6.4

CVSS3.1

CVE-2026-5711 - Post Blocks & Tools <= 1.3.0 - Authenticated (Author+) Stored Cross-Site Scripting via 'sliderStyleโ€ฆ

The Post Blocks & Tools plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'sliderStyle' block attribute in the Posts Slider block in all versions up to, and including, 1.3.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes itโ€ฆ

๐Ÿ“… Published: April 8, 2026, 9:25 p.m. ๐Ÿ”„ Last Modified: April 24, 2026, 6:04 p.m.

4.3

CVSS3.1

CVE-2026-5894 - Google Chrome: Chromium: Google Chrome/Chromium: Navigation restriction bypass via crafted HTML page

Inappropriate implementation in PDF in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Low)

๐Ÿ“… Published: April 8, 2026, 9:20 p.m. ๐Ÿ”„ Last Modified: April 14, 2026, 5:06 p.m.

9.6

CVSS3.1

CVE-2026-5874 - Google Chrome: Chromium: Google Chrome: Sandbox escape via use-after-free in PrivateAI

Use after free in PrivateAI in Google Chrome prior to 147.0.7727.55 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)

๐Ÿ“… Published: April 8, 2026, 9:20 p.m. ๐Ÿ”„ Last Modified: April 13, 2026, 5:57 p.m.

8.8

CVSS3.1

CVE-2026-5858 - Google Chrome: WebML: Chromium: Google Chrome: Arbitrary code execution via heap buffer overflow inโ€ฆ

Heap buffer overflow in WebML in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: Critical)

๐Ÿ“… Published: April 8, 2026, 9:20 p.m. ๐Ÿ”„ Last Modified: April 13, 2026, 5:24 p.m.

5.1

CVSS4.0

CVE-2026-5806 - code-projects Easy Blog Site update.php cross site scripting

A security vulnerability has been detected in code-projects Easy Blog Site 1.0. This affects an unknown function of the file /posts/update.php. The manipulation of the argument postTitle leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed publicly andโ€ฆ

๐Ÿ“… Published: April 8, 2026, 9:15 p.m. ๐Ÿ”„ Last Modified: April 24, 2026, 6:04 p.m.

5.7

CVSS3.1

CVE-2026-39901 - monetr: Protected Transactions Deletable via PUT

monetr is a budgeting application focused on planning for recurring expenses. Prior to 1.12.3, a transaction integrity flaw allows an authenticated tenant user to soft-delete synced non-manual transactions through the transaction update endpoint, despite the application explicitly blocking deletionโ€ฆ

๐Ÿ“… Published: April 8, 2026, 9:02 p.m. ๐Ÿ”„ Last Modified: April 16, 2026, 2:57 p.m.

9

CVSS3.1

CVE-2026-39860 - Nix sandbox escape: file write via symlink at FOD `.tmp` copy destination

Nix is a package manager for Linux and other Unix systems. A bug in the fix for CVE-2024-27297 allowed for arbitrary overwrites of files writable by the Nix process orchestrating the builds (typically the Nix daemon running as root in multi-user installations) by following symlinks during fixed-outโ€ฆ

๐Ÿ“… Published: April 8, 2026, 8:58 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 4:12 p.m.

6.9

CVSS4.0

CVE-2026-39892 - cryptography has a buffer overflow if non-contiguous buffers were passed to APIs

cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. From 45.0.0 to before 46.0.7, if a non-contiguous buffer was passed to APIs which accepted Python buffers (e.g. Hash.update()), this could lead to buffer overflows. This vulnerability is fixed inโ€ฆ

๐Ÿ“… Published: April 8, 2026, 8:49 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 4:12 p.m.

8.8

CVSS3.1

CVE-2026-39891 - PraisonAI has a Template Injection in Agent Tool Definitions

PraisonAI is a multi-agent teams system. Prior to 4.5.115, the create_agent_centric_tools() function returns tools (like acp_create_file) that process file content using template rendering. When user input from agent.start() is passed directly into these tools without escaping, template expressionsโ€ฆ

๐Ÿ“… Published: April 8, 2026, 8:46 p.m. ๐Ÿ”„ Last Modified: April 22, 2026, 4:51 p.m.

9.8

CVSS3.1

CVE-2026-39890 - PraisonAI Affected by Remote Code Execution via YAML Deserialization in Agent Definition Loading

PraisonAI is a multi-agent teams system. Prior to 4.5.115, the AgentService.loadAgentFromFile method uses the js-yaml library to parse YAML files without disabling dangerous tags (such as !!js/function and !!js/undefined). This allows an attacker to craft a malicious YAML file that, when parsed, exโ€ฆ

๐Ÿ“… Published: April 8, 2026, 8:45 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 5:56 p.m.
Total resulsts: 349182
Page 578 of 34,919
ยซ previous page ยป next page
Filters