Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
11537
Total
770
Critical
3263
High
3665
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-5867 | UNKNOWN | — | Heap buffer overflow in WebML in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to obtain potentially sensitive information from process memory via a … | Apr 08, 2026 |
| CVE-2026-5866 | HIGH | 8.8 | Use after free in Media in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted … | Apr 08, 2026 |
| CVE-2026-5865 | UNKNOWN | — | Type Confusion in V8 in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML … | Apr 08, 2026 |
| CVE-2026-5864 | UNKNOWN | — | Heap buffer overflow in WebAudio in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to obtain potentially sensitive information from process memory via a … | Apr 08, 2026 |
| CVE-2026-5863 | UNKNOWN | — | Inappropriate implementation in V8 in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML … | Apr 08, 2026 |
| CVE-2026-5862 | UNKNOWN | — | Inappropriate implementation in V8 in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML … | Apr 08, 2026 |
| CVE-2026-5861 | UNKNOWN | — | Use after free in V8 in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted … | Apr 08, 2026 |
| CVE-2026-5860 | UNKNOWN | — | Use after free in WebRTC in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted … | Apr 08, 2026 |
| CVE-2026-5859 | UNKNOWN | — | Integer overflow in WebML in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium … | Apr 08, 2026 |
| CVE-2026-5858 | UNKNOWN | — | Heap buffer overflow in WebML in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium … | Apr 08, 2026 |
| CVE-2026-5810 | LOW | 3.5 | A flaw has been found in SourceCodester Sales and Inventory System 1.0. Affected is an unknown function of the file /delete.php of the component GET … | Apr 08, 2026 |
| CVE-2026-5808 | MEDIUM | 4.3 | A vulnerability was detected in openstatusHQ openstatus up to 1b678e71a85961ae319cbb214a8eae634059330c. This impacts an unknown function of the file apps/dashboard/src/app/(dashboard)/onboarding/client.tsx of the component Onboarding Endpoint. The … | Apr 08, 2026 |
| CVE-2026-5806 | LOW | 3.5 | A security vulnerability has been detected in code-projects Easy Blog Site 1.0. This affects an unknown function of the file /posts/update.php. The manipulation of the … | Apr 08, 2026 |
| CVE-2026-5711 | MEDIUM | 6.4 | The Post Blocks & Tools plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'sliderStyle' block attribute in the Posts Slider block in … | Apr 08, 2026 |
| CVE-2026-40037 | MEDIUM | 6.5 | OpenClaw before 2026.3.31 (patched in 2026.4.8) contains a request body replay vulnerability in fetchWithSsrFGuard that allows unsafe request bodies to be resent across cross-origin redirects. … | Apr 08, 2026 |
| CVE-2026-40036 | HIGH | 7.5 | Unfurl before 2026.04 contains an unbounded zlib decompression vulnerability in parse_compressed.py that allows remote attackers to cause denial of service. Attackers can submit highly compressed … | Apr 08, 2026 |
| CVE-2026-40035 | CRITICAL | 9.1 | Unfurl through 2025.08 contains an improper input validation vulnerability in config parsing that enables Flask debug mode by default. The debug configuration value is read … | Apr 08, 2026 |
| CVE-2026-40032 | HIGH | 7.8 | UAC (Unix-like Artifacts Collector) before 3.3.0-rc1 contains a command injection vulnerability in the placeholder substitution and command execution pipeline where the _run_command() function passes constructed … | Apr 08, 2026 |
| CVE-2026-40031 | HIGH | 7.8 | MemProcFS before 5.17 contains multiple unsafe library-loading patterns that enable DLL and shared-library hijacking across six attack surfaces, including bare-name LoadLibraryU and dlopen calls without … | Apr 08, 2026 |
| CVE-2026-40030 | HIGH | 7.8 | parseusbs before 1.9 contains an OS command injection vulnerability where the volume listing path argument (-v flag) is passed unsanitized into an os.popen() shell command … | Apr 08, 2026 |
| CVE-2026-40029 | HIGH | 7.8 | parseusbs before 1.9 contains an OS command injection vulnerability in parseUSBs.py where LNK file paths are passed unsanitized into an os.popen() shell command, allowing arbitrary … | Apr 08, 2026 |
| CVE-2026-40028 | MEDIUM | 5.4 | Hayabusa versions prior to 3.8.0 contain a cross-site scripting (XSS) vulnerability in its HTML report output that allows an attacker to execute arbitrary JavaScript when … | Apr 08, 2026 |
| CVE-2026-40027 | HIGH | 7.3 | ALEAPP (Android Logs Events And Protobuf Parser) through 3.4.0 contains a path traversal vulnerability in the NQ_Vault.py artifact parser that uses attacker-controlled file_name_from values from … | Apr 08, 2026 |
| CVE-2026-40026 | MEDIUM | 4.4 | The Sleuth Kit through 4.14.0 contains an out-of-bounds read vulnerability in the ISO9660 filesystem parser where the parse_susp() function trusts len_id, len_des, and len_src fields … | Apr 08, 2026 |
| CVE-2026-40025 | MEDIUM | 4.4 | The Sleuth Kit through 4.14.0 contains an out-of-bounds read vulnerability in the APFS filesystem keybag parser where the wrapped_key_parser class follows attacker-controlled length fields without … | Apr 08, 2026 |