6.5

CVSS3.1

CVE-2026-40889 - Frappe HR has Improper Access Control on Files

Frappe HR is an open-source human resources management solution (HRMS). Prior to versions 15.58.2 and 16.4.2, authenticated users can access unauthorized files by exploiting certain api endpoint. Versions 15.58.2 and 16.4.2 contain a patch. No known workarounds are available.

πŸ“… Published: April 21, 2026, 7:32 p.m. πŸ”„ Last Modified: April 22, 2026, 9:24 p.m.

6.5

CVSS3.0

CVE-2026-40888 - Frappe HR vulnerable to Improper Access Control

Frappe HR is an open-source human resources management solution (HRMS). Prior to versions 15.58.1 and 16.4.1, an authenticated user with default role can access unauthorized information by exploiting certain api endpoint. Versions 15.58.1 and 16.4.1 contain a patch. No known workarounds are availab…

πŸ“… Published: April 21, 2026, 7:28 p.m. πŸ”„ Last Modified: April 22, 2026, 9:24 p.m.

9.1

CVSS3.1

CVE-2026-40887 - @vendure/core has a SQL Injection vulnerability

Vendure is an open-source headless commerce platform. Starting in version 1.7.4 and prior to versions 2.3.4, 3.5.7, and 3.6.2, an unauthenticated SQL injection vulnerability exists in the Vendure Shop API. A user-controlled query string parameter is interpolated directly into a raw SQL expression w…

πŸ“… Published: April 21, 2026, 7:24 p.m. πŸ”„ Last Modified: April 22, 2026, 9:08 p.m.

2.1

CVSS4.0

CVE-2026-40878 - mailcow-dockerized Login Page has Reflected Parameter Injection / Wrong-Context XSS Escaping

mailcow: dockerized is an open source groupware/email suite based on docker. In versions prior to 2026-03b, the mailcow web interface passes the raw `$_SERVER['REQUEST_URI']` to Twig as a global template variable and renders it inside a JavaScript string literal in the `setLang()` helper of `base.t…

πŸ“… Published: April 21, 2026, 7:21 p.m. πŸ”„ Last Modified: April 22, 2026, 9:02 p.m.

6.1

CVSS3.1

CVE-2026-33812 - Excessive memory allocation when decoding malicious SFNT in golang.org/x/image

Parsing a malicious font file can cause excessive memory allocation.

πŸ“… Published: April 21, 2026, 7:21 p.m. πŸ”„ Last Modified: April 22, 2026, 9:24 p.m.

7.5

CVSS3.1

CVE-2026-33813 - Panic when decoding large WEBP image on 32-bit platforms in golang.org/x/image

Parsing a WEBP image with an invalid, large size panics on 32-bit platforms.

πŸ“… Published: April 21, 2026, 7:21 p.m. πŸ”„ Last Modified: April 22, 2026, 9:24 p.m.

6.3

CVSS4.0

CVE-2026-40881 - Zebra: addr/addrv2 Deserialization Resource Exhaustion

ZEBRA is a Zcash node written entirely in Rust. Prior to zebrad version 4.3.0 and zebra-network version 5.0.1, when deserializing addr or addrv2 messages, which contain vectors of addresses, Zebra would fully deserialize them up to a maximum length (over 233,000) that was derived from the 2 MiB mes…

πŸ“… Published: April 21, 2026, 7:20 p.m. πŸ”„ Last Modified: April 22, 2026, 9:24 p.m.

9.1

CVSS3.1

CVE-2026-40372 - ASP.NET Core Elevation of Privilege Vulnerability

Improper verification of cryptographic signature in ASP.NET Core allows an unauthorized attacker to elevate privileges over a network.

πŸ“… Published: April 21, 2026, 7:20 p.m. πŸ”„ Last Modified: April 24, 2026, 12:51 p.m.

7

CVSS4.0

CVE-2026-40875 - mailcow: dockerized vulnerable to stored XSS in user login history real_rip

mailcow: dockerized is an open source groupware/email suite based on docker. In versions prior to 2026-03b, the user dashboard's "Seen successful connections" (login history) renders the client IP from login logs without HTML escaping. Because the server trusts the X-Real-IP header as the source IP…

πŸ“… Published: April 21, 2026, 7:19 p.m. πŸ”„ Last Modified: April 22, 2026, 9:02 p.m.

7.2

CVSS4.0

CVE-2026-40880 - Zebra: Cached Mempool Verification Bypasses Consensus Rules for Ahead-of-Tip Blocks

ZEBRA is a Zcash node written entirely in Rust. Prior to zebrad version 4.3.1 and zebra-consensus version 5.0.2, a logic error in Zebra's transaction verification cache could allow a malicious miner to induce a consensus split. By carefully submitting a transaction that is valid for height H+1 but …

πŸ“… Published: April 21, 2026, 7:18 p.m. πŸ”„ Last Modified: April 22, 2026, 9:24 p.m.
Total resulsts: 346620
Page 105 of 34,662
Β« previous page Β» next page
Filters