5.3

CVSS3.1

CVE-2026-21726 - Loki Path Traversal - CVE-2021-36156 Bypass

The CVE-2021-36156 fix validates the namespace parameter for path traversal sequences after a single URL decode, by double encoding, an attacker can read files at the Ruler API endpoint /loki/api/v1/rules/{namespace} Thanks to Prasanth Sundararajan for reporting this vulnerability.

πŸ“… Published: April 15, 2026, 7:24 p.m. πŸ”„ Last Modified: April 24, 2026, 8 a.m.

9.1

CVSS3.1

CVE-2025-41118 - Sensitive COS `SecretKey` exposed in plaintext via configuration API due to missing type protection

Pyroscope is an open-source continuous profiling database. The database supports various storage backends, including Tencent Cloud Object Storage (COS). If the database is configured to use Tencent COS as the storage backend, an attacker could extract the secret_key configuration value from the Py…

πŸ“… Published: April 15, 2026, 7:15 p.m. πŸ”„ Last Modified: April 24, 2026, 8 a.m.

6.5

CVSS3.1

CVE-2026-6385 - Ffmpeg: ffmpeg: denial of service and potential arbitrary code execution via signed integer overflo…

A flaw was found in FFmpeg. A remote attacker could exploit this vulnerability by providing a specially crafted MPEG-PS/VOB media file containing a malicious DVD subtitle stream. This vulnerability is caused by a signed integer overflow in the DVD subtitle parser's fragment reassembly bounds checks…

πŸ“… Published: April 15, 2026, 7:11 p.m. πŸ”„ Last Modified: April 17, 2026, 3:17 p.m.

3.7

CVSS3.1

CVE-2026-33877 - ApostropheCMS: User Enumeration via Timing Side Channel in Password Reset Endpoint

ApostropheCMS is an open-source Node.js content management system. Versions 4.28.0 and prior contain a timing side-channel vulnerability in the password reset endpoint (/api/v1/@apostrophecms/login/reset-request) that allows unauthenticated username and email enumeration. When a user is not found, …

πŸ“… Published: April 15, 2026, 7:11 p.m. πŸ”„ Last Modified: April 20, 2026, 5:05 p.m.

6.5

CVSS3.1

CVE-2026-6364 - Skia: Google Chrome: Chromium: Skia: Information disclosure via out-of-bounds read in Google Chrome

Out of bounds read in Skia in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted file. (Chromium security severity: Medium)

πŸ“… Published: April 15, 2026, 7:04 p.m. πŸ”„ Last Modified: April 17, 2026, 7:19 p.m.

8.8

CVSS3.1

CVE-2026-6317 - Google Chrome: Chromium: Google Chrome and Chromium: Arbitrary code execution via a crafted HTML pa…

Use after free in Cast in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)

πŸ“… Published: April 15, 2026, 7:04 p.m. πŸ”„ Last Modified: April 17, 2026, 7:08 p.m.

8.8

CVSS3.1

CVE-2026-6363 - V8: Google Chrome: Chromium: Google Chrome V8: Out-of-bounds memory access via crafted HTML page

Type Confusion in V8 in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page. (Chromium security severity: Medium)

πŸ“… Published: April 15, 2026, 7:04 p.m. πŸ”„ Last Modified: April 17, 2026, 7:19 p.m.

8.3

CVSS3.1

CVE-2026-6361 - PDFium: Google Chrome: Chromium: PDFium in Google Chrome: Arbitrary code execution via crafted PDF …

Heap buffer overflow in PDFium in Google Chrome on Windows prior to 147.0.7727.101 allowed a remote attacker who convinced a user to engage in specific UI gestures to execute arbitrary code inside a sandbox via a crafted PDF file. (Chromium security severity: High)

πŸ“… Published: April 15, 2026, 7:04 p.m. πŸ”„ Last Modified: April 17, 2026, 7:20 p.m.

8.8

CVSS3.1

CVE-2026-6316 - Google Chrome: Chromium: Google Chrome/Chromium: Arbitrary code execution via use-after-free in For…

Use after free in Forms in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

πŸ“… Published: April 15, 2026, 7:04 p.m. πŸ”„ Last Modified: April 17, 2026, 7:08 p.m.

8.3

CVSS3.1

CVE-2026-6314 - Google Chrome: Chromium: Google Chrome and Chromium: Sandbox escape via out-of-bounds write in GPU

Out of bounds write in GPU in Google Chrome prior to 147.0.7727.101 allowed a remote attacker who had compromised the GPU process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

πŸ“… Published: April 15, 2026, 7:04 p.m. πŸ”„ Last Modified: April 17, 2026, 5:25 p.m.
Total resulsts: 347742
Page 292 of 34,775
Β« previous page Β» next page
Filters