9.6

CVSS3.1

CVE-2026-5288 - Use‑After‑Free in Chrome Android WebView Enables Potential Sandbox Escape

Use after free in WebView in Google Chrome on Android prior to 146.0.7680.178 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

📅 Published: April 1, 2026, 4:41 a.m. 🔄 Last Modified: April 2, 2026, 8:18 p.m.

5.1

CVSS4.0

CVE-2026-5254 - welovemedia FFmate Webhook AppJsonTreeView.vue cross site scripting

A security vulnerability has been detected in welovemedia FFmate up to 2.0.15. Affected by this issue is some unknown functionality of the file /ui/app/components/AppJsonTreeView.vue of the component Webhook Handler. The manipulation leads to cross site scripting. The attack may be initiated remote…

📅 Published: April 1, 2026, 4:15 a.m. 🔄 Last Modified: April 24, 2026, 6:12 p.m.

5.1

CVSS4.0

CVE-2026-5253 - bufanyun HotGo editNotice Endpoint MessageList.vue cross site scripting

A weakness has been identified in bufanyun HotGo 1.0/2.0. Affected by this vulnerability is an unknown functionality of the file /web/src/layout/components/Header/MessageList.vue of the component editNotice Endpoint. Executing a manipulation can lead to cross site scripting. The attack can be launc…

📅 Published: April 1, 2026, 3:15 a.m. 🔄 Last Modified: April 24, 2026, 6:12 p.m.

5.1

CVSS4.0

CVE-2026-5252 - z-9527 admin Message Create Endpoint message.js cross site scripting

A security flaw has been discovered in z-9527 admin 1.0/2.0. Affected is an unknown function of the file /server/routes/message.js of the component Message Create Endpoint. Performing a manipulation results in cross site scripting. The attack can be initiated remotely. The exploit has been released…

📅 Published: April 1, 2026, 3:15 a.m. 🔄 Last Modified: April 24, 2026, 6:12 p.m.

5.3

CVSS4.0

CVE-2026-5251 - z-9527 admin User Update Endpoint user.js dynamically-determined object attributes

A vulnerability was identified in z-9527 admin 1.0/2.0. This impacts an unknown function of the file /server/routes/user.js of the component User Update Endpoint. Such manipulation of the argument isAdmin with the input 1 leads to dynamically-determined object attributes. It is possible to launch t…

📅 Published: April 1, 2026, 2:30 a.m. 🔄 Last Modified: April 24, 2026, 6:12 p.m.

4.7

CVSS3.1

CVE-2026-3774 - Self-Modifications Affecting Altered Printing and Redaction in Foxit PDF Editor

The application allows PDF JavaScript and document/print actions (such as WillPrint/DidPrint) to update form fields, annotations, or optional content groups (OCGs) immediately before or after redaction, encryption, or printing. These script‑driven updates are not fully covered by the existing redac…

📅 Published: April 1, 2026, 1:40 a.m. 🔄 Last Modified: April 10, 2026, 9:45 a.m.

7.8

CVSS3.1

CVE-2026-3775 - Foxit PDF Editor/Reader Update Service Uncontrolled Search Path Element Local Privilege Escalation …

The application's update service, when checking for updates, loads certain system libraries from a search path that includes directories writable by low‑privileged users and is not strictly restricted to trusted system locations. Because these libraries may be resolved and loaded from user‑writable…

📅 Published: April 1, 2026, 1:40 a.m. 🔄 Last Modified: April 15, 2026, 4:45 p.m.

5.5

CVSS3.1

CVE-2026-3776 - Null pointer dereference in Foxit PDF Editor/Reader when accessing stamp annotation

The application does not validate the presence of required appearance (AP) data before accessing stamp annotation resources. When a PDF contains a stamp annotation missing its AP entry, the code continues to dereference the associated object without a prior null or validity check, which allows a cr…

📅 Published: April 1, 2026, 1:40 a.m. 🔄 Last Modified: April 15, 2026, 4:45 p.m.

7.3

CVSS3.1

CVE-2026-3780 - Foxit PDF Editor/Reader Installer Uncontrolled Search Path Privilege Escalation

The application's installer runs with elevated privileges but resolves system executables and DLLs using untrusted search paths that can include user-writable directories, allowing a local attacker to place malicious binaries with the same names and have them loaded or executed instead of the legit…

📅 Published: April 1, 2026, 1:40 a.m. 🔄 Last Modified: April 28, 2026, 2:14 p.m.

6.2

CVSS3.1

CVE-2026-3778 - Stack exhaustion caused by cyclic references in Foxit PDF Editor/Reader

The application does not detect or guard against cyclic PDF object references while handling JavaScript in PDF. When pages and annotations are crafted that reference each other in a loop, passing the document to APIs (e.g., SOAP) that perform deep traversal can cause uncontrolled recursion, stack e…

📅 Published: April 1, 2026, 1:40 a.m. 🔄 Last Modified: April 15, 2026, 4:45 p.m.
Total resulsts: 349182
Page 758 of 34,919
« previous page » next page
Filters