7.5

CVSS3.1

CVE-2025-67223 - Unrestricted Access to Sensitive Files via Predictable Log Names in Aranda File Server

The Aranda File Server (AFS) component in Aranda Software Aranda Service Desk before 8.3.12 stores daily activity logs with predictable names in a publicly accessible directory, which allows unauthenticated remote attackers to obtain direct virtual paths of uploaded files and bypass access controls…

πŸ“… Published: April 28, 2026, midnight πŸ”„ Last Modified: April 29, 2026, 10:11 a.m.

8.2

CVSS3.1

CVE-2026-38651 -

Authentication Bypass vulnerability exists in Netmaker versions prior to 1.5.0. The VerifyHostToken function in logic/jwts.go fails to validate the JWT signature when verifying host tokens. An attacker can forge a JWT signed with any arbitrary key and use it to impersonate any host in the network, …

πŸ“… Published: April 28, 2026, midnight πŸ”„ Last Modified: April 29, 2026, 2:30 a.m.

6.1

CVSS3.1

CVE-2026-37750 -

A reflected Cross-Site Scripting (XSS) vulnerability in School Management System by mahmoudai1 allows unauthenticated remote attackers to execute arbitrary JavaScript in victim's browsers via the unsanitized type parameter in register.php.

πŸ“… Published: April 28, 2026, midnight πŸ”„ Last Modified: April 30, 2026, 4:15 a.m.

0.0

CVE-2026-38948 -

Cross-Site Scripting (XSS) vulnerability exists in FUEL CMS v1.5.2 and before within the asset upload functionality. The application fails to properly sanitize uploaded SVG files, allowing a low-privileged authenticated user to upload a crafted SVG file containing malicious code.

πŸ“… Published: April 28, 2026, midnight πŸ”„ Last Modified: April 28, 2026, 3:55 p.m.

8.8

CVSS3.1

CVE-2026-7363 - chromium-browser: Use after free in Canvas

Use after free in Canvas in Google Chrome on Linux, ChromeOS prior to 147.0.7727.138 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Critical)

πŸ“… Published: April 28, 2026, midnight πŸ”„ Last Modified: April 30, 2026, 4:37 p.m.

8.3

CVSS3.1

CVE-2026-7352 - chromium-browser: Use after free in Media

Use after free in Media in Google Chrome on Android prior to 147.0.7727.138 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

πŸ“… Published: April 28, 2026, midnight πŸ”„ Last Modified: April 30, 2026, 4:40 p.m.

8.1

CVSS3.1

CVE-2026-7347 - chromium-browser: Use after free in Chromoting

Use after free in Chromoting in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to execute arbitrary code via malicious network traffic. (Chromium security severity: High)

πŸ“… Published: April 28, 2026, midnight πŸ”„ Last Modified: April 30, 2026, 6:27 p.m.

8.8

CVSS3.1

CVE-2026-7342 - chromium-browser: Use after free in WebView

Use after free in WebView in Google Chrome on Android prior to 147.0.7727.138 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

πŸ“… Published: April 28, 2026, midnight πŸ”„ Last Modified: April 30, 2026, 4:36 p.m.

8.8

CVSS3.1

CVE-2026-7341 - chromium-browser: Use after free in WebRTC

Use after free in WebRTC in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

πŸ“… Published: April 28, 2026, midnight πŸ”„ Last Modified: April 30, 2026, 4:36 p.m.

4.3

CVSS3.1

CVE-2026-7340 - chromium-browser: Integer overflow in ANGLE

Integer overflow in ANGLE in Google Chrome on Windows prior to 147.0.7727.138 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: Medium)

πŸ“… Published: April 28, 2026, midnight πŸ”„ Last Modified: April 30, 2026, 4:36 p.m.
Total resulsts: 347933
Page 105 of 34,794
Β« previous page Β» next page
Filters