8.2

CVSS4.0

CVE-2026-40604 - ClearanceKit: opfilter system extension can be suspended or signalled by a root process, disabling …

ClearanceKit intercepts file-system access events on macOS and enforces per-process access policies. Prior to 5.0.6, the opfilter Endpoint Security system extension (bundle ID uk.craigbass.clearancekit.opfilter) can be suspended with SIGSTOP or kill -STOP, or killed with SIGKILL/SIGTERM, by any pro…

πŸ“… Published: April 21, 2026, 5:41 p.m. πŸ”„ Last Modified: April 24, 2026, 8:49 p.m.

5.6

CVSS3.1

CVE-2026-40602 - hass-cli: Handling of user-supplied Jinja2 templates

The Home Assistant Command-line interface (hass-cli) is a command-line tool for Home Assistant. Up to 1.0.0 of home-assitant-cli an unrestricted environment was used to handle Jninja2 templates instead of a sandboxed one. The user-supplied input within Jinja2 templates was rendered locally with no …

πŸ“… Published: April 21, 2026, 5:40 p.m. πŸ”„ Last Modified: April 22, 2026, 9:24 p.m.

8.4

CVSS4.0

CVE-2026-40599 - ClearanceKit: Ad-hoc signed binaries can spoof Apple process identities in the global allowlist

ClearanceKit intercepts file-system access events on macOS and enforces per-process access policies. Prior to 5.0.5, ClearanceKit incorrectly treats a process with an empty Team ID and a non-empty Signing ID as an Apple platform binary. This bug allows a malicious software to impersonate an apple p…

πŸ“… Published: April 21, 2026, 5:37 p.m. πŸ”„ Last Modified: April 24, 2026, 8:50 p.m.

5.4

CVSS3.1

CVE-2026-41194 - FreeScout's Mailbox OAuth disconnect uses a state-changing GET and is CSRFable

FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.215, the mailbox OAuth disconnect action is implemented as `GET /mailbox/oauth-disconnect/{id}/{in_out}/{provider}`. It removes stored OAuth metadata from the mailbox and then redirects. Because it is a GET route, no…

πŸ“… Published: April 21, 2026, 5:16 p.m. πŸ”„ Last Modified: April 22, 2026, 9:08 p.m.

9.1

CVSS3.1

CVE-2026-41193 - FreeScout has Zip Slip path traversal in module installation that allows arbitrary file write leadi…

FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.215, FreeScout's module installation feature extracts ZIP archives without validating file paths, allowing an authenticated admin to write files arbitrarily on the server filesystem via a specially crafted ZIP. Versi…

πŸ“… Published: April 21, 2026, 5:15 p.m. πŸ”„ Last Modified: April 22, 2026, 9:10 p.m.

4.8

CVSS3.1

CVE-2026-40594 - pyLoad: Session Cookie Security Downgrade via Untrusted X-Forwarded-Proto Header Spoofing (Global S…

pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev98, the set_session_cookie_secure before_request handler in src/pyload/webui/app/__init__.py reads the X-Forwarded-Proto header from any HTTP request without validating that the request originates from a truste…

πŸ“… Published: April 21, 2026, 5:14 p.m. πŸ”„ Last Modified: April 22, 2026, 9:24 p.m.

7.1

CVSS3.1

CVE-2026-41192 - FreeScout's client-controlled attachment IDs allow deletion of existing conversation attachments

FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.215, the reply and draft flows trust client-supplied encrypted attachment IDs. Any IDs present in `attachments_all[]` but omitted from retained lists are decrypted and passed directly to `Attachment::deleteByIds()`. …

πŸ“… Published: April 21, 2026, 5:12 p.m. πŸ”„ Last Modified: April 22, 2026, 9:10 p.m.

8.1

CVSS3.1

CVE-2026-40588 - blueprintUE: Authenticated Password Change Does Not Verify Current Password

blueprintUE is a tool to help Unreal Engine developers. Prior to 4.2.0, the password change form at /profile/{slug}/edit/ does not include a current_password field and does not verify the user's existing password before accepting a new one. Any attacker who obtains a valid authenticated session β€” t…

πŸ“… Published: April 21, 2026, 5:12 p.m. πŸ”„ Last Modified: April 22, 2026, 9:16 p.m.

6.5

CVSS3.1

CVE-2026-40587 - blueprintUE: Active Sessions Are Not Invalidated After Password Change or Reset

blueprintUE is a tool to help Unreal Engine developers. Prior to 4.2.0, when a user changes their password via the profile edit page, or when a password reset is completed via the reset link, neither operation invalidates existing authenticated sessions for that user. A server-side session store as…

πŸ“… Published: April 21, 2026, 5:11 p.m. πŸ”„ Last Modified: April 22, 2026, 9:16 p.m.

7.5

CVSS3.1

CVE-2026-40586 - blueprintUE: Login Endpoint Has No Rate Limiting, Lockout, or Brute-Force Protection

blueprintUE is a tool to help Unreal Engine developers. Prior to 4.2.0, the login form handler performs no throttling of any kind. Failed authentication attempts are processed at full network speed with no IP-based rate limiting, no per-account attempt counter, no temporary lockout, no progressive …

πŸ“… Published: April 21, 2026, 5:10 p.m. πŸ”„ Last Modified: April 22, 2026, 9:16 p.m.
Total resulsts: 346560
Page 102 of 34,656
Β« previous page Β» next page
Filters