6.9

CVSS4.0

CVE-2026-40343 - free5GC UDR: Fail-open handling in PolicyDataSubsToNotifyPost allows unintended subscription creatiโ€ฆ

free5GC UDR is the user data repository (UDR) for free5GC, an an open-source project for 5th generation (5G) mobile core networks. In versions up to and including 1.4.2, a fail-open request handling flaw in the UDR service causes the `/nudr-dr/v2/policy-data/subs-to-notify` POST handler to continueโ€ฆ

๐Ÿ“… Published: April 21, 2026, 11:47 p.m. ๐Ÿ”„ Last Modified: April 23, 2026, 7:44 p.m.

8.8

CVSS3.1

CVE-2026-41133 - pyLoad has Stale Session Privilege After Role/Permission Change (Privilege Revocation Bypass)

pyLoad is a free and open-source download manager written in Python. Versions up to and including 0.5.0b3.dev97 cache `role` and `permission` in the session at login and continues to authorize requests using these cached values, even after an admin changes the user's role/permissions in the databasโ€ฆ

๐Ÿ“… Published: April 21, 2026, 11:41 p.m. ๐Ÿ”„ Last Modified: April 22, 2026, 9:23 p.m.

5

CVSS3.1

CVE-2026-41131 - OpenFGA has Improper Policy Enforcement

OpenFGA is an authorization/permission engine built for developers. Prior to version 1.14.1, in specific scenarios, models using conditions with caching enabled can result in two different check requests producing the same cache key. This could result in OpenFGA reusing an earlier cached result forโ€ฆ

๐Ÿ“… Published: April 21, 2026, 11:38 p.m. ๐Ÿ”„ Last Modified: April 24, 2026, 1:44 p.m.

5.5

CVSS4.0

CVE-2026-41130 - Craft CMS has a host header injection leading to SSRF via resource-js endpoint

Craft CMS is a content management system (CMS). In versions on the 4.x branch through 4.17.8 and the 5.x branch through 5.9.14, the `resource-js` endpoint in Craft CMS allows unauthenticated requests to proxy remote JavaScript resources. When `trustedHosts` is not explicitly restricted (default coโ€ฆ

๐Ÿ“… Published: April 21, 2026, 11:36 p.m. ๐Ÿ”„ Last Modified: April 22, 2026, 8:26 p.m.

5.5

CVSS4.0

CVE-2026-41129 - Craft CMS has Server-Side Request Forgery (SSRF) with Asset Uploads Mutations

Craft CMS is a content management system (CMS). Versions on the 4.x branch through 4.17.8 and the 5.x branch through 5.9.14 are vulnerable to Server-Side Request Forgery. The exploitation requires a few permissions to be enabled in the used GraphQL schema: "Edit assets in the <VolumeName> volume" aโ€ฆ

๐Ÿ“… Published: April 21, 2026, 11:34 p.m. ๐Ÿ”„ Last Modified: April 22, 2026, 8:26 p.m.

5.3

CVSS4.0

CVE-2026-41128 - Craft CMS has a Missing Authorization Check on User Group Removal via save-permissions Action

Craft CMS is a content management system (CMS). In versions 5.6.0 through 5.9.14, the `actionSavePermissions()` endpoint allows a user with only `viewUsers` permission to remove arbitrary users from all user groups. While `_saveUserGroups()` enforces per-group authorization for additions, it perforโ€ฆ

๐Ÿ“… Published: April 21, 2026, 11:32 p.m. ๐Ÿ”„ Last Modified: April 22, 2026, 8:26 p.m.

6.5

CVSS3.1

CVE-2026-41127 - BigBlueButton's missing authorization allows viewer to inject/overwrite captions

BigBlueButton is an open-source virtual classroom. Versions prior to 3.0.24 have a missing authorization that allows viewers to inject/overwrite captions Version 3.0.24 tightened the permissions on who is able to submit captions. No known workarounds are available.

๐Ÿ“… Published: April 21, 2026, 11:24 p.m. ๐Ÿ”„ Last Modified: April 22, 2026, 8:26 p.m.

4.3

CVSS3.1

CVE-2026-41126 - BigBlueButton has Open Redirect through bigbluebutton/api/join via get-parameter "logoutURL"

BigBlueButton is an open-source virtual classroom. Versions prior to 3.0.24 have an Open Redirect through bigbluebutton/api/join via get-parameter "logoutURL." Version 3.0.24 has adjusted the handling of requests with incorrect checksum so that the default logoutURL is used. No known workarounds arโ€ฆ

๐Ÿ“… Published: April 21, 2026, 11:22 p.m. ๐Ÿ”„ Last Modified: April 22, 2026, 8:26 p.m.

9.1

CVSS3.1

CVE-2026-40575 - OAuth2 Proxy has an Authentication Bypass via X-Forwarded-Uri Header Spoofing

OAuth2 Proxy is a reverse proxy that provides authentication using OAuth2 providers. Versions 7.5.0 through 7.15.1 may trust a client-supplied `X-Forwarded-Uri` header when `--reverse-proxy` is enabled and `--skip-auth-regex` or `--skip-auth-route` is configured. An attacker can spoof this header sโ€ฆ

๐Ÿ“… Published: April 21, 2026, 11:20 p.m. ๐Ÿ”„ Last Modified: April 22, 2026, 9:23 p.m.

8.2

CVSS3.1

CVE-2026-41059 - OAuth2 Proxy has an Authentication Bypass via Fragment Confusion in skip_auth_routes and skip_auth_โ€ฆ

OAuth2 Proxy is a reverse proxy that provides authentication using OAuth2 providers. Versions 7.5.0 through 7.15.1 have a configuration-dependent authentication bypass. Deployments are affected when all of the following are true: Use of `skip_auth_routes` or the legacy `skip_auth_regex`; use of patโ€ฆ

๐Ÿ“… Published: April 21, 2026, 11:17 p.m. ๐Ÿ”„ Last Modified: April 22, 2026, 9:23 p.m.
Total resulsts: 346749
Page 103 of 34,675
ยซ previous page ยป next page
Filters