7.5

CVSS3.1

CVE-2026-3924 - chromium-browser: Use after free in WindowDialog

use after free in WindowDialog in Google Chrome prior to 146.0.7680.71 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

πŸ“… Published: March 10, 2026, midnight πŸ”„ Last Modified: April 17, 2026, 10 a.m.

4.3

CVSS3.1

CVE-2026-3928 - chromium-browser: Insufficient policy enforcement in Extensions

Insufficient policy enforcement in Extensions in Google Chrome prior to 146.0.7680.71 allowed an attacker who convinced a user to install a malicious extension to perform UI spoofing via a crafted Chrome Extension. (Chromium security severity: Medium)

πŸ“… Published: March 10, 2026, midnight πŸ”„ Last Modified: April 17, 2026, 10 a.m.

6.5

CVSS3.1

CVE-2026-3938 - chromium-browser: Insufficient policy enforcement in Clipboard

Insufficient policy enforcement in Clipboard in Google Chrome prior to 146.0.7680.71 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)

πŸ“… Published: March 10, 2026, midnight πŸ”„ Last Modified: April 16, 2026, 3 a.m.

8.8

CVSS3.1

CVE-2026-3920 - chromium-browser: Out of bounds memory access in WebML

Out of bounds memory access in WebML in Google Chrome prior to 146.0.7680.71 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

πŸ“… Published: March 10, 2026, midnight πŸ”„ Last Modified: April 16, 2026, 3 a.m.

8.4

CVSS3.1

CVE-2025-70798 -

Tenda i24V3.0si V3.0.0.5 Firmware V3.0.0.5 was discovered to contain a hardcoded password vulnerability in /etc_ro/shadow, which allows attackers to log in as root.

πŸ“… Published: March 10, 2026, midnight πŸ”„ Last Modified: April 9, 2026, 8:27 p.m.

7.5

CVSS3.1

CVE-2025-70244 -

Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the webPage parameter to goform/formWlanSetup.

πŸ“… Published: March 10, 2026, midnight πŸ”„ Last Modified: March 11, 2026, 8:01 p.m.

6.5

CVSS3.1

CVE-2026-3934 - chromium-browser: Insufficient policy enforcement in ChromeDriver

Insufficient policy enforcement in ChromeDriver in Google Chrome prior to 146.0.7680.71 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium security severity: Medium)

πŸ“… Published: March 10, 2026, midnight πŸ”„ Last Modified: April 16, 2026, 3 a.m.

8.4

CVSS3.1

CVE-2025-70802 -

Tenda G1V3.1si V16.01.7.8 Firmware V16.01.7.8 was discovered to contain a hardcoded password vulnerability in /etc_ro/shadow, which allows attackers to log in as root.

πŸ“… Published: March 10, 2026, midnight πŸ”„ Last Modified: April 9, 2026, 8:27 p.m.

7.5

CVSS3.1

CVE-2026-26801 - SSRF Vulnerability in pdfmake Source Resolver Allows Remote Information Disclosure

Server-Side Request Forgery (SSRF) vulnerability in pdfmake versions 0.3.0-beta.2 through 0.3.5 allows a remote attacker to obtain sensitive information via the src/URLResolver.js component. The fix was released in version 0.3.6 which introduces the setUrlAccessPolicy() method allowing server opera…

πŸ“… Published: March 10, 2026, midnight πŸ”„ Last Modified: May 7, 2026, 8:32 p.m.

5.3

CVSS3.1

CVE-2025-70129 -

If the anti spam-captcha functionality in PluXml versions 5.8.22 and earlier is enabled, a captcha challenge is generated with a format that can be automatically recognized for articles, such that an automated script is able to solve this anti-spam mechanism trivially and publish spam comments. The…

πŸ“… Published: March 10, 2026, midnight πŸ”„ Last Modified: April 7, 2026, 1:21 a.m.
Total resulsts: 349182
Page 1231 of 34,919
Β« previous page Β» next page
Filters