2026-04-08
2026-04-08 22:16Z
HIGH

CVE-2026-5883 — Google Chrome: Use after free in Media in Google Chrome prior to 147.0.7727.55 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-5883

Use after free in Media in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium) CVSSv3.1 8.8 (HIGH) · EPSS 32th percentile

CWECWE 416VNDGoogleTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-04-08
2026-04-08 22:16Z
HIGH

CVE-2026-5879 — Google Chrome: Insufficient validation of untrusted input in ANGLE in Google Chrome on Mac prior to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-5879

Insufficient validation of untrusted input in ANGLE in Google Chrome on Mac prior to 147.0.7727.55 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium) CVSSv3.1 8.8 (HIGH)

CWECWE 20VNDGoogleTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-04-08
2026-04-08 22:16Z
HIGH

CVE-2026-5877 — Google Chrome: Use after free in Navigation in Google Chrome prior to 147.0.7727.55 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-5877

Use after free in Navigation in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium) CVSSv3.1 8.8 (HIGH)

CWECWE 416VNDGoogleTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-04-08
2026-04-08 22:16Z
CRIT

CVE-2026-5874 — Google Chrome: Use after free in PrivateAI in Google Chrome prior to 147.0.7727.55 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-5874

Use after free in PrivateAI in Google Chrome prior to 147.0.7727.55 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium) CVSSv3.1 9.6 (CRITICAL)

CWECWE 416VNDGoogleTYPVulnerability
9.6
CVSS v3.1
98
Edit Score
2026-04-08
2026-04-08 22:16Z
HIGH

CVE-2026-5873 — Google Chrome: Out of bounds read and write in V8 in Google Chrome prior to 147.0.7727.55

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-5873

Out of bounds read and write in V8 in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.8 (HIGH)

CWECWE 125CWECWE 787VNDGoogleTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-04-08
2026-04-08 22:16Z
HIGH

CVE-2026-5872 — Google Chrome: Use after free in Blink in Google Chrome prior to 147.0.7727.55 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-5872

Use after free in Blink in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.8 (HIGH)

CWECWE 416VNDGoogleTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-04-08
2026-04-08 22:16Z
HIGH

CVE-2026-5871 — Google Chrome: Type Confusion in V8 in Google Chrome prior to 147.0.7727.55 allowed a remote attacker

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-5871

Type Confusion in V8 in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.8 (HIGH)

CWECWE 843VNDGoogleVNDTypeTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-04-08
2026-04-08 22:16Z
HIGH

CVE-2026-5870 — Google Chrome: Integer overflow in Skia in Google Chrome prior to 147.0.7727.55 allowed a remote attacker

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-5870

Integer overflow in Skia in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.8 (HIGH)

CWECWE 190CWECWE 472VNDGoogleTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-04-08
2026-04-08 22:16Z
HIGH

CVE-2026-5868 — Google Chrome: Heap buffer overflow in ANGLE in Google Chrome on Mac prior to 147.0.7727.55 allowed

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-5868

Heap buffer overflow in ANGLE in Google Chrome on Mac prior to 147.0.7727.55 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.8 (HIGH)

CWECWE 122VNDGoogleVNDHeapTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-04-08
2026-04-08 22:16Z
HIGH

CVE-2026-5866 — Google Chrome: Use after free in Media in Google Chrome prior to 147.0.7727.55 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-5866

Use after free in Media in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.8 (HIGH)

CWECWE 416VNDGoogleTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-04-08
2026-04-08 22:16Z
HIGH

CVE-2026-5865 — Google Chrome: Type Confusion in V8 in Google Chrome prior to 147.0.7727.55 allowed a remote attacker

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-5865

Type Confusion in V8 in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.8 (HIGH)

CWECWE 843VNDGoogleVNDTypeTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-04-08
2026-04-08 22:16Z
HIGH

CVE-2026-5863 — Google Chrome: Inappropriate implementation in V8 in Google Chrome prior to 147.0.7727.55 allowed a remote attacker

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-5863

Inappropriate implementation in V8 in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.8 (HIGH)

VNDGoogleVNDInappropriateTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-04-08
2026-04-08 22:16Z
HIGH

CVE-2026-5862 — Google Chrome: Inappropriate implementation in V8 in Google Chrome prior to 147.0.7727.55 allowed a remote attacker

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-5862

Inappropriate implementation in V8 in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.8 (HIGH)

VNDGoogleVNDInappropriateTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-04-08
2026-04-08 22:16Z
HIGH

CVE-2026-5861 — Google Chrome: Use after free in V8 in Google Chrome prior to 147.0.7727.55 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-5861

Use after free in V8 in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.8 (HIGH)

CWECWE 416VNDGoogleTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-04-08
2026-04-08 22:16Z
HIGH

CVE-2026-5860 — Google Chrome: Use after free in WebRTC in Google Chrome prior to 147.0.7727.55 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-5860

Use after free in WebRTC in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.8 (HIGH)

CWECWE 416VNDGoogleTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-04-08
2026-04-08 22:16Z
HIGH

CVE-2026-5859 — Google Chrome: Integer overflow in WebML in Google Chrome prior to 147.0.7727.55 allowed a remote attacker

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-5859

Integer overflow in WebML in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical) CVSSv3.1 8.8 (HIGH)

CWECWE 472VNDGoogleTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-04-08
2026-04-08 22:16Z
HIGH

CVE-2026-5858 — Google Chrome: Heap buffer overflow in WebML in Google Chrome prior to 147.0.7727.55 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-5858

Heap buffer overflow in WebML in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: Critical) CVSSv3.1 8.8 (HIGH)

CWECWE 122VNDGoogleVNDHeapTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-04-08
2026-04-08 22:16Z
CRIT

CVE-2026-40035 — Unfurl: through 2025.08 contains an improper input validation vulnerability in config parsing that enables

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-40035

Unfurl through 2025.08 contains an improper input validation vulnerability in config parsing that enables Flask debug mode by default. The debug configuration value is read as a string and passed directly to app.run(), causing any non-empty string to evaluate truthy, allowing attackers to access the Werkzeug debugger and disclose sensitive information or achieve remote code execution. CVSSv3.1 9.1 (CRITICAL)

CWECWE 489VNDUnfurlTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-04-08
2026-04-08 22:00Z
HIGH

Tearing down a car telematic unit (and finding an accident on Facebook)

Quarkslab·blog.quarkslab.com

Quarkslab researchers performed a physical teardown and firmware extraction of a BYD vehicle telematic unit (TCU) containing a Qualcomm MDM9628 modem. Analysis of the extracted filesystem revealed cleartext Wi-Fi credentials, unauthenticated guest access, enabled debugging interfaces (ADB, Telnet), and forensic GNSS logs that reconstructed the vehicle's complete journey across three countries and correlated to a real accident via OSINT.

SRFHardwareVNDQualcommVNDBydTYPResearchTYPWriteupSTGDiscoverySTGCollectionTECT1005
78
Edit Score
2026-04-08
2026-04-08 21:44Z
HIGH

kernel-hack-drill — Linux kernel exploitation experiments

GitHub · kernel exploits·github.comGITHUB POC

kernel-hack-drill is an open-source Linux kernel exploitation playground providing intentionally vulnerable kernel modules and corresponding proof-of-concept exploits. The repository demonstrates fundamental kernel exploitation techniques including use-after-free (UAF), out-of-bounds writes, and privilege escalation via ROP chains, Dirty Pipe, and page table manipulation on x86_64 systems.

SRFOsTACTA0004TACTA0005TYPResearchTYPToolTYPWriteupSTGDefense EvasionSTGPrivesc
72
Edit Score
2026-04-08
2026-04-08 21:25Z
INFO

v9.0.0-rc3

BloodHound releases·github.com

BloodHound v9.0.0-rc3 release candidate published with bug fixes and feature updates including auditor permission bypass fix (BED-7764), UI alignment corrections, and client bearer auth feature flag enablement. This is a pre-release version in the v9.0.0 development cycle.

VNDBloodhoundVNDSpecteropsTYPTool
28
Edit Score
2026-04-08
2026-04-08 21:17Z
HIGH

CVE-2026-5436 — Form: The MW WP Form plugin for WordPress is vulnerable to Arbitrary File Move/Read in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-5436

The MW WP Form plugin for WordPress is vulnerable to Arbitrary File Move/Read in all versions up to and including 5.1.1. This is due to insufficient validation of the $name parameter (upload field key) passed to the generate_user_file_dirpath() function, which uses WordPress's path_join() — a function that returns absolute paths unchanged, discarding the intended base directory. The attacker-controlled key is injected via the mwf_upload_files[] POST parameter, which is loaded CVSSv3.1 8.1 (HIGH) · EPSS 47th percentile

CWECWE 22VNDFormTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-04-08
2026-04-08 21:17Z
CRIT

CVE-2026-39892 — Cryptography.io Cryptography: Hash.update()), this could lead to buffer overflows.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-39892

cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. From 45.0.0 to before 46.0.7, if a non-contiguous buffer was passed to APIs which accepted Python buffers (e.g. Hash.update()), this could lead to buffer overflows. This vulnerability is fixed in 46.0.7. CVSSv3.1 9.8 (CRITICAL)

CWECWE 119CWECWE 131VNDCryptography IoTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-04-08
2026-04-08 21:17Z
HIGH

CVE-2026-39891 — PraisonAI: Prior to 4.5.115, the create_agent_centric_tools() function returns tools (like acp_create_file) that process file content

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-39891

PraisonAI is a multi-agent teams system. Prior to 4.5.115, the create_agent_centric_tools() function returns tools (like acp_create_file) that process file content using template rendering. When user input from agent.start() is passed directly into these tools without escaping, template expressions in the input are executed rather than treated as literal text. This vulnerability is fixed in 4.5.115. CVSSv3.1 8.8 (HIGH)

CWECWE 94VNDPraisonaiTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-04-08
2026-04-08 21:17Z
CRIT

CVE-2026-39890 — PraisonAI: This allows an attacker to craft a malicious YAML file that, when parsed, executes

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-39890

PraisonAI is a multi-agent teams system. Prior to 4.5.115, the AgentService.loadAgentFromFile method uses the js-yaml library to parse YAML files without disabling dangerous tags (such as !!js/function and !!js/undefined). This allows an attacker to craft a malicious YAML file that, when parsed, executes arbitrary JavaScript code. An attacker can exploit this vulnerability by uploading a malicious agent definition file via the API endpoint, leading to remote code execution (R CVSSv3.1 9.8 (CRITICAL)

CWECWE 502VNDPraisonaiTYPVulnerability
9.8
CVSS v3.1
99
Edit Score