9.6

CVSS3.1

CVE-2026-7321 - Sandbox escape due to incorrect boundary conditions in the WebRTC: Networking component

Sandbox escape due to incorrect boundary conditions in the WebRTC: Networking component. This vulnerability was fixed in Firefox 150, Thunderbird 150, Firefox ESR 140.10.1, and Thunderbird 140.10.1.

πŸ“… Published: April 28, 2026, 1:49 p.m. πŸ”„ Last Modified: May 1, 2026, 5:54 p.m.

7.3

CVSS3.1

CVE-2026-7324 - Memory safety bugs fixed in Thunderbird 150.0.1

Memory safety bugs present in Thunderbird 150.0.0. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 150.0.1 and Thunderbird 150.0.1.

πŸ“… Published: April 28, 2026, 1:49 p.m. πŸ”„ Last Modified: May 1, 2026, 3:27 p.m.

7.3

CVSS3.1

CVE-2026-7323 - Memory safety bugs fixed in Thunderbird ESR 140.10.1 and Thunderbird 150.0.1

Memory safety bugs present in Thunderbird ESR 140.10.0 and Thunderbird 150.0.0. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 150.0.1, Firefox ESR …

πŸ“… Published: April 28, 2026, 1:49 p.m. πŸ”„ Last Modified: April 30, 2026, 6:38 p.m.

7.3

CVSS3.1

CVE-2026-7322 - Memory safety bugs fixed in Thunderbird ESR 140.10.1 and Thunderbird 150.0.1

Memory safety bugs present in Thunderbird ESR 140.10.0 and Thunderbird 150.0.0. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 150.0.1, Firefox ESR …

πŸ“… Published: April 28, 2026, 1:49 p.m. πŸ”„ Last Modified: May 1, 2026, 12:30 p.m.

7.5

CVSS3.1

CVE-2026-7320 - Information disclosure due to incorrect boundary conditions in the Audio/Video component

Information disclosure due to incorrect boundary conditions in the Audio/Video component. This vulnerability was fixed in Firefox 150.0.1, Firefox ESR 140.10.1, Firefox ESR 115.35.1, Thunderbird 150.0.1, and Thunderbird 140.10.1.

πŸ“… Published: April 28, 2026, 1:49 p.m. πŸ”„ Last Modified: May 1, 2026, 12:32 p.m.

9.2

CVSS4.0

CVE-2026-27760 - OpenCATS PHP Code Injection via installer AJAX endpoint

OpenCATS prior to commit 3002a29 contains a PHP code injection vulnerability in the installer AJAX endpoint that allows unauthenticated attackers to execute arbitrary code by injecting PHP statements into the databaseConnectivity action parameter. Attackers can break out of the define() string cont…

πŸ“… Published: April 28, 2026, 1:43 p.m. πŸ”„ Last Modified: April 28, 2026, 4 p.m.

4.3

CVSS3.1

CVE-2026-40968 - Spring gRPC SecurityContext leaks across requests on authorization failure

When an authenticated user is denied access to a gRPC method, their authenticated identity remains bound to the gRPC worker thread and can be inherited by a subsequent unauthenticated request on the same thread. This may allow the subsequent user to gain escalated permissions. Affected versions: S…

πŸ“… Published: April 28, 2026, 1:42 p.m. πŸ”„ Last Modified: April 30, 2026, 1:32 p.m.

5.1

CVSS4.0

CVE-2026-7282 - SourceCodester Pharmacy Sales and Inventory System ajax.php delete_expired sql injection

A vulnerability was identified in SourceCodester Pharmacy Sales and Inventory System 1.0. This affects the function delete_expired of the file /ajax.php?action=delete_expired. The manipulation of the argument ID leads to sql injection. It is possible to initiate the attack remotely. The exploit is …

πŸ“… Published: April 28, 2026, 1:30 p.m. πŸ”„ Last Modified: April 28, 2026, 4 p.m.

4.8

CVSS4.0

CVE-2026-7281 - SourceCodester Pharmacy Sales and Inventory System index.php supplier cross site scripting

A vulnerability was determined in SourceCodester Pharmacy Sales and Inventory System 1.0. The impacted element is the function supplier of the file /index.php?page=supplier. Executing a manipulation of the argument Name can lead to cross site scripting. The attack may be performed from remote. The …

πŸ“… Published: April 28, 2026, 1:15 p.m. πŸ”„ Last Modified: April 28, 2026, 3 p.m.

4.7

CVSS4.0

CVE-2026-40552 - Remote Code Execution in mpGabinet

mpGabinet is vulnerable to Remote Command Execution. An authorized user with access to the application and direct access to the backend database can achieve system command execution by uploading an attachment and modifying its storage path in the database to reference an attacker-controlled remote …

πŸ“… Published: April 28, 2026, 1:13 p.m. πŸ”„ Last Modified: April 29, 2026, 10:10 a.m.
Total resulsts: 348395
Page 142 of 34,840
Β« previous page Β» next page
Filters