Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
0.0 NA
CVE-2025-56537 — Opennebula Stored XSS Vulnerability

A stored cross-site scripting (XSS) vulnerability in opennebula v6.10.0.1 and fixed in v.7.0 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the virtual…

| Cross-Site Scripting
Apr 29, 2026 Apr 29, 2026
Apr 29, 2026
Apr 29, 2026
0.0 NA
CVE-2025-56536 — Opennebula Stored XSS Vulnerability

A stored cross-site scripting (XSS) vulnerability in opennebula v6.10.0.1 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the user information parameter.

| Cross-Site Scripting
Apr 29, 2026 Apr 29, 2026
Apr 29, 2026
Apr 29, 2026
0.0 NA
CVE-2026-37555 — Libsndfile IMA ADPCM Integer Overflow Denial of Service

An issue was discovered in libsndfile 1.2.2 IMA ADPCM codec. The AIFF code path (line 241) was fixed with (sf_count_t) cast, but the WAV code path (line 235) and close path (line 167) were not. When …

| Memory Corruption
Apr 29, 2026 Apr 29, 2026
Apr 29, 2026
Apr 29, 2026
0.0 NA
CVE-2025-56535 — Opennebula XSS

A cross-site scripting (XSS) vulnerability in opennebula v6.10.0.1 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the zone attribute parameter.

| Cross-Site Scripting
Apr 29, 2026 Apr 29, 2026
Apr 29, 2026
Apr 29, 2026
0.0 NA
CVE-2025-56534 — OpenNebula Custom Authenticator Driver XSS Vulnerability

A cross-site scripting (XSS) vulnerability in the custom authenticator driver of opennebula v6.10.0.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.

| Cross-Site Scripting
Apr 29, 2026 Apr 29, 2026
Apr 29, 2026
Apr 29, 2026
0.0 NA
CVE-2026-38993 — Cockpit Directory Traversal Vulnerability

Cockpit 2.13.5 and earlier is vulnerable to directory traversal via the Buckets component. This vulnerability allows authenticated attackers to write files to arbitrary locations within the uploads d…

| Path Traversal
Apr 29, 2026 Apr 29, 2026
Apr 29, 2026
Apr 29, 2026
0.0 NA
CVE-2026-38991 — "Cockpit File Extension Filter Bypass"

Cockpit 2.13.5 and earlier is affected by a misconfiguration within the Bucket component _isFileTypeAllowed function where a specially crafted filename bypasses an extension filter. This allows an au…

| Misconfiguration
Apr 29, 2026 Apr 29, 2026
Apr 29, 2026
Apr 29, 2026
8.8 HIGH
CVE-2026-7363 — "Google Chrome Canvas Use-After-Free Vulnerability"

Use after free in Canvas in Google Chrome on Linux, ChromeOS prior to 147.0.7727.138 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security s…

chrome | Remote | Memory Corruption
Apr 28, 2026 Apr 29, 2026
Apr 28, 2026
Apr 29, 2026
8.8 HIGH
CVE-2026-7361 — Google Chrome iOS Use-After-Free Heap Corruption

Use after free in iOS in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)

chrome | Remote | Memory Corruption
Apr 28, 2026 Apr 29, 2026
Apr 28, 2026
Apr 29, 2026
3.1 LOW
CVE-2026-7360 — Google Chrome Site Isolation Bypass

Insufficient validation of untrusted input. in Compositing in Google Chrome prior to 147.0.7727.138 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a c…

chrome | Remote | Information Disclosure
Apr 28, 2026 Apr 29, 2026
Apr 28, 2026
Apr 29, 2026
0.0 NA
CVE-2026-7359 — Google Chrome ANGLE Use-After-Free Sandbox Escape

Use after free in ANGLE in Google Chrome prior to 147.0.7727.138 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (C…

chrome | Memory Corruption
Apr 28, 2026 Apr 28, 2026
Apr 28, 2026
Apr 28, 2026
0.0 NA
CVE-2026-7358 — Google Chrome Use After Free in Animation Vulnerability

Use after free in Animation in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

chrome | Memory Corruption
Apr 28, 2026 Apr 28, 2026
Apr 28, 2026
Apr 28, 2026
0.0 NA
CVE-2026-7357 — Google Chrome GPU Use-After-Free Vulnerability

Use after free in GPU in Google Chrome prior to 147.0.7727.138 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. (Chro…

chrome | Memory Corruption
Apr 28, 2026 Apr 28, 2026
Apr 28, 2026
Apr 28, 2026
0.0 NA
CVE-2026-7356 — Google Chrome Use After Free Vulnerability in Navigation

Use after free in Navigation in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)

chrome | Memory Corruption
Apr 28, 2026 Apr 28, 2026
Apr 28, 2026
Apr 28, 2026
8.8 HIGH
CVE-2026-7355 — Google Chrome Media Use-After-Free Vulnerability

Use after free in Media in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)

chrome | Remote | Memory Corruption
Apr 28, 2026 Apr 29, 2026
Apr 28, 2026
Apr 29, 2026
0.0 NA
CVE-2026-7354 — Google Chrome Angle Out-of-Bounds Write Vulnerability

Out of bounds read and write in Angle in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: …

chrome | Memory Corruption
Apr 28, 2026 Apr 28, 2026
Apr 28, 2026
Apr 28, 2026
8.3 HIGH
CVE-2026-7353 — Google Chrome Skia Heap Buffer Overflow

Heap buffer overflow in Skia in Google Chrome prior to 147.0.7727.138 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML pag…

chrome | Remote | Memory Corruption
Apr 28, 2026 Apr 29, 2026
Apr 28, 2026
Apr 29, 2026
8.3 HIGH
CVE-2026-7352 — Google Chrome Android Media Use-After-Free Sandbox Escape

Use after free in Media in Google Chrome on Android prior to 147.0.7727.138 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HT…

chrome | Remote | Memory Corruption
Apr 28, 2026 Apr 29, 2026
Apr 28, 2026
Apr 29, 2026
3.1 LOW
CVE-2026-7351 — Google Chrome MHTML Cross-Origin Data Leak Vulnerability

Race in MHTML in Google Chrome prior to 147.0.7727.138 allowed an attacker who convinced a user to install a malicious extension to leak cross-origin data via a crafted Chrome Extension. (Chromium se…

chrome | Remote | Race Condition
Apr 28, 2026 Apr 29, 2026
Apr 28, 2026
Apr 29, 2026
8.3 HIGH
CVE-2026-7350 — Google Chrome WebMIDI Use After Free Vulnerability

Use after free in WebMIDI in Google Chrome prior to 147.0.7727.138 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. …

chrome | Remote | Memory Corruption
Apr 28, 2026 Apr 29, 2026
Apr 28, 2026
Apr 29, 2026
Showing 20 of 5936 Results