Use after free in WebView in Google Chrome on Android prior to 147.0.7727.138 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
CVSSv3.1 8.8 (HIGH)
CWECWE 416TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-04-28
2026-04-28 23:16Z
CRIT
CVE-2026-7341 — Use: after free in WebRTC in Google Chrome prior to 147.0.7727.138 allowed a remote
Use after free in WebRTC in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
CVSSv3.1 9.8 (CRITICAL)
CWECWE 416TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-04-28
2026-04-28 23:16Z
HIGH
CVE-2026-7339 — Heap: buffer overflow in WebRTC in Google Chrome prior to 147.0.7727.138 allowed a remote
Heap buffer overflow in WebRTC in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
CVSSv3.1 8.8 (HIGH)
CWECWE 122VNDHeapTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-04-28
2026-04-28 23:16Z
HIGH
CVE-2026-7337 — Type: Confusion in V8 in Google Chrome prior to 147.0.7727.138 allowed a remote attacker
Type Confusion in V8 in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
CVSSv3.1 8.8 (HIGH)
CWECWE 843VNDTypeTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-04-28
2026-04-28 23:16Z
HIGH
CVE-2026-7336 — Use: after free in WebRTC in Google Chrome prior to 147.0.7727.138 allowed a remote
Use after free in WebRTC in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
CVSSv3.1 8.8 (HIGH)
CWECWE 416TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-04-28
2026-04-28 23:16Z
HIGH
CVE-2026-7335 — Use: after free in media in Google Chrome prior to 147.0.7727.138 allowed a remote
Use after free in media in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
CVSSv3.1 8.8 (HIGH)
CWECWE 416TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-04-28
2026-04-28 23:16Z
HIGH
CVE-2026-7334 — Use: after free in Views in Google Chrome on Mac prior to 147.0.7727.138 allowed
Use after free in Views in Google Chrome on Mac prior to 147.0.7727.138 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVSSv3.1 8.8 (HIGH)
CWECWE 416TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-04-28
2026-04-28 23:16Z
CRIT
CVE-2026-7333 — Use: after free in GPU in Google Chrome prior to 147.0.7727.138 allowed a remote
Use after free in GPU in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
CVSSv3.1 9.6 (CRITICAL)
CWECWE 416TYPVulnerability
9.6
CVSS v3.1
98
Edit Score
2026-04-28
2026-04-28 23:16Z
HIGH
CVE-2026-42167 — ProFTPD: mod_sql in ProFTPD before 1.3.10rc1 allows remote attackers to execute arbitrary code via a
mod_sql in ProFTPD before 1.3.10rc1 allows remote attackers to execute arbitrary code via a username, in scenarios where there is logging of USER requests with an expansion such as %U, and the SQL backend allows commands (e.g., COPY TO PROGRAM).
CVSSv3.1 8.1 (HIGH)
CWECWE 89VNDProftpdTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-04-28
2026-04-28 22:16Z
CRIT
CVE-2026-41446 — Snap: One WattBox 800 and 820 series firmware versions prior to 2.10.0.0 contain undisclosed
Snap One WattBox 800 and 820 series firmware versions prior to 2.10.0.0 contain undisclosed diagnostic HTTP endpoints that require only the device MAC address and service tag for authentication, both of which are printed in plaintext on the physical device label. Attackers with access to the device label or documentation containing these values can authenticate to the several endpoints and execute arbitrary commands as root on the device.
CVSSv3.1 9.8 (CRITICAL)
CWECWE 798CWECWE 912VNDSnapTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-04-28
2026-04-28 20:57Z
INFO
etc-collector-com — Open-source Active Directory & Entra ID security auditor. 419+ checks, ADCS ESC1-ESC11, attack paths. 6.2× faster than P
GitHub · Azure / Entra tools·github.comGITHUB POC
ETC Collector is an open-source Active Directory and Microsoft Entra ID security auditor written in Go, featuring 498+ detectors across 23 categories, ADCS ESC1-ESC11 checks, attack-path analysis, and compliance framework tagging (ANSSI, CIS, NIST, DISA, HDS, RGPD, NIS2). The tool runs as a single static binary with three modes: CLI one-shot, standalone HTTPS server with web UI, or SaaS daemon, completing full-forest audits in ~1 second with no .NET or Python dependencies.
BloodHound v9.1.0-rc2 release candidate published with incremental UI/UX improvements, bug fixes, and backend refactoring. Changes include PDF attack paths table, OpenGraph extension permissions, improved filtering, component library updates, and post-processing migrations to DCA.
SWBloodhoundTYPTool
35
Edit Score
2026-04-28
2026-04-28 19:37Z
HIGH
CVE-2026-42431 — OpenClaw: before 2026.4.8 contains a security bypass vulnerability in node.invoke(browser.proxy) that allows mutation of
OpenClaw before 2026.4.8 contains a security bypass vulnerability in node.invoke(browser.proxy) that allows mutation of persistent browser profiles. Attackers can exploit this path to circumvent the browser.request persistent profile-mutation guard and modify browser configurations.
CVSSv3.1 8.1 (HIGH)
CWECWE 863VNDOpenclawTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-04-28
2026-04-28 19:37Z
HIGH
CVE-2026-42426 — OpenClaw: Attackers with operator.write permissions can bypass pairing approval restrictions to gain unauthorized access to
OpenClaw before 2026.4.8 contains an improper authorization vulnerability where the node.pair.approve method accepts operator.write scope instead of the narrower operator.pairing scope, allowing unprivileged users to approve node pairing. Attackers with operator.write permissions can bypass pairing approval restrictions to gain unauthorized access to exec-capable nodes.
CVSSv3.1 8.8 (HIGH)
CWECWE 863VNDOpenclawTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-04-28
2026-04-28 19:37Z
HIGH
CVE-2026-42422 — OpenClaw: before 2026.4.8 contains a role bypass vulnerability in the device.token.rotate function that allows
OpenClaw before 2026.4.8 contains a role bypass vulnerability in the device.token.rotate function that allows minting tokens for unapproved roles. Attackers can bypass device role-upgrade pairing to preserve or mint roles and scopes that had not undergone intended approval.
CVSSv3.1 8.8 (HIGH)
CWECWE 863VNDOpenclawTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-04-28
2026-04-28 19:37Z
HIGH
CVE-2026-41914 — OpenClaw: before 2026.4.8 contains a server-side request forgery vulnerability in QQ Bot media download
OpenClaw before 2026.4.8 contains a server-side request forgery vulnerability in QQ Bot media download paths that bypass SSRF protection. Attackers can exploit unprotected media fetch endpoints to access internal resources and bypass allowlist policies.
CVSSv3.1 8.5 (HIGH)
CWECWE 918VNDOpenclawTYPVulnerability
8.5
CVSS v3.1
93
Edit Score
2026-04-28
2026-04-28 19:37Z
HIGH
CVE-2026-41404 — OpenClaw: before 2026.3.31 contains an incomplete scope-clearing vulnerability in trusted-proxy authentication mode that allows
OpenClaw before 2026.3.31 contains an incomplete scope-clearing vulnerability in trusted-proxy authentication mode that allows operator.admin privilege escalation. Attackers can exploit this by declaring operator scopes on non-Control-UI clients, allowing self-declared scopes to persist on identity-bearing authentication paths and escalate privileges.
CVSSv3.1 8.8 (HIGH)
CWECWE 863VNDOpenclawTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-04-28
2026-04-28 19:37Z
HIGH
CVE-2026-41394 — OpenClaw: before 2026.3.31 contains an authentication bypass vulnerability where unauthenticated plugin-auth HTTP routes receive
OpenClaw before 2026.3.31 contains an authentication bypass vulnerability where unauthenticated plugin-auth HTTP routes receive operator runtime write scopes. Attackers can access these routes without authentication to perform privileged runtime actions intended for authorized operators.
CVSSv3.1 8.2 (HIGH)
CWECWE 862VNDOpenclawTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-04-28
2026-04-28 19:37Z
CRIT
CVE-2026-41386 — OpenClaw: before 2026.3.22 contains a privilege escalation vulnerability where bootstrap setup codes are not
OpenClaw before 2026.3.22 contains a privilege escalation vulnerability where bootstrap setup codes are not bound to intended device roles and scopes during pairing. Attackers can exploit this during first-use device pairing to escalate privileges beyond their intended role and scope.
CVSSv3.1 9.1 (CRITICAL)
CWECWE 648VNDOpenclawTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-04-28
2026-04-28 19:37Z
HIGH
CVE-2026-41383 — OpenClaw: before 2026.4.2 contains an arbitrary directory deletion vulnerability in mirror mode that allows
OpenClaw before 2026.4.2 contains an arbitrary directory deletion vulnerability in mirror mode that allows attackers to delete remote directories by influencing remoteWorkspaceDir and remoteAgentWorkspaceDir configuration values. Attackers can manipulate these OpenShell config paths to cause mirror sync operations to delete unintended remote directory contents and replace them with uploaded workspace data.
CVSSv3.1 8.1 (HIGH)
CWECWE 22VNDOpenclawTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-04-28
2026-04-28 19:37Z
HIGH
CVE-2026-41378 — OpenClaw: before 2026.3.31 contains a privilege escalation vulnerability allowing paired nodes with role=node to
OpenClaw before 2026.3.31 contains a privilege escalation vulnerability allowing paired nodes with role=node to dispatch node.event agent requests with unrestricted gateway-side tool access. Attackers with trusted paired node credentials can escalate privileges by leveraging unrestricted agent.request dispatch to achieve remote code execution on the gateway.
CVSSv3.1 8.8 (HIGH)
CWECWE 862VNDOpenclawTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-04-28
2026-04-28 19:37Z
CRIT
CVE-2026-3893 — Carlson: The Carlson VASCO-B GNSS Receiver lacks an authentication mechanism, allowing an attacker with network
The Carlson VASCO-B GNSS Receiver lacks an authentication mechanism,
allowing an attacker with network access to directly access and modify
its configuration and operational functions without needing credentials.
CVSSv3.1 9.4 (CRITICAL)
CWECWE 306VNDCarlsonTYPVulnerability
9.4
CVSS v3.1
97
Edit Score
2026-04-28
2026-04-28 19:37Z
HIGH
CVE-2026-38949 — Site: Cross-Site Scripting (XSS) vulnerability exists in HTMLy version 3.1.1 in the content creation functionality
Cross-Site Scripting (XSS) vulnerability exists in HTMLy version 3.1.1 in the content creation functionality at the /add/content?type=image endpoint. The application fails to properly sanitize user input, allowing injection of arbitrary code
CVSSv3.1 8.9 (HIGH) · EPSS 6th percentile
CWECWE 79TYPVulnerability
8.9
CVSS v3.1
95
Edit Score
2026-04-28
2026-04-28 19:36Z
HIGH
CVE-2026-24222 — NVIDIA: A successful exploit of this vulnerability might lead to information disclosure.
NVIDIA NeMoClaw contains a vulnerability in the sandbox environment initialization component, where a remote attacker could cause improper access control by sending prompt-injected content that causes the agent to read and exfiltrate host environment variables not properly restricted during sandbox creation. A successful exploit of this vulnerability might lead to information disclosure.
CVSSv3.1 8.6 (HIGH)
CWECWE 497VNDNvidiaTYPVulnerability
8.6
CVSS v3.1
93
Edit Score
2026-04-28
2026-04-28 19:36Z
HIGH
CVE-2026-24186 — NVIDIA: FLARE SDK contains a vulnerability in FOBS, where an attacker may cause deserialization
NVIDIA FLARE SDK contains a vulnerability in FOBS, where an attacker may cause deserialization of untrusted data by sending a malicious FOBS- encoded message. A successful exploit of this vulnerability might lead to code execution.
CVSSv3.1 8.8 (HIGH)