2.8

CVSS3.1

CVE-2026-34781 - Electron crashes in clipboard.readImage() on malformed clipboard image data

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.5, 40.8.5, 41.1.0, and 42.0.0-alpha.5, apps that call clipboard.readImage() may be vulnerable to a denial of service. If the system clipboard contains image data that fails to decod…

πŸ“… Published: April 7, 2026, 9:20 p.m. πŸ”„ Last Modified: April 8, 2026, 7:34 p.m.

6

CVSS3.1

CVE-2026-34765 - Electron named window.open targets not scoped to the opener's browsing context

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.5, 40.8.5, 41.1.0, and 42.0.0-alpha.5, when a renderer calls window.open() with a target name, Electron did not correctly scope the named-window lookup to the opener's browsing cont…

πŸ“… Published: April 7, 2026, 9:18 p.m. πŸ”„ Last Modified: April 8, 2026, 7:34 p.m.

8.7

CVSS4.0

CVE-2026-34582 - Botan has a TLS 1.3 certificate authentication bypass

Botan is a C++ cryptography library. Prior to version 3.11.1, the TLS 1.3 implementation allowed ApplicationData records to be processed prior to the Finished message being received. A server which is attempting to enforce client authentication via certificates can by bypassed by a client which ent…

πŸ“… Published: April 7, 2026, 9:13 p.m. πŸ”„ Last Modified: April 8, 2026, 7:34 p.m.

9.3

CVSS4.0

CVE-2026-34580 - Botan has a certificate authentication bypass due to trust anchor confusion

Botan is a C++ cryptography library. In 3.11.0, the function Certificate_Store::certificate_known had a misleading name; it would return true if any certificate in the store had a DN (and subject key identifier, if set) matching that of the argument. It did not check that the cert it found and the …

πŸ“… Published: April 7, 2026, 9:12 p.m. πŸ”„ Last Modified: April 8, 2026, 7:34 p.m.

6.3

CVSS3.1

CVE-2026-34371 - LibreChat Affected by Arbitrary File Write via `execute_code` Artifact Filename Traversal

LibreChat is a ChatGPT clone with additional features. Prior to 0.8.4, LibreChat trusts the name field returned by the execute_code sandbox when persisting code-generated artifacts. On deployments using the default local file strategy, a malicious artifact filename containing traversal sequences (f…

πŸ“… Published: April 7, 2026, 9:08 p.m. πŸ”„ Last Modified: April 8, 2026, 7:34 p.m.

7.6

CVSS4.0

CVE-2026-35568 - MCP Java-SDK has a DNS Rebinding Vulnerability

MCP Java SDK is the official Java SDK for Model Context Protocol servers and clients. Prior to 1.0.0, the java-sdk contains a DNS rebinding vulnerability. This vulnerability allows an attacker to access a locally or network-private java-sdk MCP server via a victims browser that is either local, or …

πŸ“… Published: April 7, 2026, 9:06 p.m. πŸ”„ Last Modified: April 8, 2026, 7:45 p.m.

7.8

CVSS3.1

CVE-2026-35533 - mise has a local settings bypass config trust checks

mise manages dev tools like node, python, cmake, and terraform. From 2026.2.18 through 2026.4.5, mise loads trust-control settings from a local project .mise.toml before the trust check runs. An attacker who can place a malicious .mise.toml in a repository can make that same file appear trusted and…

πŸ“… Published: April 7, 2026, 9:01 p.m. πŸ”„ Last Modified: April 8, 2026, 7:34 p.m.

6.8

CVSS4.0

CVE-2026-34080 - xdg-dbus-proxy has an eavesdrop filter bypass allowing message interception

xdg-dbus-proxy is a filtering proxy for D-Bus connections. Prior to 0.1.7, a policy parser vulnerability allows bypassing eavesdrop restrictions. The proxy checks for eavesdrop=true in policy rules but fails to handle eavesdrop ='true' (with a space before the equals sign) and similar cases. Client…

πŸ“… Published: April 7, 2026, 8:57 p.m. πŸ”„ Last Modified: April 11, 2026, 1:34 a.m.

8.2

CVSS3.1

CVE-2026-34045 - Podman Desktop WebView Server Exposed

Podman Desktop is a graphical tool for developing on containers and Kubernetes. Prior to 1.26.2, an unauthenticated HTTP server exposed by Podman Desktop allows any network attacker to remotely trigger denial-of-service conditions and extract sensitive information. By abusing missing connection lim…

πŸ“… Published: April 7, 2026, 8:52 p.m. πŸ”„ Last Modified: April 8, 2026, 7:34 p.m.

9.3

CVSS4.0

CVE-2026-33439 - Pre-Authentication Remote Code Execution via `jato.clientSession` Deserialization in OpenAM

Open Access Management (OpenAM) is an access management solution. Prior to 16.0.6, OpenIdentityPlatform OpenAM is vulnerable to pre-authentication Remote Code Execution (RCE) via unsafe Java deserialization of the jato.clientSession HTTP parameter. This bypasses the WhitelistObjectInputStream mitig…

πŸ“… Published: April 7, 2026, 8:46 p.m. πŸ”„ Last Modified: April 8, 2026, 7:34 p.m.
Total resulsts: 343975
Page 106 of 34,398
Β« previous page Β» next page
Filters