Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
8.8 HIGH
CVE-2026-5871 — Google Chrome V8 Type Confusion Arbitrary Code Execution

Type Confusion in V8 in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

linux_kernel chrome macos windows edge_chromium | Remote | Memory Corruption
Apr 08, 2026 Apr 13, 2026
Apr 08, 2026
Apr 13, 2026
8.8 HIGH
CVE-2026-5870 — Google Chrome Skia Integer Overflow

Integer overflow in Skia in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

linux_kernel chrome macos windows edge_chromium | Remote | Memory Corruption
Apr 08, 2026 Apr 13, 2026
Apr 08, 2026
Apr 13, 2026
6.5 MEDIUM
CVE-2026-5869 — Google Chrome Heap Buffer Overflow Vulnerability

Heap buffer overflow in WebML in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium secu…

linux_kernel chrome macos windows edge_chromium | Remote | Memory Corruption
Apr 08, 2026 Apr 14, 2026
Apr 08, 2026
Apr 14, 2026
8.8 HIGH
CVE-2026-5868 — Google Chrome ANGLE Heap Buffer Overflow Vulnerability

Heap buffer overflow in ANGLE in Google Chrome on Mac prior to 147.0.7727.55 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity:…

chrome macos edge_chromium | Remote | Memory Corruption
Apr 08, 2026 Apr 13, 2026
Apr 08, 2026
Apr 13, 2026
6.5 MEDIUM
CVE-2026-5867 — Google Chrome Heap Buffer Overflow Vulnerability

Heap buffer overflow in WebML in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium secu…

linux_kernel chrome macos windows edge_chromium | Remote | Memory Corruption
Apr 08, 2026 Apr 14, 2026
Apr 08, 2026
Apr 14, 2026
8.8 HIGH
CVE-2026-5866 — Google Chrome Use After Free Remote Code Execution

Use after free in Media in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

linux_kernel chrome macos windows edge_chromium | Remote | Memory Corruption
Apr 08, 2026 Apr 13, 2026
Apr 08, 2026
Apr 13, 2026
8.8 HIGH
CVE-2026-5865 — Google Chrome V8 Type Confusion Vulnerability

Type Confusion in V8 in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

linux_kernel chrome macos windows edge_chromium | Remote | Memory Corruption
Apr 08, 2026 Apr 13, 2026
Apr 08, 2026
Apr 13, 2026
6.5 MEDIUM
CVE-2026-5864 — Google Chrome Heap Buffer Overflow

Heap buffer overflow in WebAudio in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium s…

linux_kernel chrome macos windows edge_chromium | Remote | Memory Corruption
Apr 08, 2026 Apr 14, 2026
Apr 08, 2026
Apr 14, 2026
8.8 HIGH
CVE-2026-5863 — Google Chrome V8 Sandbox Code Execution Vulnerability

Inappropriate implementation in V8 in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: H…

linux_kernel chrome macos windows edge_chromium | Remote | Memory Corruption
Apr 08, 2026 Apr 13, 2026
Apr 08, 2026
Apr 13, 2026
8.8 HIGH
CVE-2026-5862 — Google Chrome V8 HTML Sandbox Code Execution Vulnerability

Inappropriate implementation in V8 in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: H…

linux_kernel chrome macos windows edge_chromium | Remote | Memory Corruption
Apr 08, 2026 Apr 13, 2026
Apr 08, 2026
Apr 13, 2026
8.8 HIGH
CVE-2026-5861 — Google Chrome V8 Use-After-Free Vulnerability

Use after free in V8 in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

linux_kernel chrome macos windows edge_chromium | Remote | Memory Corruption
Apr 08, 2026 Apr 13, 2026
Apr 08, 2026
Apr 13, 2026
8.8 HIGH
CVE-2026-5860 — Google Chrome WebRTC Use After Free Arbitrary Code Execution

Use after free in WebRTC in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

linux_kernel chrome macos windows edge_chromium | Remote | Memory Corruption
Apr 08, 2026 Apr 13, 2026
Apr 08, 2026
Apr 13, 2026
8.8 HIGH
CVE-2026-5859 — Google Chrome WebML Integer Overflow

Integer overflow in WebML in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)

linux_kernel chrome macos windows edge_chromium | Remote | Memory Corruption
Apr 08, 2026 Apr 13, 2026
Apr 08, 2026
Apr 13, 2026
8.8 HIGH
CVE-2026-5858 — Google Chrome Heap Buffer Overflow Vulnerability

Heap buffer overflow in WebML in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: Critical)

linux_kernel chrome macos windows edge_chromium | Remote | Memory Corruption
Apr 08, 2026 Apr 13, 2026
Apr 08, 2026
Apr 13, 2026
5.1 MEDIUM
CVE-2026-5810 — SourceCodester Sales and Inventory System GET Parameter delete.php cross site scripting

A flaw has been found in SourceCodester Sales and Inventory System 1.0. Affected is an unknown function of the file /delete.php of the component GET Parameter Handler. This manipulation of the argume…

sales_and_inventory_system | Remote | Cross-Site Scripting
Apr 08, 2026 Apr 13, 2026
Apr 08, 2026
Apr 13, 2026
5.3 MEDIUM
CVE-2026-5808 — openstatusHQ openstatus Onboarding Endpoint client.tsx cross site scripting

A vulnerability was detected in openstatusHQ openstatus up to 1b678e71a85961ae319cbb214a8eae634059330c. This impacts an unknown function of the file apps/dashboard/src/app/(dashboard)/onboarding/clie…

Remote | Cross-Site Scripting
Apr 08, 2026 Apr 13, 2026
Apr 08, 2026
Apr 13, 2026
5.1 MEDIUM
CVE-2026-5806 — code-projects Easy Blog Site update.php cross site scripting

A security vulnerability has been detected in code-projects Easy Blog Site 1.0. This affects an unknown function of the file /posts/update.php. The manipulation of the argument postTitle leads to cro…

Remote | Cross-Site Scripting
Apr 08, 2026 Apr 13, 2026
Apr 08, 2026
Apr 13, 2026
6.4 MEDIUM
CVE-2026-5711 — Post Blocks & Tools <= 1.3.0 - Authenticated (Author+) Stored Cross-Site Scripting via 's…

The Post Blocks & Tools plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'sliderStyle' block attribute in the Posts Slider block in all versions up to, and including, 1.3.0 d…

Remote | Cross-Site Scripting
Apr 08, 2026 Apr 13, 2026
Apr 08, 2026
Apr 13, 2026
7.1 HIGH
CVE-2026-40037 — OpenClaw < 2026.3.31 - Unsafe Request Body Replay via fetchWithSsrFGuard Cross-Origin Red…

OpenClaw before 2026.3.31 (patched in 2026.4.8) contains a request body replay vulnerability in fetchWithSsrFGuard that allows unsafe request bodies to be resent across cross-origin redirects. Attack…

openclaw | Remote | Server-Side Request Forgery
Apr 08, 2026 Apr 13, 2026
Apr 08, 2026
Apr 13, 2026
8.7 HIGH
CVE-2026-40036 — Unfurl < 2026.04 - Denial of Service via Unbounded zlib Decompression

Unfurl before 2026.04 contains an unbounded zlib decompression vulnerability in parse_compressed.py that allows remote attackers to cause denial of service. Attackers can submit highly compressed pay…

unfurl | Remote | Denial of Service
Apr 08, 2026 Apr 17, 2026
Apr 08, 2026
Apr 17, 2026
Showing 20 of 6193 Results