7.5

CVSS3.1

CVE-2026-40164 - jq: Algorithmic complexity DoS via hardcoded MurmurHash3 seed

jq is a command-line JSON processor. Before commit 0c7d133c3c7e37c00b6d46b658a02244fdd3c784, jq used MurmurHash3 with a hardcoded, publicly visible seed (0x432A9843) for all JSON object hash table operations, which allowed an attacker to precompute key collisions offline. By supplying a crafted JSO…

πŸ“… Published: April 13, 2026, 11:40 p.m. πŸ”„ Last Modified: April 17, 2026, 3:26 p.m.

7.5

CVSS3.1

CVE-2026-5086 - Crypt::SecretBuffer versions before 0.019 for Perl is suseceptible to timing attacks

Crypt::SecretBuffer versions before 0.019 for Perl is suseceptible to timing attacks. For example, if Crypt::SecretBuffer was used to store and compare plaintext passwords, then discrepencies in timing could be used to guess the secret password.

πŸ“… Published: April 13, 2026, 10:54 p.m. πŸ”„ Last Modified: April 17, 2026, 3:18 p.m.

6.1

CVSS3.1

CVE-2026-6203 - User Registration & Membership <= 5.1.4 - Unauthenticated Open Redirect via 'redirect_to_on_logout'…

The User Registration & Membership plugin for WordPress is vulnerable to Open Redirect in versions up to and including 5.1.4. This is due to insufficient validation of user-supplied URLs passed via the 'redirect_to_on_logout' GET parameter before redirecting users. The `redirect_to_on_logout` GET p…

πŸ“… Published: April 13, 2026, 10:25 p.m. πŸ”„ Last Modified: April 15, 2026, 3:45 p.m.

6.9

CVSS4.0

CVE-2026-39979 - jq: Out-of-Bounds Read in jv_parse_sized() Error Formatting for Non-NUL-Terminated Counted Buffers

jq is a command-line JSON processor. In commits before 2f09060afab23fe9390cce7cb860b10416e1bf5f, the jv_parse_sized() API in libjq accepts a counted buffer with an explicit length parameter, but its error-handling path formats the input buffer using %s in jv_string_fmt(), which reads until a NUL te…

πŸ“… Published: April 13, 2026, 10:18 p.m. πŸ”„ Last Modified: April 17, 2026, 3:26 p.m.

6.1

CVSS3.1

CVE-2026-39956 - jq: Missing runtime type checks for _strindices lead to crash and limited memory disclosure

jq is a command-line JSON processor. In commits after 69785bf77f86e2ea1b4a20ca86775916889e91c9, the _strindices builtin in jq's src/builtin.c passes its arguments directly to jv_string_indexes() without verifying they are strings, and jv_string_indexes() in src/jv.c relies solely on assert() checks…

πŸ“… Published: April 13, 2026, 10:10 p.m. πŸ”„ Last Modified: April 17, 2026, 3:26 p.m.

7

CVSS4.0

CVE-2026-4786 - Incomplete mitigation of CVE-2026-4519, %action expansion for command injection to webbrowser.open()

Mitgation ofΒ CVE-2026-4519 was incomplete. If the URL contained "%action" the mitigation could be bypassed for certain browser types the "webbrowser.open()" API could have commands injected into the underlying shell. SeeΒ CVE-2026-4519 for details.

πŸ“… Published: April 13, 2026, 9:52 p.m. πŸ”„ Last Modified: April 17, 2026, 3:18 p.m.

6.2

CVSS3.1

CVE-2026-33947 - jq: Unbounded Recursion in jv_setpath(), jv_getpath() and delpaths_sorted()

jq is a command-line JSON processor. In versions 1.8.1 and below, functions jv_setpath(), jv_getpath(), and delpaths_sorted() in jq's src/jv_aux.c use unbounded recursion whose depth is controlled by the length of a caller-supplied path array, with no depth limit enforced. An attacker can supply a …

πŸ“… Published: April 13, 2026, 9:50 p.m. πŸ”„ Last Modified: April 17, 2026, 3:26 p.m.

6.2

CVSS3.1

CVE-2026-40312 - ImageMagick: Off-by-One in MSL decoder could result in crash

ImageMagick is free and open-source software used for editing and manipulating digital images. In versions below 7.1.2-19, an off by one error in the MSL decoder could result in a crash when a malicous MSL file is read. This issue has been fixed in version 7.1.2-19.

πŸ“… Published: April 13, 2026, 9:43 p.m. πŸ”„ Last Modified: April 17, 2026, 8:42 p.m.

5.5

CVSS3.1

CVE-2026-40311 - ImageMagick: Heap-use-after-free via XMP profile could result in a crash when printing values

ImageMagick is free and open-source software used for editing and manipulating digital images. Versions below 7.1.2-19 and 6.9.13-44 contain a heap use-after-free vulnerability that can cause a crash when reading and printing values from an invalid XMP profile. This issue has been fixed in versions…

πŸ“… Published: April 13, 2026, 9:36 p.m. πŸ”„ Last Modified: April 17, 2026, 8:43 p.m.

5.5

CVSS3.1

CVE-2026-40310 - ImageMagick: Heap out-of-bounds write in JP2 encoder

ImageMagick is free and open-source software used for editing and manipulating digital images. Versions below both 7.1.2-19 and 6.9.13-44, contain a heap out-of-bounds write in the JP2 encoder with when a user specifies an invalid sampling index. This issue has been fixed in versions 6.9.13-44 and …

πŸ“… Published: April 13, 2026, 9:32 p.m. πŸ”„ Last Modified: April 17, 2026, 8:44 p.m.
Total resulsts: 345227
Page 103 of 34,523
Β« previous page Β» next page
Filters