2026-04-15
2026-04-15 23:16Z
HIGH

CVE-2026-40316 — Owasp Owasp_blt: Versions prior to 2.1.1 contain an RCE vulnerability in the .github/workflows/regenerate-migrations.yml workflow.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-40316

OWASP BLT is a QA testing and vulnerability disclosure platform that encompasses websites, apps, git repositories, and more. Versions prior to 2.1.1 contain an RCE vulnerability in the .github/workflows/regenerate-migrations.yml workflow. The workflow uses the pull_request_target trigger to run with full GITHUB_TOKEN write permissions, copies attacker-controlled files from untrusted pull requests into the trusted runner workspace via git show, and then executes python manage. CVSSv3.1 8.8 (HIGH) · EPSS 20th percentile

CWECWE 94CWECWE 95VNDOwaspTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-04-15
2026-04-15 22:17Z
CRIT

CVE-2026-6388 — ArgoCD: This vulnerability allows an attacker, with permissions to create or modify an ImageUpdater resource

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-6388

A flaw was found in ArgoCD Image Updater. This vulnerability allows an attacker, with permissions to create or modify an ImageUpdater resource in a multi-tenant environment, to bypass namespace boundaries. By exploiting insufficient validation, the attacker can trigger unauthorized image updates on applications managed by other tenants. This leads to cross-namespace privilege escalation, impacting application integrity through unauthorized application updates. CVSSv3.1 9.1 (CRITICAL)

CWECWE 1220VNDArgocdTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-04-15
2026-04-15 22:00Z
MED

Obfuscation vs the Optimizer: An LLVM Middle-End Arms Race

Quarkslab·blog.quarkslab.com

Quarkslab research demonstrates how LLVM compiler optimizations progressively defeat code obfuscation techniques, specifically showing how a single commit in LLVM 19 (implementing De Morgan's Law in InstCombine) collapsed Mixed Boolean Arithmetic (MBA) obfuscation that survived LLVM 18. The post traces an arms race between obfuscators and optimizers, illustrating that obfuscation resilience has an expiration date as compiler middle-end passes evolve.

SRFApplicationVNDClangVNDLlvmTYPResearchTYPTechniqueSTGDefense EvasionTECT1027TECT1027.001
72
Edit Score
2026-04-15
2026-04-15 21:17Z
HIGH

CVE-2026-40261 — Getcomposer Composer: Versions 1.0 through 2.2.26 and 2.3 through 2.9.5 contain a command injection vulnerability in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-40261

Composer is a dependency manager for PHP. Versions 1.0 through 2.2.26 and 2.3 through 2.9.5 contain a command injection vulnerability in the Perforce::syncCodeBase() method, which appends the $sourceReference parameter to a shell command without proper escaping, and additionally in the Perforce::generateP4Command() method as in GHSA-wg36-wvj6-r67p / CVE-2026-40176, which interpolates user-supplied Perforce connection parameters (port, user, client) from the source url field w CVSSv3.1 8.8 (HIGH) · EPSS 12th percentile

CWECWE 20CWECWE 78VNDComposerVNDGetcomposerTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-04-15
2026-04-15 21:17Z
CRIT

CVE-2026-40173 — Dgraph Dgraph: Versions 25.3.1 and prior contain an unauthenticated credential disclosure vulnerability where the /debug/pprof/cmdline endpoint

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-40173

Dgraph is an open source distributed GraphQL database. Versions 25.3.1 and prior contain an unauthenticated credential disclosure vulnerability where the /debug/pprof/cmdline endpoint is registered on the default mux and reachable without authentication, exposing the full process command line including the admin token configured via the --security "token=..." startup flag. An attacker can retrieve the leaked token and reuse it in the X-Dgraph-AuthToken header to gain unauthor CVSSv3.1 9.4 (CRITICAL) · EPSS 31th percentile

CWECWE 200CWECWE 522CWECWE 215VNDDgraphTYPVulnerability
9.4
CVSS v3.1
97
Edit Score
2026-04-15
2026-04-15 20:16Z
HIGH

CVE-2026-6363 — Google Chrome: Type Confusion in V8 in Google Chrome prior to 147.0.7727.101 allowed a remote attacker

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-6363

Type Confusion in V8 in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page. (Chromium security severity: Medium) CVSSv3.1 8.8 (HIGH) · EPSS 21th percentile

CWECWE 843VNDGoogleVNDTypeTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-04-15
2026-04-15 20:16Z
HIGH

CVE-2026-6361 — Google Chrome: Heap buffer overflow in PDFium in Google Chrome on Windows prior to 147.0.7727.101 allowed

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-6361

Heap buffer overflow in PDFium in Google Chrome on Windows prior to 147.0.7727.101 allowed a remote attacker who convinced a user to engage in specific UI gestures to execute arbitrary code inside a sandbox via a crafted PDF file. (Chromium security severity: High) CVSSv3.1 8.3 (HIGH) · EPSS 4th percentile

CWECWE 122VNDGoogleVNDHeapTYPVulnerability
8.3
CVSS v3.1
92
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-04-15
2026-04-15 20:16Z
HIGH

CVE-2026-6360 — Google Chrome: Use after free in FileSystem in Google Chrome prior to 147.0.7727.101 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-6360

Use after free in FileSystem in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to potentially exploit object corruption via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.8 (HIGH) · EPSS 7th percentile

CWECWE 416VNDGoogleTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-04-15
2026-04-15 20:16Z
HIGH

CVE-2026-6358 — Google Chrome: Use after free in XR in Google Chrome on Android prior to 147.0.7727.101 allowed

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-6358

Use after free in XR in Google Chrome on Android prior to 147.0.7727.101 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: Critical) CVSSv3.1 8.8 (HIGH) · EPSS 30th percentile

CWECWE 416VNDGoogleTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-04-15
2026-04-15 20:16Z
HIGH

CVE-2026-6318 — Google Chrome: Use after free in Codecs in Google Chrome prior to 147.0.7727.101 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-6318

Use after free in Codecs in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium) CVSSv3.1 8.8 (HIGH) · EPSS 15th percentile

CWECWE 416VNDGoogleTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-04-15
2026-04-15 20:16Z
HIGH

CVE-2026-6317 — Google Chrome: Use after free in Cast in Google Chrome prior to 147.0.7727.101 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-6317

Use after free in Cast in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.8 (HIGH) · EPSS 33th percentile

CWECWE 416VNDGoogleTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-04-15
2026-04-15 20:16Z
HIGH

CVE-2026-6316 — Google Chrome: Use after free in Forms in Google Chrome prior to 147.0.7727.101 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-6316

Use after free in Forms in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.8 (HIGH) · EPSS 33th percentile

CWECWE 416VNDGoogleTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-04-15
2026-04-15 20:16Z
HIGH

CVE-2026-6315 — Google Chrome: Use after free in Permissions in Google Chrome on Android prior to 147.0.7727.101 allowed

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-6315

Use after free in Permissions in Google Chrome on Android prior to 147.0.7727.101 allowed a remote attacker who convinced a user to engage in specific UI gestures to execute arbitrary code via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.8 (HIGH) · EPSS 30th percentile

CWECWE 416VNDGoogleTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-04-15
2026-04-15 20:16Z
HIGH

CVE-2026-6314 — Google Chrome: Out of bounds write in GPU in Google Chrome prior to 147.0.7727.101 allowed a

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-6314

Out of bounds write in GPU in Google Chrome prior to 147.0.7727.101 allowed a remote attacker who had compromised the GPU process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.3 (HIGH) · EPSS 10th percentile

CWECWE 787VNDGoogleTYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-04-15
2026-04-15 20:16Z
HIGH

CVE-2026-6311 — Google Chrome: Uninitialized Use in Accessibility in Google Chrome on Windows prior to 147.0.7727.101 allowed a

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-6311

Uninitialized Use in Accessibility in Google Chrome on Windows prior to 147.0.7727.101 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.3 (HIGH) · EPSS 8th percentile

CWECWE 457VNDGoogleVNDUninitializedTYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-04-15
2026-04-15 20:16Z
HIGH

CVE-2026-6310 — Google Chrome: Use after free in Dawn in Google Chrome prior to 147.0.7727.101 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-6310

Use after free in Dawn in Google Chrome prior to 147.0.7727.101 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.3 (HIGH) · EPSS 11th percentile

CWECWE 416VNDGoogleTYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-04-15
2026-04-15 20:16Z
HIGH

CVE-2026-6309 — Google Chrome: Use after free in Viz in Google Chrome prior to 147.0.7727.101 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-6309

Use after free in Viz in Google Chrome prior to 147.0.7727.101 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.3 (HIGH) · EPSS 11th percentile

CWECWE 416VNDGoogleTYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-04-15
2026-04-15 20:16Z
HIGH

CVE-2026-6306 — Google Chrome: Heap buffer overflow in PDFium in Google Chrome prior to 147.0.7727.101 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-6306

Heap buffer overflow in PDFium in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted PDF file. (Chromium security severity: High) CVSSv3.1 8.8 (HIGH) · EPSS 9th percentile

CWECWE 122VNDGoogleVNDHeapTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-04-15
2026-04-15 20:16Z
HIGH

CVE-2026-6305 — Google Chrome: Heap buffer overflow in PDFium in Google Chrome prior to 147.0.7727.101 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-6305

Heap buffer overflow in PDFium in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted PDF file. (Chromium security severity: High) CVSSv3.1 8.8 (HIGH) · EPSS 9th percentile

CWECWE 787CWECWE 122VNDGoogleVNDHeapTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-04-15
2026-04-15 20:16Z
HIGH

CVE-2026-6304 — Google Chrome: Use after free in Graphite in Google Chrome prior to 147.0.7727.101 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-6304

Use after free in Graphite in Google Chrome prior to 147.0.7727.101 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.3 (HIGH) · EPSS 11th percentile

CWECWE 416VNDGoogleTYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-04-15
2026-04-15 20:16Z
HIGH

CVE-2026-6303 — Google Chrome: Use after free in Codecs in Google Chrome prior to 147.0.7727.101 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-6303

Use after free in Codecs in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.8 (HIGH) · EPSS 15th percentile

CWECWE 416VNDGoogleTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-04-15
2026-04-15 20:16Z
HIGH

CVE-2026-6302 — Google Chrome: Use after free in Video in Google Chrome prior to 147.0.7727.101 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-6302

Use after free in Video in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.8 (HIGH) · EPSS 15th percentile

CWECWE 416VNDGoogleTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-04-15
2026-04-15 20:16Z
HIGH

CVE-2026-6301 — Google Chrome: Type Confusion in Turbofan in Google Chrome prior to 147.0.7727.101 allowed a remote attacker

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-6301

Type Confusion in Turbofan in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.8 (HIGH) · EPSS 10th percentile

CWECWE 843VNDGoogleVNDTypeTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-04-15
2026-04-15 20:16Z
HIGH

CVE-2026-6300 — Google Chrome: Use after free in CSS in Google Chrome prior to 147.0.7727.101 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-6300

Use after free in CSS in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.8 (HIGH) · EPSS 15th percentile

CWECWE 416VNDGoogleTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-04-15
2026-04-15 20:16Z
HIGH

CVE-2026-6299 — Google Chrome: Use after free in Prerender in Google Chrome prior to 147.0.7727.101 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-6299

Use after free in Prerender in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: Critical) CVSSv3.1 8.8 (HIGH) · EPSS 15th percentile

CWECWE 416VNDGoogleTYPVulnerability
8.8
CVSS v3.1
94
Edit Score