CVE Feed

    Dashboard / CVE

    8.3
    High

    CVE-2026-7353

    Last Modified: 30 Apr 2026

    Heap buffer overflow in Skia in Google Chrome prior to 147.0.7727.138 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

    Published: 28 Apr 2026
    8.3
    High

    CVE-2026-7352

    Last Modified: 30 Apr 2026

    Use after free in Media in Google Chrome on Android prior to 147.0.7727.138 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

    Published: 28 Apr 2026
    3.1
    Low

    CVE-2026-7351

    Last Modified: 30 Apr 2026

    Race in MHTML in Google Chrome prior to 147.0.7727.138 allowed an attacker who convinced a user to install a malicious extension to leak cross-origin data via a crafted Chrome Extension. (Chromium security severity: High)

    Published: 28 Apr 2026
    7.5
    High

    CVE-2026-7349

    Last Modified: 30 Apr 2026

    Use after free in Cast in Google Chrome prior to 147.0.7727.138 allowed an attacker on the local network segment to execute arbitrary code inside a sandbox via malicious network traffic. (Chromium security severity: High)

    Published: 28 Apr 2026
    8.3
    High

    CVE-2026-7345

    Last Modified: 30 Apr 2026

    Insufficient validation of untrusted input in Feedback in Google Chrome prior to 147.0.7727.138 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

    Published: 28 Apr 2026
    7.5
    High

    CVE-2026-7343

    Last Modified: 30 Apr 2026

    Use after free in Views in Google Chrome on Windows prior to 147.0.7727.138 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)

    Published: 28 Apr 2026
    8.8
    High

    CVE-2026-7342

    Last Modified: 30 Apr 2026

    Use after free in WebView in Google Chrome on Android prior to 147.0.7727.138 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

    Published: 28 Apr 2026
    8.8
    High

    CVE-2026-7341

    Last Modified: 30 Apr 2026

    Use after free in WebRTC in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

    Published: 28 Apr 2026
    4.3
    Medium

    CVE-2026-7340

    Last Modified: 30 Apr 2026

    Integer overflow in ANGLE in Google Chrome on Windows prior to 147.0.7727.138 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: Medium)

    Published: 28 Apr 2026
    8.8
    High

    CVE-2026-7363

    Last Modified: 30 Apr 2026

    Use after free in Canvas in Google Chrome on Linux, ChromeOS prior to 147.0.7727.138 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Critical)

    Published: 28 Apr 2026
    8.1
    High

    CVE-2026-7347

    Last Modified: 30 Apr 2026

    Use after free in Chromoting in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to execute arbitrary code via malicious network traffic. (Chromium security severity: High)

    Published: 28 Apr 2026
    6.1
    Medium

    CVE-2026-37750

    Last Modified: 30 Apr 2026

    A reflected Cross-Site Scripting (XSS) vulnerability in School Management System by mahmoudai1 allows unauthenticated remote attackers to execute arbitrary JavaScript in victim's browsers via the unsanitized type parameter in register.php.

    Published: 28 Apr 2026
    8.8
    High

    CVE-2026-7358

    Last Modified: 30 Apr 2026

    Use after free in Animation in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

    Published: 28 Apr 2026
    8.8
    High

    CVE-2026-7361

    Last Modified: 30 Apr 2026

    Use after free in iOS in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)

    Published: 28 Apr 2026
    8.8
    High

    CVE-2026-7355

    Last Modified: 30 Apr 2026

    Use after free in Media in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)

    Published: 28 Apr 2026
    8.8
    High

    CVE-2026-7344

    Last Modified: 30 Apr 2026

    Use after free in Accessibility in Google Chrome on Windows prior to 147.0.7727.138 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)

    Published: 28 Apr 2026
    7.5
    High

    CVE-2025-67223

    Last Modified: 29 Apr 2026

    The Aranda File Server (AFS) component in Aranda Software Aranda Service Desk before 8.3.12 stores daily activity logs with predictable names in a publicly accessible directory, which allows unauthenticated remote attackers to obtain direct virtual paths of uploaded files and bypass access controls to download sensitive documents containing PII.

    Published: 28 Apr 2026
    8.3
    High

    CVE-2026-7350

    Last Modified: 30 Apr 2026

    Use after free in WebMIDI in Google Chrome prior to 147.0.7727.138 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

    Published: 28 Apr 2026
    5.9
    Medium

    CVE-2026-40355

    Last Modified: 28 Apr 2026

    In MIT Kerberos 5 (aka krb5) before 1.22.3, there is a NULL pointer dereference if an application calls gss_accept_sec_context() on a system with a NegoEx mechanism registered in /etc/gss/mech. An unauthenticated remote attacker can trigger this, causing the process to terminate in parse_nego_message.

    Published: 28 Apr 2026
    5.9
    Medium

    CVE-2026-40356

    Last Modified: 28 Apr 2026

    In MIT Kerberos 5 (aka krb5) before 1.22.3, there is an integer underflow and resultant out-of-bounds read if an application calls gss_accept_sec_context() on a system with a NegoEx mechanism registered in /etc/gss/mech. An unauthenticated remote attacker can trigger this, possibly causing the process to terminate in parse_message.

    Published: 28 Apr 2026
    5.3
    Medium

    CVE-2025-60887

    Last Modified: 29 Apr 2026

    An issue was discovered in Cista v0.15 and below. Insecure deserialization of untrusted input under certain conditions may lead to leaking of stack/heap addresses which may be used to bypass ASLR. Classes with pointer-like mechanics under the cista::raw namespace are prone to reference tampering, where Cista does not perform sufficient checks to safeguard against self-referencing pointers and referencing other data within the payload. The leak occurs if the deserialized values are observable by the attacker.

    Published: 28 Apr 2026
    8.8
    High

    CVE-2026-7339

    Last Modified: 30 Apr 2026

    Heap buffer overflow in WebRTC in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)

    Published: 28 Apr 2026
    8.2
    High

    CVE-2026-38651

    Last Modified: 18 May 2026

    Authentication Bypass vulnerability exists in Netmaker versions prior to 1.5.0. The VerifyHostToken function in logic/jwts.go fails to validate the JWT signature when verifying host tokens. An attacker can forge a JWT signed with any arbitrary key and use it to impersonate any host in the network, gaining access to sensitive information

    Published: 28 Apr 2026
    5.4
    Medium

    CVE-2026-38948

    Last Modified: 29 Apr 2026

    Cross-Site Scripting (XSS) vulnerability exists in FUEL CMS v1.5.2 and before within the asset upload functionality. The application fails to properly sanitize uploaded SVG files, allowing a low-privileged authenticated user to upload a crafted SVG file containing malicious code.

    Published: 28 Apr 2026
    8.6
    High

    CVE-2026-20766

    Last Modified: 28 Apr 2026

    An out-of-bounds memory access vulnerability exists in specific firmware versions of Milesight AIOT cameras.

    Published: 27 Apr 2026
    8.9
    High

    CVE-2026-7202

    Last Modified: 29 Apr 2026

    A vulnerability has been found in Totolink A8000RU 7.1cu.643_b20200521. This affects the function setWiFiWpsStart of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. The manipulation of the argument wscDisabled leads to os command injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 27 Apr 2026
    7.3
    High

    CVE-2026-32649

    Last Modified: 28 Apr 2026

    A command injection vulnerability exists in the web server of specific firmware versions of Milesight cameras.

    Published: 27 Apr 2026
    9.2
    Critical

    CVE-2026-32644

    Last Modified: 28 Apr 2026

    Specific firmware versions of Milesight AIOT cameras use SSL certificates with default private keys.

    Published: 27 Apr 2026
    7.7
    High

    CVE-2026-27785

    Last Modified: 28 Apr 2026

    Specific firmware versions of Milesight AIOT camera firmware contain hard-coded credentials.

    Published: 27 Apr 2026
    4.7
    Medium

    CVE-2026-40977

    Last Modified: 30 Apr 2026

    When an application is configured to use `ApplicationPidFileWriter`, a local attacker with write access to the PID file's location can corrupt one file on the host each time the application is started. Affected: Spring Boot 4.0.0–4.0.5 (fix 4.0.6), 3.5.0–3.5.13 (fix 3.5.14), 3.4.0–3.4.15 (fix 3.4.16), 3.3.0–3.3.18 (fix 3.3.19), 2.7.0–2.7.32 (fix 2.7.33); PID file / symlink behavior (`ApplicationPidFileWriter`). Versions that are no longer supported are also affected per vendor advisory.

    Published: 27 Apr 2026
    9.1
    Critical

    CVE-2026-40976

    Last Modified: 30 Apr 2026

    In certain circumstances, Spring Boot's default web security is ineffective allowing unauthorized access to all endpoints. For an application to be vulnerable, it must: be a servlet-based web application; have no Spring Security configuration of its own and rely on the default web security filter chain; depend on spring-boot-actuator-autoconfigure; not depend on spring-boot-health. If any of the above does not apply, the application is not vulnerable. Affected: Spring Boot 4.0.0–4.0.5; upgrade to 4.0.6 or later per vendor advisory.

    Published: 27 Apr 2026
    4.8
    Medium

    CVE-2026-40975

    Last Modified: 14 Aug 2026

    Values produced by ${random.value} are not suitable for use as secrets. ${random.uuid} is not affected. ${random.int} and ${random.long} should never be used for secrets as they are numeric values with a predictable range. Affected: Spring Boot 4.0.0–4.0.5 (fix 4.0.6), 3.5.0–3.5.13 (fix 3.5.14), 3.4.0–3.4.15 (fix 3.4.16), 3.3.0–3.3.18 (fix 3.3.19), 2.7.0–2.7.32 (fix 2.7.33); random value property source / weak PRNG for secrets. Versions that are no longer supported are also affected per vendor advisory.

    Published: 27 Apr 2026
    5
    Medium

    CVE-2026-40974

    Last Modified: 14 May 2026

    Spring Boot's Cassandra auto-configuration does not perform hostname verification when establishing an SSL connection to Cassandra. Affected: Spring Boot 4.0.0–4.0.5 (fix 4.0.6), 3.5.0–3.5.13 (fix 3.5.14), 3.4.0–3.4.15 (fix 3.4.16), 3.3.0–3.3.18 (fix 3.3.19), 2.7.0–2.7.32 (fix 2.7.33); Cassandra SSL auto-configuration. Versions that are no longer supported are also affected per vendor advisory.

    Published: 27 Apr 2026
    2.1
    Low

    CVE-2026-7200

    Last Modified: 28 Apr 2026

    A flaw has been found in SourceCodester Pharmacy Sales and Inventory System 1.0. Affected by this issue is some unknown functionality of the file /index.php?page=types. Executing a manipulation of the argument ID can lead to cross site scripting. It is possible to launch the attack remotely. The exploit has been published and may be used.

    Published: 27 Apr 2026
    7
    High

    CVE-2026-40973

    Last Modified: 30 Apr 2026

    A local attacker on the same host as the application may be able to take control of the directory used by `ApplicationTemp`. When `server.servlet.session.persistent` is set to `true` and the attack persists across application restarts, this may allow the attacker to read session information and hijack authenticated users or deploy a gadget chain and execute code as the application's user. Affected: Spring Boot 4.0.0–4.0.5 (fix 4.0.6), 3.5.0–3.5.13 (fix 3.5.14), 3.4.0–3.4.15 (fix 3.4.16), 3.3.0–3.3.18 (fix 3.3.19), 2.7.0–2.7.32 (fix 2.7.33); predictable temp directory / `ApplicationTemp` ownership verification. Versions that are no longer supported are also affected per vendor advisory.

    Published: 27 Apr 2026
    6.9
    Medium

    CVE-2026-41372

    Last Modified: 28 Apr 2026

    OpenClaw before 2026.4.2 fails to normalize trailing-dot localhost hosts in remote CDP discovery responses, allowing bypass of loopback protections. Attackers can craft hostile discovery responses returning localhost. to retarget authenticated browser control toward localhost endpoints and expose browser state.

    Published: 27 Apr 2026
    8.4
    High

    CVE-2026-41371

    Last Modified: 28 Apr 2026

    OpenClaw before 2026.3.28 contains a privilege escalation vulnerability in chat.send that allows write-scoped gateway callers to trigger admin-only session reset operations. Attackers can rotate target sessions, archive prior transcript state, and force new session IDs without requiring admin scope by exploiting improper authorization checks in the chat.send path.

    Published: 27 Apr 2026
    7.1
    High

    CVE-2026-41370

    Last Modified: 29 Apr 2026

    OpenClaw before 2026.3.31 contains a path traversal vulnerability in ACP dispatch that allows attackers to read arbitrary files by manipulating inbound channel attachment paths. Remote attackers can bypass attachment-cache and root directory checks to access files outside intended directories.

    Published: 27 Apr 2026
    7.1
    High

    CVE-2026-41369

    Last Modified: 28 Apr 2026

    OpenClaw before 2026.3.31 contains insufficient environment variable sanitization in host exec operations, failing to filter package, registry, Docker, compiler, and TLS override variables. Attackers can exploit this by injecting malicious environment variables to override critical system configurations and compromise host execution integrity.

    Published: 27 Apr 2026
    7.1
    High

    CVE-2026-41368

    Last Modified: 27 Apr 2026

    OpenClaw before 2026.3.28 contains an environment variable disclosure vulnerability in the jq safe-bin policy that fails to block the $ENV filter. Attackers can bypass safe-bin restrictions by using $ENV in jq programs to access sensitive environment variables that should be restricted.

    Published: 27 Apr 2026
    5.3
    Medium

    CVE-2026-41367

    Last Modified: 28 Apr 2026

    OpenClaw versions 2026.2.14 through 2026.3.24 fail to consistently apply guild and channel policy gates to Discord button and component interactions. Attackers can trigger privileged component actions from blocked contexts by bypassing channel policy enforcement.

    Published: 27 Apr 2026
    6
    Medium

    CVE-2026-41366

    Last Modified: 28 Apr 2026

    OpenClaw before 2026.3.31 contains a local roots self-whitelisting vulnerability in appendLocalMediaParentRoots that allows model-initiated arbitrary host file read. Attackers can exploit improper media parent directory validation to exfiltrate credentials and access sensitive files.

    Published: 27 Apr 2026
    5.3
    Medium

    CVE-2026-41365

    Last Modified: 28 Apr 2026

    OpenClaw before 2026.3.31 contains a sender allowlist bypass vulnerability in MS Teams thread history fetched via Graph API. Attackers can retrieve thread messages that should be filtered by sender allowlists, bypassing message filtering restrictions.

    Published: 27 Apr 2026
    7.2
    High

    CVE-2026-41364

    Last Modified: 29 Apr 2026

    OpenClaw before 2026.3.31 contains a symlink following vulnerability in SSH sandbox tar upload that allows remote attackers to write arbitrary files. Attackers can exploit this by uploading tar archives containing symlinks to escape the sandbox and overwrite files on the remote host.

    Published: 27 Apr 2026
    6
    Medium

    CVE-2026-41363

    Last Modified: 28 Apr 2026

    OpenClaw versions 2026.2.6 through 2026.3.24 contain a path traversal vulnerability in the Feishu extension resolveUploadInput function that bypasses file-system sandbox restrictions. Attackers can exploit improper path resolution during upload_image operations to read arbitrary files outside configured localRoots boundaries.

    Published: 27 Apr 2026
    2.3
    Low

    CVE-2026-41362

    Last Modified: 26 May 2026

    OpenClaw versions 2026.2.19 before 2026.3.31 contain an improper cache isolation vulnerability in the Zalo webhook replay-dedupe mechanism that is shared across authenticated webhook targets. Attackers controlling one authenticated Zalo webhook path in multi-account deployments can suppress legitimate events on different accounts by matching event_name and message_id parameters.

    Published: 27 Apr 2026
    7.5
    High

    CVE-2026-40972

    Last Modified: 30 Apr 2026

    An attacker on the same network as the remote application may be able to utilize a timing attack to discover information about the remote secret. In extreme circumstances this could result in the attacker determining the secret and uploading changed classes, thereby achieving remote code execution in the remote application. Affected: Spring Boot 4.0.0–4.0.5 (fix 4.0.6), 3.5.0–3.5.13 (fix 3.5.14), 3.4.0–3.4.15 (fix 3.4.16), 3.3.0–3.3.18 (fix 3.3.19), 2.7.0–2.7.32 (fix 2.7.33); DevTools remote secret comparison. Versions that are no longer supported are also affected per vendor advisory.

    Published: 27 Apr 2026
    5.5
    Medium

    CVE-2026-7199

    Last Modified: 28 Apr 2026

    A vulnerability was detected in SourceCodester Pharmacy Sales and Inventory System 1.0. Affected by this vulnerability is an unknown functionality of the file /ajax.php?action=delete_product. Performing a manipulation of the argument ID results in sql injection. It is possible to initiate the attack remotely. The exploit is now public and may be used.

    Published: 27 Apr 2026
    2.1
    Low

    CVE-2026-7196

    Last Modified: 28 Apr 2026

    A security vulnerability has been detected in CodeAstro Online Classroom 1.0. Affected is an unknown function of the file /guestdetails. Such manipulation of the argument deleteid leads to sql injection. The attack may be performed from remote. The exploit has been disclosed publicly and may be used.

    Published: 27 Apr 2026
    5
    Medium

    CVE-2026-40971

    Last Modified: 14 May 2026

    When configured to use an SSL bundle, Spring Boot's RabbitMQ auto-configuration does not perform hostname verification when connecting to the RabbitMQ broker. Affected: Spring Boot 4.0.0–4.0.5 (fix 4.0.6), 3.5.0–3.5.13 (fix 3.5.14) per vendor advisory.

    Published: 27 Apr 2026