Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
4.3 MEDIUM
CVE-2026-7340 — Google Chrome ANGLE Integer Overflow Memory Read

Integer overflow in ANGLE in Google Chrome on Windows prior to 147.0.7727.138 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: M…

chrome | Remote | Memory Corruption
Apr 28, 2026 Apr 30, 2026
Apr 28, 2026
Apr 30, 2026
8.8 HIGH
CVE-2026-7339 — Google Chrome WebRTC Heap Buffer Overflow Vulnerability

Heap buffer overflow in WebRTC in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)

chrome | Remote | Memory Corruption
Apr 28, 2026 Apr 30, 2026
Apr 28, 2026
Apr 30, 2026
7.5 HIGH
CVE-2026-7338 — Google Chrome Use After Free Heap Corruption Vulnerability

Use after free in Cast in Google Chrome prior to 147.0.7727.138 allowed an attacker on the local network segment to potentially exploit heap corruption via malicious network traffic. (Chromium securi…

chrome | Memory Corruption
Apr 28, 2026 Apr 30, 2026
Apr 28, 2026
Apr 30, 2026
8.8 HIGH
CVE-2026-7337 — Google Chrome V8 Type Confusion Arbitrary Code Execution

Type Confusion in V8 in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

chrome | Remote | Memory Corruption
Apr 28, 2026 Apr 30, 2026
Apr 28, 2026
Apr 30, 2026
8.8 HIGH
CVE-2026-7336 — Google Chrome WebRTC Use-After-Free Arbitrary Code Execution

Use after free in WebRTC in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

chrome | Remote | Memory Corruption
Apr 28, 2026 Apr 30, 2026
Apr 28, 2026
Apr 30, 2026
8.8 HIGH
CVE-2026-7335 — Google Chrome Use After Free in Media

Use after free in media in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

chrome | Remote | Memory Corruption
Apr 28, 2026 Apr 30, 2026
Apr 28, 2026
Apr 30, 2026
8.8 HIGH
CVE-2026-7334 — Google Chrome Views Use After Free Heap Corruption Vulnerability

Use after free in Views in Google Chrome on Mac prior to 147.0.7727.138 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

chrome | Remote | Memory Corruption
Apr 28, 2026 Apr 30, 2026
Apr 28, 2026
Apr 30, 2026
9.6 CRITICAL
CVE-2026-7333 — Google Chrome GPU Use-After-Free Vulnerability

Use after free in GPU in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

chrome | Remote | Memory Corruption
Apr 28, 2026 Apr 30, 2026
Apr 28, 2026
Apr 30, 2026
8.1 HIGH
CVE-2026-42167 — ProFTPD mod_sql Remote Code Execution Vulnerability

mod_sql in ProFTPD before 1.3.10rc1 allows remote attackers to execute arbitrary code via a username, in scenarios where there is logging of USER requests with an expansion such as %U, and the SQL ba…

proftpd | Remote | Injection
Apr 28, 2026 Apr 29, 2026
Apr 28, 2026
Apr 29, 2026
7.5 HIGH
CVE-2026-7319 — elinsky execution-system-mcp add_action Tool server.py _get_context_file_path path traver…

A flaw has been found in elinsky execution-system-mcp 0.1.0. The impacted element is the function _get_context_file_path of the file src/execution_system_mcp/server.py of the component add_action Too…

Remote | Path Traversal
Apr 28, 2026 Apr 29, 2026
Apr 28, 2026
Apr 29, 2026
5.9 MEDIUM
CVE-2026-7318 — elie mcp-project research_server.py search_papers path traversal

A vulnerability was detected in elie mcp-project 0.1.0. The affected element is the function search_papers of the file research_server.py. The manipulation of the argument topic results in path trave…

| Path Traversal
Apr 28, 2026 Apr 29, 2026
Apr 28, 2026
Apr 29, 2026
5.0 MEDIUM
CVE-2026-7317 — Grav CMS Cache Value FileCache.php doGet deserialization

A vulnerability was found in Grav CMS up to 1.7.49.5/2.0.0-beta.1. Affected by this vulnerability is the function FileCache::doGet of the file system/src/Grav/Framework/Cache/Adapter/FileCache.php of…

Remote | Information Disclosure
Apr 28, 2026 Apr 29, 2026
Apr 28, 2026
Apr 29, 2026
7.5 HIGH
CVE-2026-7316 — eiliyaabedini aider-mcp code_with_ai aider_mcp.py command injection

A vulnerability has been found in eiliyaabedini aider-mcp up to 667b914301aada695aab0e46d1fb3a7d5e32c8af. Affected is an unknown function of the file aider_mcp.py of the component code_with_ai. The m…

Remote | Injection
Apr 28, 2026 Apr 29, 2026
Apr 28, 2026
Apr 29, 2026
7.5 HIGH
CVE-2026-7315 — eiceblue spire-pdf-mcp-server PDF File server.py get_pdf_path path traversal

A flaw has been found in eiceblue spire-pdf-mcp-server 0.1.1. This impacts the function get_pdf_path of the file src/spire_pdf_mcp/server.py of the component PDF File Handler. Executing a manipulatio…

Remote | Path Traversal
Apr 28, 2026 Apr 29, 2026
Apr 28, 2026
Apr 29, 2026
7.5 HIGH
CVE-2026-7314 — eiceblue spire-doc-mcp-server base.py get_doc_path path traversal

A vulnerability was detected in eiceblue spire-doc-mcp-server 1.0.0. This affects the function get_doc_path of the file src/spire_doc_mcp/api/base.py. Performing a manipulation of the argument docume…

Remote | Path Traversal
Apr 28, 2026 Apr 29, 2026
Apr 28, 2026
Apr 29, 2026
6.3 MEDIUM
CVE-2026-7306 — Xuxueli xxl-job OpenAPI Endpoint OpenApiController.java hard-coded key

A security vulnerability has been detected in Xuxueli xxl-job up to 3.3.2. The impacted element is an unknown function of the file xxl-job-admin/src/main/java/com/xxl/job/admin/scheduler/openapi/Open…

xxl-job | Remote | Cryptography
Apr 28, 2026 Apr 29, 2026
Apr 28, 2026
Apr 29, 2026
6.5 MEDIUM
CVE-2026-7305 — Xuxueli xxl-job trigger Endpoint XxlJobServiceImpl.java triggerJob server-side request fo…

A weakness has been identified in Xuxueli xxl-job up to 3.3.2. The affected element is the function triggerJob of the file xxl-job-admin/src/main/java/com/xxl/job/admin/service/impl/XxlJobServiceImpl…

xxl-job | Remote | Server-Side Request Forgery
Apr 28, 2026 Apr 29, 2026
Apr 28, 2026
Apr 29, 2026
6.3 MEDIUM
CVE-2026-7303 — Xuxueli xxl-job Execution Log JobLogController.java logDetailCat resource injection

A security flaw has been discovered in Xuxueli xxl-job up to 3.3.2. Impacted is the function logDetailCat of the file xxl-job-admin/src/main/java/com/xxl/job/admin/controller/biz/JobLogController.jav…

xxl-job | Remote | Path Traversal
Apr 28, 2026 Apr 29, 2026
Apr 28, 2026
Apr 29, 2026
4.8 MEDIUM
CVE-2026-7297 — SourceCodester Pizzafy Ecommerce System ajax.php save_user cross site scripting

A vulnerability was determined in SourceCodester Pizzafy Ecommerce System 1.0. This vulnerability affects the function save_user of the file /admin/ajax.php?action=save_user. Executing a manipulation…

Remote | Cross-Site Scripting
Apr 28, 2026 Apr 29, 2026
Apr 28, 2026
Apr 29, 2026
4.8 MEDIUM
CVE-2026-7296 — SourceCodester Pizzafy Ecommerce System ajax.php save_order cross site scripting

A vulnerability was found in SourceCodester Pizzafy Ecommerce System 1.0. This affects the function save_order of the file /admin/ajax.php?action=save_order. Performing a manipulation of the argument…

Remote | Cross-Site Scripting
Apr 28, 2026 Apr 29, 2026
Apr 28, 2026
Apr 29, 2026
Showing 20 of 5889 Results