6.8

CVSS3.1

CVE-2026-5893 - chromium-browser: Race in V8

Race in V8 in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)

πŸ“… Published: April 7, 2026, midnight πŸ”„ Last Modified: April 14, 2026, 3:55 a.m.

8.8

CVSS3.1

CVE-2026-5879 - chromium-browser: Insufficient validation of untrusted input in ANGLE

Insufficient validation of untrusted input in ANGLE in Google Chrome on Mac prior to 147.0.7727.55 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)

πŸ“… Published: April 7, 2026, midnight πŸ”„ Last Modified: April 13, 2026, 5:40 p.m.

8.8

CVSS3.1

CVE-2026-5872 - chromium-browser: Use after free in Blink

Use after free in Blink in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

πŸ“… Published: April 7, 2026, midnight πŸ”„ Last Modified: April 13, 2026, 6:06 p.m.

4.3

CVSS3.1

CVE-2026-5889 - chromium-browser: Cryptographic Flaw in PDFium

Cryptographic Flaw in PDFium in Google Chrome prior to 147.0.7727.55 allowed an attacker to read potentially sensitive information from encrypted PDFs via a brute-force attack. (Chromium security severity: Medium)

πŸ“… Published: April 7, 2026, midnight πŸ”„ Last Modified: April 14, 2026, 11:45 a.m.

5.3

CVSS4.0

CVE-2026-5705 - code-projects Online Hotel Booking Booking Endpoint booknow.php cross site scripting

A vulnerability was identified in code-projects Online Hotel Booking 1.0. Affected by this vulnerability is an unknown functionality of the file /booknow.php of the component Booking Endpoint. Such manipulation of the argument roomname leads to cross site scripting. It is possible to launch the att…

πŸ“… Published: April 6, 2026, 11:30 p.m. πŸ”„ Last Modified: April 8, 2026, 2:10 p.m.

6.9

CVSS4.0

CVE-2026-5692 - Totolink A7100RU cstecgi.cgi setGameSpeedCfg os command injection

A vulnerability was found in Totolink A7100RU 7.4cu.2313_b20191024. This impacts the function setGameSpeedCfg of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument enable results in os command injection. The attack may be performed from remote. The exploit has been made public and coul…

πŸ“… Published: April 6, 2026, 11:15 p.m. πŸ”„ Last Modified: April 21, 2026, 11:30 p.m.

6.9

CVSS4.0

CVE-2026-5691 - Totolink A7100RU cstecgi.cgi setFirewallType os command injection

A vulnerability has been found in Totolink A7100RU 7.4cu.2313_b20191024. This affects the function setFirewallType of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument firewallType leads to os command injection. The attack is possible to be carried out remotely. The exploit has been d…

πŸ“… Published: April 6, 2026, 11 p.m. πŸ”„ Last Modified: April 7, 2026, 4:24 p.m.

6.9

CVSS4.0

CVE-2026-5690 - Totolink A7100RU cstecgi.cgi setRemoteCfg os command injection

A flaw has been found in Totolink A7100RU 7.4cu.2313_b20191024. The impacted element is the function setRemoteCfg of the file /cgi-bin/cstecgi.cgi. Executing a manipulation of the argument enable can lead to os command injection. The attack can be executed remotely. The exploit has been published a…

πŸ“… Published: April 6, 2026, 10:45 p.m. πŸ”„ Last Modified: April 21, 2026, 11:30 p.m.

6.9

CVSS4.0

CVE-2026-5689 - Totolink A7100RU cstecgi.cgi setNtpCfg os command injection

A vulnerability was detected in Totolink A7100RU 7.4cu.2313_b20191024. The affected element is the function setNtpCfg of the file /cgi-bin/cstecgi.cgi. Performing a manipulation of the argument tz results in os command injection. Remote exploitation of the attack is possible. The exploit is now pub…

πŸ“… Published: April 6, 2026, 10:30 p.m. πŸ”„ Last Modified: April 22, 2026, 3:45 a.m.

6.9

CVSS4.0

CVE-2026-5688 - Totolink A7100RU cstecgi.cgi setDdnsCfg os command injection

A security vulnerability has been detected in Totolink A7100RU 7.4cu.2313_b20191024. Impacted is the function setDdnsCfg of the file /cgi-bin/cstecgi.cgi. Such manipulation of the argument provider leads to os command injection. The attack may be launched remotely. The exploit has been disclosed pu…

πŸ“… Published: April 6, 2026, 10:15 p.m. πŸ”„ Last Modified: April 8, 2026, 2:09 p.m.
Total resulsts: 349182
Page 651 of 34,919
Β« previous page Β» next page
Filters