8.6

CVSS3.1

CVE-2026-30624 - Remote Code Execution via Malicious MCP Server Configuration in Agent Zero 0.9.8

Agent Zero 0.9.8 contains a remote code execution vulnerability in its External MCP Servers configuration feature. The application allows users to define MCP servers using a JSON configuration containing arbitrary command and args values. These values are executed by the application when the config…

πŸ“… Published: April 15, 2026, midnight πŸ”„ Last Modified: April 20, 2026, 8:17 p.m.

8.8

CVSS3.1

CVE-2026-6301 - chromium-browser: Type Confusion in Turbofan

Type Confusion in Turbofan in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

πŸ“… Published: April 15, 2026, midnight πŸ”„ Last Modified: April 17, 2026, 3:41 p.m.

9.8

CVSS3.1

CVE-2026-30625 - Remote Code Execution via MCP Task Creation in Upsonic 0.71.6

Upsonic 0.71.6 contains a remote code execution vulnerability in its MCP server/task creation functionality. The application allows users to define MCP tasks with arbitrary command and args values. Although an allowlist exists, certain allowed commands (npm, npx) accept argument flags that enable e…

πŸ“… Published: April 15, 2026, midnight πŸ”„ Last Modified: April 18, 2026, 5:30 p.m.

8.4

CVSS3.1

CVE-2024-53412 - Command Injection via Port Field in NietThijmen ShoppingCart Leading to Remote Code Execution

Command injection in the connect function in NietThijmen ShoppingCart 0.0.2 allows an attacker to execute arbitrary shell commands and achieve remote code execution via injection of malicious payloads into the Port field

πŸ“… Published: April 15, 2026, midnight πŸ”„ Last Modified: April 17, 2026, 3:09 p.m.

7.5

CVSS3.1

CVE-2026-30996 - Directory Traversal in SAC‑NFe v2.0.02 download.php Allows Arbitrary File Read

An issue in the file handling logic of the component download.php of SAC-NFe v2.0.02 allows attackers to execute a directory traversal and read arbitrary files from the system via a crafted GET request.

πŸ“… Published: April 15, 2026, midnight πŸ”„ Last Modified: April 17, 2026, 3:38 p.m.

8.8

CVSS3.1

CVE-2026-6358 - chromium-browser: Use after free in XR

Use after free in XR in Google Chrome on Android prior to 147.0.7727.101 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: Critical)

πŸ“… Published: April 15, 2026, midnight πŸ”„ Last Modified: April 17, 2026, 7:09 p.m.

8.8

CVSS3.1

CVE-2026-6307 - chromium-browser: Type Confusion in Turbofan

Type Confusion in Turbofan in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

πŸ“… Published: April 15, 2026, midnight πŸ”„ Last Modified: April 17, 2026, 5:27 p.m.

8.8

CVSS3.1

CVE-2026-6360 - chromium-browser: Use after free in FileSystem

Use after free in FileSystem in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to potentially exploit object corruption via a crafted HTML page. (Chromium security severity: High)

πŸ“… Published: April 15, 2026, midnight πŸ”„ Last Modified: April 17, 2026, 7:20 p.m.

7.5

CVSS3.1

CVE-2026-6319 - chromium-browser: Use after free in Payments

Use after free in Payments in Google Chrome on Android prior to 147.0.7727.101 allowed a remote attacker who convinced a user to engage in specific UI gestures to execute arbitrary code via a crafted HTML page. (Chromium security severity: Medium)

πŸ“… Published: April 15, 2026, midnight πŸ”„ Last Modified: April 17, 2026, 7:08 p.m.

8.8

CVSS3.1

CVE-2026-6300 - chromium-browser: Use after free in CSS

Use after free in CSS in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

πŸ“… Published: April 15, 2026, midnight πŸ”„ Last Modified: April 17, 2026, 3:41 p.m.
Total resulsts: 346292
Page 165 of 34,630
Β« previous page Β» next page
Filters