7.5

CVSS3.1

CVE-2026-33806 - fastify vulnerable to Body Schema Validation Bypass via Leading Space in Content-Type Header

Impact: Fastify applications using schema.body.content for per-content-type body validation can have validation bypassed entirely by prepending a space to the Content-Type header. The body is still parsed correctly but schema validation is skipped. This is a regression introduced in fastify >= 5.…

πŸ“… Published: April 15, 2026, 12:14 a.m. πŸ”„ Last Modified: April 17, 2026, 3:49 p.m.

6.5

CVSS4.0

CVE-2026-40105 - XWiki has Reflected Cross-Site Scripting (XSS) in its page history compare functionality

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Versions 10.4-rc-1, through 16.10.15, 17.0.0-rc-1, through 17.4.7 and 17.5.0-rc-1 through 17.10.0 contain a reflected cross-site scripting vulnerability (XSS) in the comparison view between rev…

πŸ“… Published: April 15, 2026, 12:07 a.m. πŸ”„ Last Modified: April 23, 2026, 1:52 p.m.

6.9

CVSS4.0

CVE-2026-40104 - XWiki's REST APIs can list all pages/spaces, leading to unavailability

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Versions 1.8-rc-1, 17.0.0-rc-1 and 17.5.0-rc-1 and prior include a resource exhaustion vulnerability in REST API endpoints such as /xwiki/rest/wikis/xwiki/spaces/AnnotationCode/pages/AnnotationC…

πŸ“… Published: April 15, 2026, 12:01 a.m. πŸ”„ Last Modified: April 23, 2026, 1:52 p.m.

8.8

CVSS3.1

CVE-2026-6359 - chromium-browser: Use after free in Video

Use after free in Video in Google Chrome on Windows prior to 147.0.7727.101 allowed a remote attacker who had compromised the renderer process to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)

πŸ“… Published: April 15, 2026, midnight πŸ”„ Last Modified: April 17, 2026, 7:21 p.m.

7.5

CVSS3.1

CVE-2026-30364 - CentSDR Commit e40795 Stack Overflow in Thread1 Function

CentSDR commit e40795 was discovered to contain a stack overflow in the "Thread1" function.

πŸ“… Published: April 15, 2026, midnight πŸ”„ Last Modified: April 17, 2026, 3:09 p.m.

8.6

CVSS3.1

CVE-2026-30995 - SQL Injection via vereador_ver.php in Slah CMS

Slah CMS v1.5.0 and below was discovered to contain a SQL injection vulnerability via the id parameter in the vereador_ver.php endpoint.

πŸ“… Published: April 15, 2026, midnight πŸ”„ Last Modified: April 17, 2026, 3:37 p.m.

9.6

CVSS3.1

CVE-2026-6296 - chromium-browser: Heap buffer overflow in ANGLE

Heap buffer overflow in ANGLE in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)

πŸ“… Published: April 15, 2026, midnight πŸ”„ Last Modified: April 17, 2026, 3:42 p.m.

7.5

CVSS3.1

CVE-2025-67841 - Algorithmic Complexity Flaw Causing Resource Exhaustion in Nordic Semiconductor IronSide SE

Nordic Semiconductor IronSide SE for nRF54H20 before 23.0.2+17 has an Algorithmic complexity issue.

πŸ“… Published: April 15, 2026, midnight πŸ”„ Last Modified: April 17, 2026, 3:09 p.m.

7.5

CVSS3.1

CVE-2026-30994 - Unauthenticated Access to Config File Exposes Session Credentials in Slah v1.5.0 and Earlier

Incorrect access control in the config.php component of Slah v1.5.0 and below allows unauthenticated attackers to access sensitive information, including active session credentials.

πŸ“… Published: April 15, 2026, midnight πŸ”„ Last Modified: April 17, 2026, 3:37 p.m.

8.8

CVSS3.1

CVE-2026-6318 - chromium-browser: Use after free in Codecs

Use after free in Codecs in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)

πŸ“… Published: April 15, 2026, midnight πŸ”„ Last Modified: April 17, 2026, 7:08 p.m.
Total resulsts: 348624
Page 394 of 34,863
Β« previous page Β» next page
Filters