8.2

CVSS4.0

CVE-2026-40481 - monetr: Unauthenticated Stripe webhook reads attacker-sized request bodies before signature validat…

monetr is a budgeting application for recurring expenses. In versions 1.12.3 and below, the public Stripe webhook endpoint buffers the entire request body into memory before validating the Stripe signature. A remote unauthenticated attacker can send oversized POST payloads to cause uncontrolled mem…

📅 Published: April 17, 2026, 10:54 p.m. 🔄 Last Modified: April 17, 2026, 10:54 p.m.

4.3

CVSS3.1

CVE-2026-40486 - Kimai's User Preferences API allows standard users to modify restricted attributes: hourly_rate, in…

Kimai is an open-source time tracking application. In versions 2.52.0 and below, the User Preferences API endpoint (PATCH /api/users/{id}/preferences) applies submitted preference values without checking the isEnabled() flag on preference objects. Although the hourly_rate and internal_rate fields a…

📅 Published: April 17, 2026, 10:35 p.m. 🔄 Last Modified: April 17, 2026, 10:35 p.m.

5.4

CVSS3.1

CVE-2026-40479 - Kimai: Stored XSS via Incomplete HTML Attribute Escaping in Team Member Widget

Kimai is an open-source time tracking application. In versions 1.16.3 through 2.52.0, the escapeForHtml() function in KimaiEscape.js does not escape double quote or single quote characters. When a user's profile alias is inserted into an HTML attribute context via the team member form prototype and…

📅 Published: April 17, 2026, 10:31 p.m. 🔄 Last Modified: April 17, 2026, 10:31 p.m.

6.4

CVSS3.1

CVE-2026-2434 - Pz-LinkCard <= 2.5.8.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Att…

The Pz-LinkCard plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'blogcard' shortcode attributes in all versions up to, and including, 2.5.8.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-le…

📅 Published: April 17, 2026, 10:27 p.m. 🔄 Last Modified: April 17, 2026, 10:27 p.m.

9.1

CVSS3.1

CVE-2026-40478 - Improper neutralization of specific syntax patterns for unauthorized expressions in Thymeleaf

Thymeleaf is a server-side Java template engine for web and standalone environments. Versions 3.1.3.RELEASE and prior contain a security bypass vulnerability in the the expression execution mechanisms. Although the library provides mechanisms to prevent expression injection, it fails to properly ne…

📅 Published: April 17, 2026, 9:57 p.m. 🔄 Last Modified: April 17, 2026, 9:57 p.m.
Load More Vulnerability
avatar

Mehmet Ince

@mdisec

CVE stats coming here

avatar

Nuri Çilengir

@ncilengir

CVE stats coming here

avatar

@aydinnyunus

CVE stats coming here

avatar

Onurcan Genç

@onurcangnc

CVE stats coming here

avatar

Seyit Sigirci

@h3xecute

CVE stats coming here

avatar

Ali İltizar

@iltosec

CVE stats coming here

avatar

@b3rsec

CVE stats coming here

avatar

@furkank

CVE stats coming here

avatar

kutaysec

@kutaysec

CVE stats coming here