| CVE-2024-11803 | Fuji Electric Tellus Lite V-Simulator 5 V8 File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Fuji Electric Tellus Lite. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of V8 files in the V-Simulator 5 component. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated data structure. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-24771. | high | |
| CVE-2026-81578 | An improper access control vulnerability exists in the web management interface of PaperCut MF and PaperCut NG. Under specific conditions, unauthenticated remote requests targeting administrative functions can trigger backend actions prior to the completion of access validation checks. This allows an unauthenticated remote attacker to modify certain system configurations. | highVulnerability of Interest | |
| CVE-2022-26905 | Microsoft Edge (Chromium-based) Spoofing Vulnerability | medium | |
| CVE-2023-21720 | Microsoft Edge (Chromium-based) Tampering Vulnerability | medium | |
| CVE-2023-36559 | Microsoft Edge (Chromium-based) Spoofing Vulnerability | medium | |
| CVE-2024-30055 | Microsoft Edge (Chromium-based) Spoofing Vulnerability | medium | |
| CVE-2024-43577 | Microsoft Edge (Chromium-based) Spoofing Vulnerability | medium | |
| CVE-2024-30058 | Microsoft Edge (Chromium-based) Spoofing Vulnerability | medium | |
| CVE-2024-38093 | Microsoft Edge (Chromium-based) Spoofing Vulnerability | medium | |
| CVE-2024-26188 | Microsoft Edge (Chromium-based) Spoofing Vulnerability | medium | |
| CVE-2014-1706 | crosh in Google Chrome OS before 33.0.1750.152 allows attackers to inject commands via unspecified vectors. | critical | |
| CVE-2021-30612 | Chromium: CVE-2021-30612 Use after free in WebRTC | high | |
| CVE-2021-30624 | Chromium: CVE-2021-30624 Use after free in Autofill | high | |
| CVE-2024-11799 | Fuji Electric Tellus Lite V-Simulator 5 V8 File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Fuji Electric Tellus Lite. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of V8 files in the V-Simulator 5 component. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-24664. | high | |
| CVE-2016-9159 | A vulnerability has been identified in SIMATIC S7-300 CPU family (All versions), SIMATIC S7-300 CPU family (incl. related ET200 CPUs and SIPLUS variants) (All versions), SIMATIC S7-400 PN/DP V6 and below CPU family (incl. SIPLUS variants) (All versions), SIMATIC S7-400 PN/DP V7 CPU family (incl. SIPLUS variants) (All versions), SIMATIC S7-400 V6 and earlier CPU family (All versions), SIMATIC S7-400 V7 CPU family (All versions), SIMATIC S7-410 V8 CPU family (All versions), SIMATIC S7-410 V8 CPU family (incl. SIPLUS variants) (All versions). An attacker with network access to port 102/tcp (ISO-TSAP) or via Profibus could obtain credentials from the PLC if protection-level 2 is configured on the affected devices. | medium | |
| CVE-2026-42799 | Out-of-bounds read vulnerability in ASR Kestrel (nr_fw modules) allows Overflow Buffers. This vulnerability is associated with program files Code/Nr/nr_fw/RA/src/NrPwrCtrl.C. This issue affects Kestrel: before 2026/02/10. | critical | |
| CVE-2026-40949 | CVE-2026-40949 is a buffer overflow vulnerability in the Secure Access Windows client prior to 14.50. Attackers with local control of the Windows client can use it to trigger a denial of service. | medium | |
| CVE-2026-55399 | CVE-2026-55399 is a resource exhaustion vulnerability in the Secure Access publisher prior to 14.55. Attackers with valid credentials to the Secure Access tunnel can create a non-persistent DoS against the publisher. | medium | |
| CVE-2026-61613 | Cursor is a code editor built for programming with AI. Prior to the Cloud Agent fix on 03/31/2026, browser-enabled Cursor Cloud Agent sessions allowed attacker-controlled web content to connect from inside the agent container to an unauthenticated local agent endpoint, enabling code execution within the affected Cloud Agent sandbox or session and access to files, repository contents, environment variables, credentials, and GitHub App access tokens available to that session. This issue was fixed on 03/31/2026 by requiring authentication for the relevant agent endpoint. | high | |
| CVE-2026-43510 | manage.get.gov is the .gov TLD registrar maintained by CISA. manage.get.gov allows an organization administrator to assign domain manager privileges for domains not already in another organization. Fixed in 1.176.0 on or around 2026-04-30. | medium | |
| CVE-2026-6343 | Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13, 11.4.x <= 11.4.3 fail to check public/private permissions which allows members without these permissions to access public playbooks via /get.. Mattermost Advisory ID: MMSA-2026-00591 | medium | |
| CVE-2026-6345 | Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13, 11.4.x <= 11.4.3 fail prevent disclosure of created user password which allows a malicious attacker to impersonate a user via the use of some of those passwords.. Mattermost Advisory ID: MMSA-2026-00614 | medium | |
| CVE-2026-21388 | Mattermost Plugins versions <=2.3.1 fail to limit the request body size on the {{/lifecycle}} webhook endpoint which allows an authenticated attacker to cause memory exhaustion and denial of service via sending an oversized JSON payload. Mattermost Advisory ID: MMSA-2026-00610 | medium | |
| CVE-2026-22545 | Mattermost versions 10.11.x <= 10.11.10 fail to validate user's authentication method when processing account auth type switch which allows an authenticated attacker to change account password without confirmation via falsely claiming a different auth provider.. Mattermost Advisory ID: MMSA-2026-00583 | low | |
| CVE-2026-54420 | LiteSpeed cPanel plugin before 2.4.8 (as distributed in LiteSpeed WHM PlugIn before 5.3.2.0) mishandles symlinks provided by a user with FTP or web shell access on a shared hosting server running CloudLinux/CageFS, as exploited in the wild in May 2026. | high | |
| CVE-2026-40953 | CVE-2026-40953 is a heap overflow in the certificate parsing function of Secure Access clients prior to 14.55. Attackers with local access and administrator permissions can create a denial of service attack against the client over which they have control. | medium | |
| CVE-2026-77642 | tor before 0.4.9.9 was prone to an out-of-bounds write when parsing a consensus or detached signature with unexpected signature digest type. Impact is minor for most Tor roles, but potentially major for directory authorities. This is TROVE-2026-019. | high | |
| CVE-2023-36354 | TP-Link TL-WR940N V4, TL-WR841N V8/V10, TL-WR740N V1/V2, TL-WR940N V2/V3, and TL-WR941ND V5/V6 were discovered to contain a buffer overflow in the component /userRpm/AccessCtrlTimeSchedRpm. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted GET request. | high | |
| CVE-2026-42600 | MinIO is a high-performance object storage system. From RELEASE.2022-07-24T01-54-52Z to before RELEASE.2026-04-14T21-32-45Z, A path traversal vulnerability in MinIO's ReadMultiple internode storage-REST endpoint allows a caller holding the cluster root JWT to read files from outside the configured drive roots, bounded only by the MinIO process UID. The attacker sends POST minio/storage/{drivePath}/v63/rmpl with a msgpack-encoded body carrying ../ sequences in the Bucket field. The server opens the resulting path via os.OpenFile with O_RDONLY|O_NOATIME and returns its contents in the msgpack response stream. This vulnerability is fixed in RELEASE.2026-04-14T21-32-45Z. | medium | |
| CVE-2021-30617 | Chromium: CVE-2021-30617 Policy bypass in Blink | medium | |
| CVE-2022-23263 | Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | high | |
| CVE-2022-26899 | Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | high | |
| CVE-2022-26909 | Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | high | |
| CVE-2022-35796 | Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | high | |
| CVE-2023-33143 | Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | high | |
| CVE-2024-21385 | Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | high | |
| CVE-2024-21388 | Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | medium | |
| CVE-2024-21399 | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | high | |
| CVE-2023-36022 | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | medium | |
| CVE-2023-36034 | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | high | |
| CVE-2023-28286 | Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability | medium | |
| CVE-2024-43472 | Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | high | |
| CVE-2024-43489 | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | high | |
| CVE-2024-43587 | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | high | |
| CVE-2024-43596 | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | high | |
| CVE-2024-43595 | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | high | |
| CVE-2026-45495 | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | critical | |
| CVE-2021-31937 | Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | high | |
| CVE-2021-36928 | Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | high | |
| CVE-2016-5179 | Chrome OS before 53.0.2785.144 allows remote attackers to execute arbitrary commands at boot. | critical | |