Skip to main content

CWE archive

CWE-474 CVEs

Programmatic archive

13 CVEs tagged with CWE-4740 Critical, 6 High, 6 Medium, 1 Low, 0 Unrated.

CVE-2026-39894

Published Jun 24, 2026

Cacti is an open source performance and fault management framework. In versions 1.2.30 and below, the locale-dependent decimal formatting in rrdtool_function_update() can corrupt…

CVSS 2.9 · Low
evidence mentions
3
Buzz score
18.9
Vendor/product tagsBeta · best-effort

CVE-2026-11102

Published Jun 4, 2026

Inappropriate implementation in Isolated Web Apps in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a malicious file…

CVSS 8.8 · High
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-11097

Published Jun 4, 2026

Inappropriate implementation in WebView in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium s…

CVSS 6.5 · Medium
evidence mentions
3
Buzz score
28.9
Vendor/product tagsBeta · best-effort

CVE-2026-25960

Published Mar 9, 2026

vLLM is an inference and serving engine for large language models (LLMs). The SSRF protection fix for CVE-2026-24779 add in 0.15.1 can be bypassed in the load_from_url_async metho…

CVSS 7.1 · High
evidence mentions
9
Buzz score
36.0
Vendor/product tagsBeta · best-effort

CVE-2026-24010

Published Jan 22, 2026

Horilla is a free and open source Human Resource Management System (HRMS). A critical File Upload vulnerability in versions prior to 1.5.0, with Social Engineering, allows authent…

CVSS 8.0 · High
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2024-7001

Published Aug 6, 2024

Inappropriate implementation in HTML in Google Chrome prior to 127.0.6533.72 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofin…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-5839

Published Jun 11, 2024

Inappropriate Implementation in Memory Allocator in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.…

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-5836

Published Jun 11, 2024

Inappropriate Implementation in DevTools in Google Chrome prior to 126.0.6478.54 allowed an attacker who convinced a user to install a malicious extension to execute arbitrary cod…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-1694

Published Jun 7, 2024

Inappropriate implementation in Google Updator prior to 1.3.36.351 in Google Chrome allowed a local attacker to bypass discretionary access control via a malicious file. (Chromium…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-2628

Published Mar 20, 2024

Inappropriate implementation in Downloads in Google Chrome prior to 123.0.6312.58 allowed a remote attacker to perform UI spoofing via a crafted URL. (Chromium security severity:…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-1672

Published Feb 21, 2024

Inappropriate implementation in Content Security Policy in Google Chrome prior to 122.0.6261.57 allowed a remote attacker to bypass content security policy via a crafted HTML page…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-13 of 13 CVEsPage 1 of 1