|
451
|
8.8 |
HIGH
Network
|
google
|
chrome
|
Use after free in WebView in Google Chrome on Android prior to 147.0.7727.138 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity…
New
|
CWE-416
Use After Free
|
CVE-2026-7342
|
2026-05-1 01:36 |
2026-04-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
452
|
7.5 |
HIGH
Network
|
google
|
chrome
|
Use after free in Views in Google Chrome on Windows prior to 147.0.7727.138 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HT…
New
|
CWE-416
Use After Free
|
CVE-2026-7343
|
2026-05-1 01:36 |
2026-04-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
453
|
8.8 |
HIGH
Network
|
google
|
chrome
|
Use after free in Accessibility in Google Chrome on Windows prior to 147.0.7727.138 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a cr…
New
|
CWE-416
Use After Free
|
CVE-2026-7344
|
2026-05-1 01:36 |
2026-04-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
454
|
8.3 |
HIGH
Network
|
google
|
chrome
|
Insufficient validation of untrusted input in Feedback in Google Chrome prior to 147.0.7727.138 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox esc…
New
|
CWE-20
Improper Input Validation
|
CVE-2026-7345
|
2026-05-1 01:36 |
2026-04-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
455
|
8.8 |
HIGH
Network
|
tenda
|
hg3_firmware
|
A security flaw has been discovered in Tenda HG3 2.0 300003070. This vulnerability affects the function formgponConf of the file /boaform/admin/formgponConf. The manipulation of the argument fmgpon_l…
Update
|
CWE-77 CWE-78
Command Injection OS Command
|
CVE-2026-7096
|
2026-05-1 01:18 |
2026-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
456
|
4.8 |
MEDIUM
Network
|
-
|
-
|
Improper Certificate Validation via Global SSL Context Downgrade in Apache Storm Prometheus Reporter
Versions Affected: from 2.6.3 to 2.8.6
Description:
In production deployments where an admin…
Update
|
CWE-295
Improper Certificate Validation
|
CVE-2026-40557
|
2026-05-1 01:16 |
2026-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
457
|
9.8 |
CRITICAL
Network
|
-
|
-
|
Cockpit v2.13.5 and earlier is vulnerable to arbitrary code execution via the filter parameter within multiple endpoints. This vulnerability allows an attacker to run system commands on the underlyin…
New
|
CWE-94
Code Injection
|
CVE-2026-38992
|
2026-05-1 01:16 |
2026-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
458
|
7.5 |
HIGH
Network
|
-
|
-
|
U-SPEED N300 router V1.0.0 does not implement rate limiting or account lockout protections on the /api/login endpoint. This allows an attacker on the local network to perform unlimited authentication…
New
|
CWE-307
mproper Restriction of Excessive Authentication Attempts
|
CVE-2026-36959
|
2026-05-1 01:16 |
2026-05-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
459
|
7.5 |
HIGH
Network
|
-
|
-
|
A denial-of-service vulnerability exists in the U-SPEED N300 V1.0.0 wireless router. By sending a large number of concurrent HTTP requests to random or non-existent endpoints on the web management in…
New
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2026-36958
|
2026-05-1 01:16 |
2026-05-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
460
|
7.5 |
HIGH
Network
|
-
|
-
|
Dbit N300 T1 Pro Easy Setup Wireless Wi-Fi Router V1.0.0 is vulnerable to Denial of Service via the boa web server URI handler. By initiating a high-volume flood of HTTP GET requests to non-existent …
New
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2026-36957
|
2026-05-1 01:16 |
2026-05-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|