7.5

CVSS3.1

CVE-2026-7349 - chromium-browser: Use after free in Cast

Use after free in Cast in Google Chrome prior to 147.0.7727.138 allowed an attacker on the local network segment to execute arbitrary code inside a sandbox via malicious network traffic. (Chromium security severity: High)

๐Ÿ“… Published: April 28, 2026, midnight ๐Ÿ”„ Last Modified: April 30, 2026, 4:40 p.m.

8.8

CVSS3.1

CVE-2026-7337 - chromium-browser: Type Confusion in V8

Type Confusion in V8 in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

๐Ÿ“… Published: April 28, 2026, midnight ๐Ÿ”„ Last Modified: April 30, 2026, 6:28 p.m.

6.5

CVSS3.1

CVE-2026-41526 - Shell Argument Quoting Vulnerability Leading to Escape in KCoreAddons

In KDE KCoreAddons before 6.25, KShell::quoteArgs is intended to safely quote arguments so that they can be passed to a shell command. This parsing does not adequately handle metacharacters, leading to an escape from the shell. All applications relying on this method in a security-critical path to โ€ฆ

๐Ÿ“… Published: April 28, 2026, midnight ๐Ÿ”„ Last Modified: April 28, 2026, 1:03 p.m.

9.8

CVSS3.1

CVE-2025-60889 -

Insecure deserialization of untrusted input in StellarGroup HPX 1.11.0 under certain conditions may allow attackers to execute arbitrary code or other unspecified impacts.

๐Ÿ“… Published: April 28, 2026, midnight ๐Ÿ”„ Last Modified: May 2, 2026, 12:45 a.m.

8.6

CVSS4.0

CVE-2026-20766 - Milesight Cameras Heap-based Buffer Overflow

An out-of-bounds memory access vulnerability exists in specific firmware versions of Milesight AIOT cameras.

๐Ÿ“… Published: April 27, 2026, 11:45 p.m. ๐Ÿ”„ Last Modified: April 28, 2026, 2:39 p.m.

9.3

CVSS4.0

CVE-2026-7202 - Totolink A8000RU CGI cstecgi.cgi setWiFiWpsStart os command injection

A vulnerability has been found in Totolink A8000RU 7.1cu.643_b20200521. This affects the function setWiFiWpsStart of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. The manipulation of the argument wscDisabled leads to os command injection. The attack can be initiated remotely. The explโ€ฆ

๐Ÿ“… Published: April 27, 2026, 11:45 p.m. ๐Ÿ”„ Last Modified: April 29, 2026, 2:13 p.m.

7.3

CVSS4.0

CVE-2026-32649 - Milesight Cameras OS Command Injection

A command injection vulnerability exists in the web server of specific firmware versions of Milesight cameras.

๐Ÿ“… Published: April 27, 2026, 11:42 p.m. ๐Ÿ”„ Last Modified: April 28, 2026, 2:42 p.m.

9.2

CVSS4.0

CVE-2026-32644 - Milesight Cameras Use of Hard-coded Cryptographic Key

Specific firmware versions of Milesight AIOT cameras use SSL certificates with default private keys.

๐Ÿ“… Published: April 27, 2026, 11:40 p.m. ๐Ÿ”„ Last Modified: April 28, 2026, 2:45 p.m.

7.7

CVSS4.0

CVE-2026-27785 - Milesight Cameras Use of Hard-coded Credentials

Specific firmware versions of Milesight AIOT camera firmware contain hard-coded credentials.

๐Ÿ“… Published: April 27, 2026, 11:38 p.m. ๐Ÿ”„ Last Modified: April 28, 2026, 9:16 a.m.

4.7

CVSS3.1

CVE-2026-40977 - Spring Boot: Spring Boot: Local file corruption via PID file manipulation

When an application is configured to use `ApplicationPidFileWriter`, a local attacker with write access to the PID file's location can corrupt one file on the host each time the application is started. Affected: Spring Boot 4.0.0โ€“4.0.5 (fix 4.0.6), 3.5.0โ€“3.5.13 (fix 3.5.14), 3.4.0โ€“3.4.15 (fix 3.4.โ€ฆ

๐Ÿ“… Published: April 27, 2026, 11:36 p.m. ๐Ÿ”„ Last Modified: April 30, 2026, 1:37 p.m.
Total resulsts: 348124
Page 128 of 34,813
ยซ previous page ยป next page
Filters