9.1

CVSS3.1

CVE-2026-40887 - @vendure/core has a SQL Injection vulnerability

Vendure is an open-source headless commerce platform. Starting in version 1.7.4 and prior to versions 2.3.4, 3.5.7, and 3.6.2, an unauthenticated SQL injection vulnerability exists in the Vendure Shop API. A user-controlled query string parameter is interpolated directly into a raw SQL expression w…

πŸ“… Published: April 21, 2026, 7:24 p.m. πŸ”„ Last Modified: April 22, 2026, 9:08 p.m.

2.1

CVSS4.0

CVE-2026-40878 - mailcow-dockerized Login Page has Reflected Parameter Injection / Wrong-Context XSS Escaping

mailcow: dockerized is an open source groupware/email suite based on docker. In versions prior to 2026-03b, the mailcow web interface passes the raw `$_SERVER['REQUEST_URI']` to Twig as a global template variable and renders it inside a JavaScript string literal in the `setLang()` helper of `base.t…

πŸ“… Published: April 21, 2026, 7:21 p.m. πŸ”„ Last Modified: April 22, 2026, 9:02 p.m.

6.1

CVSS3.1

CVE-2026-33812 - Excessive memory allocation when decoding malicious SFNT in golang.org/x/image

Parsing a malicious font file can cause excessive memory allocation.

πŸ“… Published: April 21, 2026, 7:21 p.m. πŸ”„ Last Modified: April 22, 2026, 9:24 p.m.

7.5

CVSS3.1

CVE-2026-33813 - Panic when decoding large WEBP image on 32-bit platforms in golang.org/x/image

Parsing a WEBP image with an invalid, large size panics on 32-bit platforms.

πŸ“… Published: April 21, 2026, 7:21 p.m. πŸ”„ Last Modified: April 22, 2026, 9:24 p.m.

6.3

CVSS4.0

CVE-2026-40881 - Zebra: addr/addrv2 Deserialization Resource Exhaustion

ZEBRA is a Zcash node written entirely in Rust. Prior to zebrad version 4.3.0 and zebra-network version 5.0.1, when deserializing addr or addrv2 messages, which contain vectors of addresses, Zebra would fully deserialize them up to a maximum length (over 233,000) that was derived from the 2 MiB mes…

πŸ“… Published: April 21, 2026, 7:20 p.m. πŸ”„ Last Modified: April 22, 2026, 9:24 p.m.

9.1

CVSS3.1

CVE-2026-40372 - ASP.NET Core Elevation of Privilege Vulnerability

Improper verification of cryptographic signature in ASP.NET Core allows an unauthorized attacker to elevate privileges over a network.

πŸ“… Published: April 21, 2026, 7:20 p.m. πŸ”„ Last Modified: April 24, 2026, 12:51 p.m.

7

CVSS4.0

CVE-2026-40875 - mailcow: dockerized vulnerable to stored XSS in user login history real_rip

mailcow: dockerized is an open source groupware/email suite based on docker. In versions prior to 2026-03b, the user dashboard's "Seen successful connections" (login history) renders the client IP from login logs without HTML escaping. Because the server trusts the X-Real-IP header as the source IP…

πŸ“… Published: April 21, 2026, 7:19 p.m. πŸ”„ Last Modified: April 22, 2026, 9:02 p.m.

7.2

CVSS4.0

CVE-2026-40880 - Zebra: Cached Mempool Verification Bypasses Consensus Rules for Ahead-of-Tip Blocks

ZEBRA is a Zcash node written entirely in Rust. Prior to zebrad version 4.3.1 and zebra-consensus version 5.0.2, a logic error in Zebra's transaction verification cache could allow a malicious miner to induce a consensus split. By carefully submitting a transaction that is valid for height H+1 but …

πŸ“… Published: April 21, 2026, 7:18 p.m. πŸ”„ Last Modified: April 22, 2026, 9:24 p.m.

6

CVSS4.0

CVE-2026-40874 - mailcow: dockerized missing authorization on Forwarding Hosts delete action

mailcow: dockerized is an open source groupware/email suite based on docker. In versions prior to 2026-03b, no administrator verification takes place when deleting Forwarding Hosts with `/api/v1/delete/fwdhost`. Any authenticated user can call this API. Checks are only applied for edit/add actions,…

πŸ“… Published: April 21, 2026, 7:17 p.m. πŸ”„ Last Modified: April 22, 2026, 9:02 p.m.

8.9

CVSS4.0

CVE-2026-40873 - mailcow: dockerized vulnerable to stored XSS in Quarantine attachment filenames

mailcow: dockerized is an open source groupware/email suite based on docker. In versions prior to 2026-03b, the Quarantine details modal injects attachment filenames into HTML without escaping, allowing arbitrary HTML/JS execution. An attacker can deliver an email with a crafted attachment name so …

πŸ“… Published: April 21, 2026, 7:15 p.m. πŸ”„ Last Modified: April 22, 2026, 9:02 p.m.
Total resulsts: 346578
Page 101 of 34,658
Β« previous page Β» next page
Filters