|
2071
|
8.1 |
HIGH
Network
|
google
|
chrome
|
Inappropriate implementation in Tint in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: Hi…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2026-7346
|
2026-05-1 03:28 |
2026-04-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2072
|
8.1 |
HIGH
Network
|
google
|
chrome
|
Use after free in Chromoting in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to execute arbitrary code via malicious network traffic. (Chromium security severity: High)
|
CWE-416
Use After Free
|
CVE-2026-7347
|
2026-05-1 03:27 |
2026-04-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2073
|
8.8 |
HIGH
Network
|
google
|
chrome
|
Use after free in Codecs in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
|
CWE-416
Use After Free
|
CVE-2026-7348
|
2026-05-1 03:27 |
2026-04-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2074
|
8.8 |
HIGH
Network
|
google
|
chrome
|
Heap buffer overflow in WebRTC in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
|
CWE-122
Heap-based Buffer Overflow
|
CVE-2026-7339
|
2026-05-1 03:26 |
2026-04-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2075
|
8.8 |
HIGH
Network
|
tenda
|
hg3_firmware
|
A vulnerability was determined in Tenda HG3 2.0. This vulnerability affects the function formTracert of the file /boaform/formTracert. Executing a manipulation of the argument datasize can lead to co…
|
CWE-74 CWE-77
Injection Command Injection
|
CVE-2026-7160
|
2026-05-1 03:23 |
2026-04-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2076
|
8.8 |
HIGH
Network
|
tenda
|
hg3_firmware
|
A vulnerability was determined in Tenda HG3 2.0. Impacted is the function formUploadConfig of the file /boaform/formIPv6Routing. This manipulation of the argument destNet causes stack-based buffer ov…
|
CWE-119 CWE-121
Incorrect Access of Indexable Resource ('Range Error') Stack-based Buffer Overflow
|
CVE-2026-7151
|
2026-05-1 03:22 |
2026-04-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2077
|
8.8 |
HIGH
Network
|
tenda
|
hg3_firmware
|
A vulnerability was detected in Tenda HG3 2.0. The impacted element is an unknown function of the file /boaform/formCountrystr. The manipulation of the argument countrystr results in os command injec…
|
CWE-77 CWE-78
Command Injection OS Command
|
CVE-2026-7119
|
2026-05-1 03:22 |
2026-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2078
|
6.5 |
MEDIUM
Adjacent
|
-
|
-
|
A flaw was found in libxml2. This vulnerability occurs when the library processes a specially crafted XML Schema Definition (XSD) validated document that includes an internal entity reference. An att…
|
CWE-843
Type Confusion
|
CVE-2026-6732
|
2026-05-1 03:16 |
2026-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2079
|
6.1 |
MEDIUM
Network
|
-
|
-
|
Cross Site Scripting vulnerability in RafyMrX TOKO-ONLINE-ROTI v.1.0 allows a remote attacker to execute arbitrary code via the detail_produk.php component
|
CWE-79
Cross-site Scripting
|
CVE-2026-38940
|
2026-05-1 03:16 |
2026-05-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2080
|
6.1 |
MEDIUM
Network
|
-
|
-
|
Cross Site Scripting vulnerability in andrewtch88 mvc-ecommerce v.1.0 allows a remote attacker to execute arbitrary code and obtain sensitive information via the product_catalogue.php component
|
CWE-79
Cross-site Scripting
|
CVE-2026-38939
|
2026-05-1 03:16 |
2026-05-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|