application Development Framework (ADF) product of Oracle Fusion Middleware (component: ADF Faces). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. E…
|
CWE-284
Improper Access Control
|
CVE-2026-35243
|
2026-04-25 01:43 |
2026-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4283
|
9.1 |
CRITICAL
Network
|
oracle
|
enterprise_manager_base_platform
|
Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Event Management). Supported versions that are affected are 13.5 and 24.1. Easily explo…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2026-34279
|
2026-04-25 01:43 |
2026-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4284
|
6.0 |
MEDIUM
Local
|
oracle
|
graalvm jdk jre
|
Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Hotspot). Supported versions that are affected are Oracle Java SE: 8u481 and 8u481-b50; …
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2026-22003
|
2026-04-25 01:42 |
2026-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4285
|
4.4 |
MEDIUM
Local
|
libjxl_project
|
libjxl
|
A specially-crafted file can cause libjxl's decoder to read pixel data from uninitialized (but allocated) memory.
This can be done by causing the decoder to reference an outside-image-bound area in …
|
CWE-908
Use of Uninitialized Resource
|
CVE-2025-12474
|
2026-04-25 01:42 |
2026-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4286
|
4.4 |
MEDIUM
Local
|
libjxl_project
|
libjxl
|
Un archivo especialmente diseñado puede provocar que el decodificador de libjxl lea datos de píxeles de memoria no inicializada (pero asignada).
Esto se puede lograr al provocar que el decodificador…
|
CWE-908
Use of Uninitialized Resource
|
CVE-2025-12474
|
2026-04-25 01:42 |
2026-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4287
|
9.6 |
CRITICAL
Network
|
google
|
chrome
|
Use after free in DevTools in Google Chrome prior to 147.0.7727.117 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.…
|
CWE-416
Use After Free
|
CVE-2026-6919
|
2026-04-25 01:39 |
2026-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4288
|
9.6 |
CRITICAL
Network
|
google
|
chrome
|
Out of bounds read in GPU in Google Chrome on Android prior to 147.0.7727.117 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted …
|
CWE-125
Out-of-bounds Read
|
CVE-2026-6920
|
2026-04-25 01:39 |
2026-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4289
|
8.3 |
HIGH
Network
|
google
|
chrome
|
Race in GPU in Google Chrome on Windows prior to 147.0.7727.117 allowed a remote attacker to potentially perform a sandbox escape via a crafted video file. (Chromium security severity: Medium)
|
CWE-362
Race Condition
|
CVE-2026-6921
|
2026-04-25 01:39 |
2026-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4290
|
8.8 |
HIGH
Network
|
flowiseai
|
flowise
|
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, the Chatflow configuration file upload settings can be modified to allow the application/javas…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2026-41269
|
2026-04-25 01:39 |
2026-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|