832 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2026-3927
Chrome General
4.3
MEDIUM
EPSS
0.0%
2026 1 PoC

Incorrect security UI in PictureInPicture in Google Chrome prior to 146.0.7680.71 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)

CVE-2026-22915
TDC-X401GL General
4.3
MEDIUM
EPSS
0.0%
2026 CWE-497 1 PoC

An attacker with low privileges may be able to read files from specific directories on the device, potentially exposing sensitive information.

CVE-2026-1747
GitLab DevOps
4.3
MEDIUM
EPSS
0.0%
2026 CWE-288 1 PoC

GitLab has remediated an issue in GitLab EE affecting all versions from 17.11 before 18.7.5, 18.8 before 18.8.5, and 18.9 before 18.9.1 that, under certain conditions, could have allowed Developer-role users with insufficient privileges to make unauthorized modifications to protected Conan packages.

CVE-2026-0602
GitLab DevOps
4.3
MEDIUM
EPSS
0.0%
2026 CWE-288 1 PoC

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.6 before 18.7.6, 18.8 before 18.8.6, and 18.9 before 18.9.2 that could have allowed an authenticated user to disclose metadata from private issues, merge requests, epics, milestones, or commits due to improper filtering in the snippet rendering process under certain circumstances.

CVE-2026-3925
Chrome General
4.3
MEDIUM
EPSS
0.0%
2026 1 PoC

Incorrect security UI in LookalikeChecks in Google Chrome on Android prior to 146.0.7680.71 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)

CVE-2026-44919
Ironic General
4.3
MEDIUM
EPSS
0.0%
2026 CWE-696 1 PoC

In OpenStack Ironic through 35.x before a3f6d73, during image handling, an infinite loop in checksum calculations can occur via the file:///dev/zero URL.

CVE-2026-8407
Server Web
4.3
MEDIUM
EPSS
0.0%
2026 CWE-862 1 PoC

Missing authorization in the PAM module in Devolutions Server allows an authenticated user with a PAM license but no additional permissions to obtain OTP secret keys and recovery codes via crafted requests to PAM API endpoints. This issue affects the following versions : * Devolutions Server 2026.1.6.0 through 2026.1.11.0 * Devolutions Server 2025.3.16.0 and earlier

CVE-2026-5146
Server General
4.3
MEDIUM
EPSS
0.0%
2026 CWE-862 1 PoC

Improper access control in the notification management endpoints in Devolutions Server allows an unauthenticated attacker to modify or delete arbitrary user notification records via missing session validation. This issue affects the following versions : * Devolutions Server 2026.1.6.0 through 2026.1.15.0 * Devolutions Server 2025.3.19.0 and earlier

CVE-2026-1230
GitLab DevOps
4.1
MEDIUM
EPSS
0.1%
2026 CWE-706 1 PoC

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 1.0 before 18.7.6, 18.8 before 18.8.6, and 18.9 before 18.9.2 that could have allowed an authenticated user to cause repository downloads to contain different code than displayed in the web interface due to incorrect validation of branch references under certain circumstances.

CVE-2026-42798
little cms color engine Web
4.0
MEDIUM
EPSS
0.0%
2026 CWE-190 1 PoC

Little CMS (lcms2) 2.16 through 2.18 before 2.19 has an integer overflow in ParseCube in cmscgats.c.

CVE-2026-33555
HAProxy Web
4.0
MEDIUM
EPSS
0.0%
2026 CWE-130 1 PoC

An issue was discovered in HAProxy before 3.3.6. The HTTP/3 parser does not check that the received body length matches a previously announced content-length when the stream is closed via a frame with an empty payload. This can cause desynchronization issues with the backend server and could be used for request smuggling. The earliest affected version is 2.6.

CVE-2026-41254
little cms color engine Web
4.0
MEDIUM
EPSS
0.0%
2026 CWE-696 2 PoCs

Little CMS (lcms2) through 2.18 has an integer overflow in CubeSize in cmslut.c because the overflow check is performed after the multiplication.