5.3

CVSS3.1

CVE-2026-34069 - nimiq-consensus panics via RequestMacroChain micro-block locator

nimiq/core-rs-albatross is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus algorithm. In versions 1.2.2 and below, an unauthenticated p2p peer can cause the RequestMacroChain message handler task to panic. Sending a RequestMacroChain message where the fir…

πŸ“… Published: April 13, 2026, 11:55 p.m. πŸ”„ Last Modified: April 17, 2026, 3:26 p.m.

2.9

CVSS4.0

CVE-2026-33948 - jq: Embedded-NUL Truncation in CLI JSON Input Path Causes Prefix-Only Validation of Malformed Input

jq is a command-line JSON processor. Commits before 6374ae0bcdfe33a18eb0ae6db28493b1f34a0a5b contain a vulnerability where CLI input parsing allows validation bypass via embedded NUL bytes. When reading JSON from files or stdin, jq uses strlen() to determine buffer length instead of the actual byte…

πŸ“… Published: April 13, 2026, 11:51 p.m. πŸ”„ Last Modified: April 17, 2026, 3:26 p.m.

7.5

CVSS3.1

CVE-2026-40164 - jq: Algorithmic complexity DoS via hardcoded MurmurHash3 seed

jq is a command-line JSON processor. Before commit 0c7d133c3c7e37c00b6d46b658a02244fdd3c784, jq used MurmurHash3 with a hardcoded, publicly visible seed (0x432A9843) for all JSON object hash table operations, which allowed an attacker to precompute key collisions offline. By supplying a crafted JSO…

πŸ“… Published: April 13, 2026, 11:40 p.m. πŸ”„ Last Modified: April 17, 2026, 3:26 p.m.

7.5

CVSS3.1

CVE-2026-5086 - Crypt::SecretBuffer versions before 0.019 for Perl is suseceptible to timing attacks

Crypt::SecretBuffer versions before 0.019 for Perl is suseceptible to timing attacks. For example, if Crypt::SecretBuffer was used to store and compare plaintext passwords, then discrepencies in timing could be used to guess the secret password.

πŸ“… Published: April 13, 2026, 10:54 p.m. πŸ”„ Last Modified: April 17, 2026, 3:18 p.m.

6.1

CVSS3.1

CVE-2026-6203 - User Registration & Membership <= 5.1.4 - Unauthenticated Open Redirect via 'redirect_to_on_logout'…

The User Registration & Membership plugin for WordPress is vulnerable to Open Redirect in versions up to and including 5.1.4. This is due to insufficient validation of user-supplied URLs passed via the 'redirect_to_on_logout' GET parameter before redirecting users. The `redirect_to_on_logout` GET p…

πŸ“… Published: April 13, 2026, 10:25 p.m. πŸ”„ Last Modified: April 15, 2026, 3:45 p.m.

6.9

CVSS4.0

CVE-2026-39979 - jq: Out-of-Bounds Read in jv_parse_sized() Error Formatting for Non-NUL-Terminated Counted Buffers

jq is a command-line JSON processor. In commits before 2f09060afab23fe9390cce7cb860b10416e1bf5f, the jv_parse_sized() API in libjq accepts a counted buffer with an explicit length parameter, but its error-handling path formats the input buffer using %s in jv_string_fmt(), which reads until a NUL te…

πŸ“… Published: April 13, 2026, 10:18 p.m. πŸ”„ Last Modified: April 17, 2026, 3:26 p.m.

6.1

CVSS3.1

CVE-2026-39956 - jq: Missing runtime type checks for _strindices lead to crash and limited memory disclosure

jq is a command-line JSON processor. In commits after 69785bf77f86e2ea1b4a20ca86775916889e91c9, the _strindices builtin in jq's src/builtin.c passes its arguments directly to jv_string_indexes() without verifying they are strings, and jv_string_indexes() in src/jv.c relies solely on assert() checks…

πŸ“… Published: April 13, 2026, 10:10 p.m. πŸ”„ Last Modified: April 17, 2026, 3:26 p.m.

7

CVSS4.0

CVE-2026-4786 - Incomplete mitigation of CVE-2026-4519, %action expansion for command injection to webbrowser.open()

Mitgation ofΒ CVE-2026-4519 was incomplete. If the URL contained "%action" the mitigation could be bypassed for certain browser types the "webbrowser.open()" API could have commands injected into the underlying shell. SeeΒ CVE-2026-4519 for details.

πŸ“… Published: April 13, 2026, 9:52 p.m. πŸ”„ Last Modified: April 17, 2026, 3:18 p.m.

6.2

CVSS3.1

CVE-2026-33947 - jq: Unbounded Recursion in jv_setpath(), jv_getpath() and delpaths_sorted()

jq is a command-line JSON processor. In versions 1.8.1 and below, functions jv_setpath(), jv_getpath(), and delpaths_sorted() in jq's src/jv_aux.c use unbounded recursion whose depth is controlled by the length of a caller-supplied path array, with no depth limit enforced. An attacker can supply a …

πŸ“… Published: April 13, 2026, 9:50 p.m. πŸ”„ Last Modified: April 17, 2026, 3:26 p.m.

6.2

CVSS3.1

CVE-2026-40312 - ImageMagick: Off-by-One in MSL decoder could result in crash

ImageMagick is free and open-source software used for editing and manipulating digital images. In versions below 7.1.2-19, an off by one error in the MSL decoder could result in a crash when a malicous MSL file is read. This issue has been fixed in version 7.1.2-19.

πŸ“… Published: April 13, 2026, 9:43 p.m. πŸ”„ Last Modified: April 17, 2026, 8:42 p.m.
Total resulsts: 345209
Page 101 of 34,521
Β« previous page Β» next page
Filters