6.5

CVSS3.1

CVE-2026-5881 - chromium-browser: Policy bypass in LocalNetworkAccess

Policy bypass in LocalNetworkAccess in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Medium)

๐Ÿ“… Published: April 7, 2026, midnight ๐Ÿ”„ Last Modified: April 14, 2026, 8:01 p.m.

4.3

CVSS3.1

CVE-2026-5918 - chromium-browser: Inappropriate implementation in Navigation

Inappropriate implementation in Navigation in Google Chrome prior to 147.0.7727.55 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)

๐Ÿ“… Published: April 7, 2026, midnight ๐Ÿ”„ Last Modified: April 14, 2026, 4:37 p.m.

4.3

CVSS3.1

CVE-2026-5906 - chromium-browser: Incorrect security UI in Omnibox

Incorrect security UI in Omnibox in Google Chrome on Android prior to 147.0.7727.55 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. (Chromium security severity: Low)

๐Ÿ“… Published: April 7, 2026, midnight ๐Ÿ”„ Last Modified: April 14, 2026, 4:41 p.m.

6.1

CVSS3.1

CVE-2025-70844 -

yaffa v2.0.0 is vulnerable to Cross Site Scripting (XSS). An attacker can inject malicious JavaScript into the "Add Account Group" function on the account-group page, allowing execution of arbitrary script in the context of users who view the affected page.

๐Ÿ“… Published: April 7, 2026, midnight ๐Ÿ”„ Last Modified: April 15, 2026, 4:30 p.m.

9.8

CVSS3.1

CVE-2024-36057 -

Koha Library before 23.05.10 fails to sanitize user-controllable filenames prior to unzipping, leading to remote code execution. The line "qx/unzip $filename -d $dirname/;" in upload-cover-image.pl is vulnerable to command injection via shell metacharacters because input data can be controlled by aโ€ฆ

๐Ÿ“… Published: April 7, 2026, midnight ๐Ÿ”„ Last Modified: April 10, 2026, 9:41 a.m.

6.5

CVSS3.1

CVE-2026-5905 - chromium-browser: Incorrect security UI in Permissions

Incorrect security UI in Permissions in Google Chrome on Windows prior to 147.0.7727.55 allowed a remote attacker to perform domain spoofing via a crafted HTML page. (Chromium security severity: Low)

๐Ÿ“… Published: April 7, 2026, midnight ๐Ÿ”„ Last Modified: April 14, 2026, 4:41 p.m.

4.3

CVSS3.1

CVE-2026-5880 - chromium-browser: Incorrect security UI in browser UI

Insufficient policy enforcement in browser UI in Google Chrome prior to 147.0.7727.55 allowed a remote attacker who had compromised the renderer process to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. (Chromium security severity: Medium)

๐Ÿ“… Published: April 7, 2026, midnight ๐Ÿ”„ Last Modified: April 14, 2026, 8:01 p.m.

6.1

CVSS3.1

CVE-2026-5896 - chromium-browser: Policy bypass in Audio

Policy bypass in Audio in Google Chrome prior to 147.0.7727.55 allowed a remote attacker who convinced a user to engage in specific UI gestures to bypass sandbox download restrictions via a crafted HTML page. (Chromium security severity: Low)

๐Ÿ“… Published: April 7, 2026, midnight ๐Ÿ”„ Last Modified: April 15, 2026, 4:15 p.m.

4.3

CVSS3.1

CVE-2026-5882 - chromium-browser: Incorrect security UI in Fullscreen

Incorrect security UI in Fullscreen in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)

๐Ÿ“… Published: April 7, 2026, midnight ๐Ÿ”„ Last Modified: April 14, 2026, 8:01 p.m.

9.8

CVSS3.1

CVE-2024-36058 -

The Send Basket functionality in Koha Library before 23.05.10 is susceptible to Time-Based SQL Injection because it fails to sanitize the POST parameter bib_list in /cgi-bin/koha/opac-sendbasket.pl, allowing library users to read arbitrary data from the database.

๐Ÿ“… Published: April 7, 2026, midnight ๐Ÿ”„ Last Modified: April 10, 2026, 9:41 a.m.
Total resulsts: 349182
Page 644 of 34,919
ยซ previous page ยป next page
Filters